The Experts below are selected from a list of 282 Experts worldwide ranked by ideXlab platform

David L. Mills - One of the best experts on this subject based on the ideXlab platform.

  • computer Network Time synchronization the Network Time Protocol on earth and in space second edition
    2010
    Co-Authors: David L. Mills
    Abstract:

    Carefully coordinated, reliable, and accurate Time synchronization is vital to a wide spectrum of fieldsfrom air and ground traffic control, to buying and selling goods and services, to TV Network programming. Ill-gotten Time could even lead to the unimaginable and cause DNS caches to expire, leaving the entire Internet to implode on the root servers. Written by the original developer of the Network Time Protocol (NTP), Computer Network Time Synchronization: The Network Time Protocol on Earth and in Space, Second Edition addresses the technological infrastructure of Time dissemination, distribution, and synchronizationspecifically the architecture, Protocols, and algorithms of the NTP. This system has been active in one form or another for almost three decades on the Internet and numerous private Networks on the nether side of firewalls. Just about everything today that can be connected to a Network wire has support for NTP. This book: Describes the principal components of an NTP client and how it works with redundant servers and diverse Network paths Provides an in-depth description of cryptographic and other critical algorithms Presents an overview of the engineering principles guiding Network configuration Evaluating historic events that have taken place since computer Network Timekeeping started almost three decades ago, the author details a number of systems and drivers for current radio, satellites, and telephone modem dissemination and explains how we reckon the Time, according to the stars and atoms. The original 16 chapters of the first edition have been rewritten, updated, and enhanced with new material. Four new chapters cover new algorithms and previously uncovered concepts, including Timekeeping in space missions. Praise for the first edition: " For those that need an exhaustive tome on all of the minutiae related to NTP and synchronization, this is the source. definitive this book should be considered the last word on the topic."Ben Rothke on Slashdot.org" the bible of the subject contains enough information to take you just as far as you want to go.Dr. Mills is the original developer of NTP."Books On-Line

  • Network Time Protocol version 4 Protocol and algorithms specification
    RFC, 2010
    Co-Authors: Jack L Burbank, David L. Mills, William Kasch
    Abstract:

    The Network Time Protocol (NTP) is widely used to synchronize computer clocks in the Internet. This document describes NTP version 4 (NTPv4), which is backwards compatible with NTP version 3 (NTPv3), described in RFC 1305, as well as previous versions of the Protocol. NTPv4 includes a modified Protocol header to accommodate the Internet Protocol version 6 address family. NTPv4 includes fundamental improvements in the mitigation and discipline algorithms that extend the potential accuracy to the tens of microseconds with modern workstations and fast LANs. It includes a dynamic server discovery scheme, so that in many cases, specific server configuration is not required. It corrects certain errors in the NTPv3 design and implementation and includes an optional extension mechanism. [STANDARDS-TRACK]

  • Network Time Protocol Version 4: Autokey Specification
    2010
    Co-Authors: David L. Mills, Brian Haberman
    Abstract:

    This memo describes the Autokey security model for authenticating servers to clients using the Network Time Protocol (NTP) and public key cryptography. Its design is based on the premise that IPSEC schemes cannot be adopted intact, since that would preclude stateless servers and severely compromise Timekeeping accuracy. In addition, PKI schemes presume authenticated Time values are always available to enforce certificate lifeTimes; however, cryptographically verified Timestamps require interaction between the Timekeeping and authentication functions. This memo includes the Autokey requirements analysis, design principles and Protocol specification. A detailed description of the Protocol states, events and transition functions is included. A prototype of the Autokey design based on this memo has been implemented, tested and documented in the NTP Version 4 (NTPv4) software distribution for Unix, Windows and VMS at http://www.ntp.org.

  • computer Network Time synchronization the Network Time Protocol
    2006
    Co-Authors: David L. Mills
    Abstract:

    BASIC CONCEPTS Time Synchronization Time Synchronization Protocols Computer Clocks Processing Time Values Correctness and Accuracy Expectations Security NTP in the Internet Parting Shots References HOW NTP WORKS General Infrastructure Requirements How NTP Represents the Time How NTP Reckons the Time How NTP Disciplines the Time How NTP Clients and Servers Associate How NTP Discovers Servers How NTP Manages Network Resources How NTP Avoids Errors How NTP Performance Is Determined How NTP Controls Access How NTP Watches for Terrorists How NTP Clocks Are Watched Parting Shots References Further Reading IN THE BELLY OF THE BEAST Related Technology Terms and Notation Process Flow Packet Processing Clock Filter Algorithm Selection Algorithm Clustering Algorithm Combining Algorithm Huff-'n-Puff Filter Mitigation Rules and the Prefer Peer Poll Process Parting Shots References Further Reading CLOCK DISCIPLINE ALGORITHM Feedback Control Systems Phase and Frequency Discipline Weight Factors Poll Interval Control Popcorn and Step Control Clock State Machine Parting Shots References Further Reading NTP SUBNET CONFIGURATION Automatic Server Discovery Manual Server Discovery and Configuration Evaluating the Sources Selecting the Stratum Selecting the Number of Configured Servers Engineering Campus and Corporate Networks Engineering Home Office and Small Business Networks Hardware and Network Considerations Parting Shots References Further Reading NTP PERFORMANCE IN THE INTERNET Performance Measurement Tools System Clock Latency Characteristics Characteristics of a Primary Server and Reference Clock Characteristics between Primary Servers on the Internet Characteristics of a Client and a Primary Server on a Fast Ethernet Results from an Internet Survey Server and Network Resource Requirements Parting Shots References PRIMARY SERVERS AND REFERENCE CLOCKS Driver Structure and Interface Reference Clock Drivers Further Reading KERNEL TimeKEEPING SUPPORT System Clock Reading Algorithm Clock Discipline Algorithms Kernel PLL/FLL Discipline Kernel PPS Discipline Clock Adjust Algorithm Proof of Performance Kernel PLL/FLL Discipline Performance Kernel PPS Discipline Parting Shots References Further Reading CRYPTOGRAPHIC AUTHENTICATION NTP Security Model NTP Secure Groups Autokey Security Protocol Parting Shots References Further Reading IDENTITY SCHEMES X509 Certificates Private Certificate (PC) Identity Scheme Trusted Certificate (TC) Identity Scheme Schnorr (IFF) Identity Scheme Guillou-Quisquater (GQ) Identity Scheme Mu-Varadharajan (MV) Identity Scheme Parting Shots References Further Reading ANALYSIS OF ERRORS Clock Reading Errors Timestamp Errors Sawtooth Errors Maximum Error Budget Expected Error Budget Parting Shots References MODELING AND ANALYSIS OF COMPUTER CLOCKS Computer Clock Concepts Mathematical Model of the Generic Feedback Loop Synthetic Timescales and Clock Wranglers Parting Shots References Further Reading METROLOGY AND CHRONOMETRY OF THE NTP TimeSCALE Scientific Timescales Based on Astronomy and Atomic Physics Civil Timescales Based on Earth Rotation How NTP Reckons with UTC Leap Seconds On Numbering the Calendars and Days On the Julian Day Number System On Timescales, Leap Events, and the Age of Eras The NTP Era and Buddy Epoch Comparison with Other Computer Timescales Primary Frequency and Time Standards Time and Frequency Dissemination Parting Shots References Further Reading NTP REFERENCE IMPLEMENTATION NTP Packet Header Control Flow Main Program and Common Routines Peer Process System Process Clock Discipline Process Clock Adjust Process Poll Process Parting Shots Reference Further Reading TECHNICAL HISTORY OF NTP On the Antiquity of NTP On the Proliferation of NTP around the Globe Autonomous Authentication Autonomous Configuration Radios, We Have Radios Hunting the Nanoseconds Experimental Studies Theory and Algorithms Growing Pains As Time Goes By Parting Shots References Further Reading BIBLIOGRAPHY INDEX

  • a brief history of ntp Time memoirs of an internet Timekeeper
    ACM Special Interest Group on Data Communication, 2003
    Co-Authors: David L. Mills
    Abstract:

    This paper traces the origins and evolution of the Network Time Protocol (NTP) over two decades of continuous operation. The technology has been continuously improved from hundreds of milliseconds in the rowdy Internet of the early 1980s to tens of nanoseconds in the Internet of the new century. It includes a blend of history lessons, technology milestones and series of experiments that shape, define and record the early history of the Internet and NTP.This narrative is decidedly personal, since the job description for an Internet Timekeeper is highly individualized and invites very few applicants. There is no attempt here to present a comprehensive tutorial, only a almanac of personal observations, eclectic minutiae and fireside chat. Many souls have contributed to the technology, some of which are individually acknowledged in this paper, the rest too numerous left to write their own memoirs.

Radha Poovendran - One of the best experts on this subject based on the ideXlab platform.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    IEEE Transactions on Information Forensics and Security, 2019
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based intrusion detection systems (IDSs) that detect masquerade attacks in the controller area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    arXiv: Cryptography and Security, 2018
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based Intrusion Detection Systems (IDSs) that detect masquerade attacks in the Controller Area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington (UW) EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. We validate our formal analyses through extensive experiments for different messages, IDS settings, and vehicles. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • cloaking the clock emulating clock skew in controller area Networks
    International Conference on Cyber-Physical Systems, 2018
    Co-Authors: Sang Uk Sagong, Xuhang Ying, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    Automobiles are equipped with Electronic Control Units (ECUs) that communicate via in-vehicle Network Protocol standards such as the Controller Area Network (CAN). These Protocols were designed under the assumption that separating in-vehicle communications from external Networks is sufficient for protection against cyber attacks. This assumption, however, has been shown to be invalid by recent attacks in which adversaries were able to infiltrate the in-vehicle Network. Motivated by these attacks, intrusion detection systems (IDSs) have been proposed for in-vehicle Networks that attempt to detect attacks by exploiting physical properties such as clock skew of an ECU. In this paper, we propose the cloaking attack, an intelligent masquerade attack in which an adversary modifies the timing of transmitted messages to match the clock skew of a targeted ECU. The attack leverages the fact that, while the clock skew is a physical property of each ECU that cannot be changed by the adversary, the estimation of the clock skew by other ECUs is based on the timing of Network traffic, which, being a cyber component only, can be modified by an adversary. We implement the proposed cloaking attack and test it on two IDSs, namely, the current state-of-the-art IDS and its adaptation to the widely-used Network Time Protocol (NTP). We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle, and show that it is able to deceive both IDSs. We also introduce a new metric called the Maximum Slackness Index to quantify the effectiveness of a clock skew-based IDS in detecting masquerade attacks when the adversary is unable to precisely match the clock skew of the targeted ECU.

Sang Uk Sagong - One of the best experts on this subject based on the ideXlab platform.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    IEEE Transactions on Information Forensics and Security, 2019
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based intrusion detection systems (IDSs) that detect masquerade attacks in the controller area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • Shape of the Cloak: Formal Analysis of Clock Skew-Based Intrusion Detection System in Controller Area Networks
    2019
    Co-Authors: Ying Xuhang, Sang Uk Sagong, Clark Andrew, Bushnell Linda, Poovendran Radha
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based Intrusion Detection Systems (IDSs) that detect masquerade attacks in the Controller Area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington (UW) EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. We validate our formal analyses through extensive experiments for different messages, IDS settings, and vehicles. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.Comment: Part of this work was presented at ACM/IEEE ICCPS 2018; to be published in IEEE Transactions on Information Forensics & Securit

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    arXiv: Cryptography and Security, 2018
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based Intrusion Detection Systems (IDSs) that detect masquerade attacks in the Controller Area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington (UW) EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. We validate our formal analyses through extensive experiments for different messages, IDS settings, and vehicles. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • cloaking the clock emulating clock skew in controller area Networks
    International Conference on Cyber-Physical Systems, 2018
    Co-Authors: Sang Uk Sagong, Xuhang Ying, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    Automobiles are equipped with Electronic Control Units (ECUs) that communicate via in-vehicle Network Protocol standards such as the Controller Area Network (CAN). These Protocols were designed under the assumption that separating in-vehicle communications from external Networks is sufficient for protection against cyber attacks. This assumption, however, has been shown to be invalid by recent attacks in which adversaries were able to infiltrate the in-vehicle Network. Motivated by these attacks, intrusion detection systems (IDSs) have been proposed for in-vehicle Networks that attempt to detect attacks by exploiting physical properties such as clock skew of an ECU. In this paper, we propose the cloaking attack, an intelligent masquerade attack in which an adversary modifies the timing of transmitted messages to match the clock skew of a targeted ECU. The attack leverages the fact that, while the clock skew is a physical property of each ECU that cannot be changed by the adversary, the estimation of the clock skew by other ECUs is based on the timing of Network traffic, which, being a cyber component only, can be modified by an adversary. We implement the proposed cloaking attack and test it on two IDSs, namely, the current state-of-the-art IDS and its adaptation to the widely-used Network Time Protocol (NTP). We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle, and show that it is able to deceive both IDSs. We also introduce a new metric called the Maximum Slackness Index to quantify the effectiveness of a clock skew-based IDS in detecting masquerade attacks when the adversary is unable to precisely match the clock skew of the targeted ECU.

  • Cloaking the Clock: Emulating Clock Skew in Controller Area Networks
    2018
    Co-Authors: Sang Uk Sagong, Ying Xuhang, Clark Andrew, Bushnell Linda, Poovendran Radha
    Abstract:

    Automobiles are equipped with Electronic Control Units (ECU) that communicate via in-vehicle Network Protocol standards such as Controller Area Network (CAN). These Protocols are designed under the assumption that separating in-vehicle communications from external Networks is sufficient for protection against cyber attacks. This assumption, however, has been shown to be invalid by recent attacks in which adversaries were able to infiltrate the in-vehicle Network. Motivated by these attacks, intrusion detection systems (IDSs) have been proposed for in-vehicle Networks that attempt to detect attacks by making use of device fingerprinting using properties such as clock skew of an ECU. In this paper, we propose the cloaking attack, an intelligent masquerade attack in which an adversary modifies the timing of transmitted messages in order to match the clock skew of a targeted ECU. The attack leverages the fact that, while the clock skew is a physical property of each ECU that cannot be changed by the adversary, the estimation of the clock skew by other ECUs is based on Network traffic, which, being a cyber component only, can be modified by an adversary. We implement the proposed cloaking attack and test it on two IDSs, namely, the current state-of-the-art IDS and a new IDS that we develop based on the widely-used Network Time Protocol (NTP). We implement the cloaking attack on two hardware testbeds, a prototype and a real connected vehicle, and show that it can always deceive both IDSs. We also introduce a new metric called the Maximum Slackness Index to quantify the effectiveness of the cloaking attack even when the adversary is unable to precisely match the clock skew of the targeted ECU.Comment: 11 pages, 13 figures, This work has been accepted to the 9th ACM/IEEE International Conference on Cyber-Physical Systems (ICCPS

Xuhang Ying - One of the best experts on this subject based on the ideXlab platform.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    IEEE Transactions on Information Forensics and Security, 2019
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based intrusion detection systems (IDSs) that detect masquerade attacks in the controller area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    arXiv: Cryptography and Security, 2018
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based Intrusion Detection Systems (IDSs) that detect masquerade attacks in the Controller Area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington (UW) EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. We validate our formal analyses through extensive experiments for different messages, IDS settings, and vehicles. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • cloaking the clock emulating clock skew in controller area Networks
    International Conference on Cyber-Physical Systems, 2018
    Co-Authors: Sang Uk Sagong, Xuhang Ying, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    Automobiles are equipped with Electronic Control Units (ECUs) that communicate via in-vehicle Network Protocol standards such as the Controller Area Network (CAN). These Protocols were designed under the assumption that separating in-vehicle communications from external Networks is sufficient for protection against cyber attacks. This assumption, however, has been shown to be invalid by recent attacks in which adversaries were able to infiltrate the in-vehicle Network. Motivated by these attacks, intrusion detection systems (IDSs) have been proposed for in-vehicle Networks that attempt to detect attacks by exploiting physical properties such as clock skew of an ECU. In this paper, we propose the cloaking attack, an intelligent masquerade attack in which an adversary modifies the timing of transmitted messages to match the clock skew of a targeted ECU. The attack leverages the fact that, while the clock skew is a physical property of each ECU that cannot be changed by the adversary, the estimation of the clock skew by other ECUs is based on the timing of Network traffic, which, being a cyber component only, can be modified by an adversary. We implement the proposed cloaking attack and test it on two IDSs, namely, the current state-of-the-art IDS and its adaptation to the widely-used Network Time Protocol (NTP). We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle, and show that it is able to deceive both IDSs. We also introduce a new metric called the Maximum Slackness Index to quantify the effectiveness of a clock skew-based IDS in detecting masquerade attacks when the adversary is unable to precisely match the clock skew of the targeted ECU.

Linda Bushnell - One of the best experts on this subject based on the ideXlab platform.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    IEEE Transactions on Information Forensics and Security, 2019
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based intrusion detection systems (IDSs) that detect masquerade attacks in the controller area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • shape of the cloak formal analysis of clock skew based intrusion detection system in controller area Networks
    arXiv: Cryptography and Security, 2018
    Co-Authors: Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based Intrusion Detection Systems (IDSs) that detect masquerade attacks in the Controller Area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission Times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock skew-based IDSs in automotive CAN. We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle (the University of Washington (UW) EcoCAR), and demonstrate its effectiveness against both the SOTA and NTP-based IDSs. We validate our formal analyses through extensive experiments for different messages, IDS settings, and vehicles. By comparing each predicted attack success probability curve against its experimental curve, we find that the average prediction error is within 3.0% for the SOTA IDS and 5.7% for the NTP-based IDS.

  • cloaking the clock emulating clock skew in controller area Networks
    International Conference on Cyber-Physical Systems, 2018
    Co-Authors: Sang Uk Sagong, Xuhang Ying, Andrew Clark, Linda Bushnell, Radha Poovendran
    Abstract:

    Automobiles are equipped with Electronic Control Units (ECUs) that communicate via in-vehicle Network Protocol standards such as the Controller Area Network (CAN). These Protocols were designed under the assumption that separating in-vehicle communications from external Networks is sufficient for protection against cyber attacks. This assumption, however, has been shown to be invalid by recent attacks in which adversaries were able to infiltrate the in-vehicle Network. Motivated by these attacks, intrusion detection systems (IDSs) have been proposed for in-vehicle Networks that attempt to detect attacks by exploiting physical properties such as clock skew of an ECU. In this paper, we propose the cloaking attack, an intelligent masquerade attack in which an adversary modifies the timing of transmitted messages to match the clock skew of a targeted ECU. The attack leverages the fact that, while the clock skew is a physical property of each ECU that cannot be changed by the adversary, the estimation of the clock skew by other ECUs is based on the timing of Network traffic, which, being a cyber component only, can be modified by an adversary. We implement the proposed cloaking attack and test it on two IDSs, namely, the current state-of-the-art IDS and its adaptation to the widely-used Network Time Protocol (NTP). We implement the cloaking attack on two hardware testbeds, a prototype and a real vehicle, and show that it is able to deceive both IDSs. We also introduce a new metric called the Maximum Slackness Index to quantify the effectiveness of a clock skew-based IDS in detecting masquerade attacks when the adversary is unable to precisely match the clock skew of the targeted ECU.