{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:45:41Z","timestamp":1759092341676,"version":"3.40.3"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031346705"},{"type":"electronic","value":"9783031346712"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-34671-2_10","type":"book-chapter","created":{"date-parts":[[2023,6,20]],"date-time":"2023-06-20T23:02:58Z","timestamp":1687302178000},"page":"135-150","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["CANdito: Improving Payload-Based Detection of Attacks on Controller Area Networks"],"prefix":"10.1007","author":[{"given":"Stefano","family":"Longari","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carlo Alberto","family":"Pozzoli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessandro","family":"Nichelini","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,6,21]]},"reference":[{"issue":"8","key":"10_CR1","doi-asserted-by":"publisher","first-page":"5081","DOI":"10.1109\/TITS.2020.3046974","volume":"22","author":"F Amato","year":"2021","unstructured":"Amato, F., Coppolino, L., Mercaldo, F., Moscato, F., Nardone, R., Santone, A.: Can-bus attack detection with deep learning. IEEE Trans. Intell. Transp. Syst. 22(8), 5081\u20135090 (2021). https:\/\/doi.org\/10.1109\/TITS.2020.3046974","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"doi-asserted-by":"crossref","unstructured":"Buttigieg, R., Farrugia, M., Meli, C.: Security issues in controller area networks in automobiles. CoRR abs\/1711.05824 (2017). arXiv:1711.05824","key":"10_CR2","DOI":"10.1109\/STA.2017.8314877"},{"unstructured":"Checkoway, S., et al.: Comprehensive experimental analyses of automotive attack surfaces, August 2011","key":"10_CR3"},{"unstructured":"Clevert, D.A., Unterthiner, T., Hochreiter, S.: Fast and accurate deep network learning by exponential linear units (elus). arXiv preprint arXiv:1511.07289 (2015)","key":"10_CR4"},{"key":"10_CR5","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2022.100470","volume":"35","author":"AK Desta","year":"2022","unstructured":"Desta, A.K., Ohira, S., Arai, I., Fujikawa, K.: Rec-CNN: in-vehicle networks intrusion detection using convolutional neural networks trained on recurrence plots. Veh. Commun. 35, 100470 (2022). https:\/\/doi.org\/10.1016\/j.vehcom.2022.100470","journal-title":"Veh. Commun."},{"doi-asserted-by":"publisher","unstructured":"de Faveri Tron, A., Longari, S., Carminati, M., Polino, M., Zanero, S.: CANflict: exploiting peripheral conflicts for data-link layer attacks on automotive networks. In: Yin, H., Stavrou, A., Cremers, C., Shi, E. (eds.) Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, CCS 2022, Los Angeles, CA, USA, 7\u201311 November 2022, pp. 711\u2013723. ACM (2022). https:\/\/doi.org\/10.1145\/3548606.3560618","key":"10_CR6","DOI":"10.1145\/3548606.3560618"},{"key":"10_CR7","doi-asserted-by":"publisher","first-page":"58194","DOI":"10.1109\/ACCESS.2020.2982544","volume":"8","author":"M Hanselmann","year":"2020","unstructured":"Hanselmann, M., Strauss, T., Dormann, K., Ulmer, H.: CANet: an unsupervised intrusion detection system for high dimensional can bus data. IEEE Access 8, 58194\u201358205 (2020)","journal-title":"IEEE Access"},{"issue":"7","key":"10_CR8","doi-asserted-by":"publisher","first-page":"6123","DOI":"10.1109\/TITS.2021.3078740","volume":"23","author":"HJ Jo","year":"2022","unstructured":"Jo, H.J., Choi, W.: A survey of attacks on controller area networks and corresponding countermeasures. IEEE Trans. Intell. Transp. Syst. 23(7), 6123\u20136141 (2022). https:\/\/doi.org\/10.1109\/TITS.2021.3078740","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"6","key":"10_CR9","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0155781","volume":"11","author":"MJ Kang","year":"2016","unstructured":"Kang, M.J., Kang, J.W.: Intrusion detection system using deep neural network for in-vehicle network security. PLoS ONE 11(6), e0155781 (2016)","journal-title":"PLoS ONE"},{"unstructured":"Kingma, D.P., Ba, J.: Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014)","key":"10_CR10"},{"doi-asserted-by":"crossref","unstructured":"Koscher, K., et al.: Experimental security analysis of a modern automobile. In: 2010 IEEE Symposium on Security and Privacy, pp. 447\u2013462. IEEE (2010)","key":"10_CR11","DOI":"10.1109\/SP.2010.34"},{"doi-asserted-by":"publisher","unstructured":"Lampe, B., Meng, W.: IDS for CAN: a practical intrusion detection system for CAN bus security. In: IEEE Global Communications Conference, GLOBECOM 2022, Rio de Janeiro, Brazil, 4\u20138 December 2022, pp. 1782\u20131787. IEEE (2022). https:\/\/doi.org\/10.1109\/GLOBECOM48099.2022.10001536","key":"10_CR12","DOI":"10.1109\/GLOBECOM48099.2022.10001536"},{"unstructured":"Lin, Y., Chen, C., Xiao, F., Avatefipour, O., Alsubhi, K., Yunianta, A.: An evolutionary deep learning anomaly detection framework for in-vehicle networks-can bus. IEEE Trans. Ind. Appl. (2020)","key":"10_CR13"},{"key":"10_CR14","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2022.100471","volume":"35","author":"W Lo","year":"2022","unstructured":"Lo, W., AlQahtani, H., Thakur, K., Almadhor, A., Chander, S., Kumar, G.: A hybrid deep learning based intrusion detection system using spatial-temporal representation of in-vehicle network traffic. Veh. Commun. 35, 100471 (2022). https:\/\/doi.org\/10.1016\/j.vehcom.2022.100471","journal-title":"Veh. Commun."},{"doi-asserted-by":"publisher","unstructured":"Longari, S., Cannizzo, A., Carminati, M., Zanero, S.: A secure-by-design framework for automotive on-board network risk analysis. In: 2019 IEEE Vehicular Networking Conference (VNC), pp. 1\u20138 (2019). https:\/\/doi.org\/10.1109\/VNC48660.2019.9062783","key":"10_CR15","DOI":"10.1109\/VNC48660.2019.9062783"},{"doi-asserted-by":"publisher","unstructured":"Longari, S., Penco, M., Carminati, M., Zanero, S.: Copycan: an error-handling protocol based intrusion detection system for controller area network. In: Cavallaro, L., Kinder, J., Holz, T. (eds.) Proceedings of the ACM Workshop on Cyber-Physical Systems Security & Privacy, CPS-SPC@CCS 2019, London, UK, 11 November 2019, pp. 39\u201350. ACM (2019). https:\/\/doi.org\/10.1145\/3338499.3357362","key":"10_CR16","DOI":"10.1145\/3338499.3357362"},{"doi-asserted-by":"crossref","unstructured":"Longari, S., Valcarcel, D.H.N., Zago, M., Carminati, M., Zanero, S.: CANnolo: an anomaly detection system based on LSTM autoencoders for controller area network. IEEE Trans. Netw. Serv. Manag. (2020)","key":"10_CR17","DOI":"10.1109\/TNSM.2020.3038991"},{"doi-asserted-by":"crossref","unstructured":"Maffiola, D., Longari, S., Carminati, M., Tanelli, M., Zanero, S.: GOLIATH: a decentralized framework for data collection in intelligent transportation systems. IEEE Trans. Intell. Transp. Syst. (2021)","key":"10_CR18","DOI":"10.1109\/TITS.2021.3123824"},{"unstructured":"Malhotra, P., Ramakrishnan, A., Anand, G., Vig, L., Agarwal, P., Shroff, G.: LSTM-based encoder-decoder for multi-sensor anomaly detection. arXiv preprint arXiv:1607.00148 (2016)","key":"10_CR19"},{"issue":"4","key":"10_CR20","doi-asserted-by":"publisher","first-page":"1083","DOI":"10.1109\/TIFS.2018.2870826","volume":"14","author":"M Marchetti","year":"2018","unstructured":"Marchetti, M., Stabili, D.: READ: reverse engineering of automotive data frames. IEEE Trans. Inf. Forensics Secur. 14(4), 1083\u20131097 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"doi-asserted-by":"crossref","unstructured":"Marchetti, M., Stabili, D., Guido, A., Colajanni, M.: Evaluation of anomaly detection for in-vehicle networks through information-theoretic algorithms. In: 2016 IEEE 2nd International Forum on Research and Technologies for Society and Industry Leveraging a better tomorrow (RTSI), pp. 1\u20136. IEEE (2016)","key":"10_CR21","DOI":"10.1109\/RTSI.2016.7740627"},{"issue":"260\u2013264","key":"10_CR22","first-page":"15","volume":"21","author":"C Miller","year":"2013","unstructured":"Miller, C., Valasek, C.: Adventures in automotive networks and control units. Def. Con. 21(260\u2013264), 15\u201331 (2013)","journal-title":"Def. Con."},{"unstructured":"Miller, C., Valasek, C.: Remote exploitation of an unaltered passenger vehicle. Black Hat USA 2015(S 91) (2015)","key":"10_CR23"},{"key":"10_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2020.100291","volume":"27","author":"H Qin","year":"2021","unstructured":"Qin, H., Yan, M., Ji, H.: Application of controller area network (CAN) bus anomaly detection based on time series prediction. Veh. Commun. 27, 100291 (2021). https:\/\/doi.org\/10.1016\/j.vehcom.2020.100291","journal-title":"Veh. Commun."},{"unstructured":"Robert Bosch GMBH: Can specification, version 2.0. Standard, Robert Bosch GmbH, Stuttgart, Germany (1991)","key":"10_CR25"},{"doi-asserted-by":"crossref","unstructured":"Seo, E., Song, H.M., Kim, H.K.: GIDS: GAN based intrusion detection system for in-vehicle network. In: 2018 16th Annual Conference on Privacy, Security and Trust (PST), pp. 1\u20136. IEEE (2018)","key":"10_CR26","DOI":"10.1109\/PST.2018.8514157"},{"doi-asserted-by":"publisher","unstructured":"Song, H., Kim, H., Kim, H.K.: Intrusion detection system based on the analysis of time intervals of can messages for in-vehicle network, pp. 63\u201368, January 2016. https:\/\/doi.org\/10.1109\/ICOIN.2016.7427089","key":"10_CR27","DOI":"10.1109\/ICOIN.2016.7427089"},{"doi-asserted-by":"publisher","unstructured":"Song, H.M., Woo, J., Kim, H.K.: In-vehicle network intrusion detection using deep convolutional neural network. Veh. Commun. 21 (2020). https:\/\/doi.org\/10.1016\/j.vehcom.2019.100198","key":"10_CR28","DOI":"10.1016\/j.vehcom.2019.100198"},{"unstructured":"Sutskever, I., Vinyals, O., Le, Q.V.: Sequence to sequence learning with neural networks. arXiv preprint arXiv:1409.3215 (2014)","key":"10_CR29"},{"key":"10_CR30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101857","volume":"94","author":"S Tariq","year":"2020","unstructured":"Tariq, S., Lee, S., Kim, H.K., Woo, S.S.: CAN-ADF: the controller area network attack detection framework. Comput. Secur. 94, 101857 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101857","journal-title":"Comput. Secur."},{"doi-asserted-by":"publisher","unstructured":"Tariq, S., Lee, S., Woo, S.S.: CANTransfer: transfer learning based intrusion detection on a controller area network using convolutional LSTM network. In: Hung, C., Cern\u00fd, T., Shin, D., Bechini, A. (eds.) SAC \u201920: The 35th ACM\/SIGAPP Symposium on Applied Computing, online event, [Brno, Czech Republic], March 30\u20133 April 2020, pp. 1048\u20131055. ACM (2020). https:\/\/doi.org\/10.1145\/3341105.3373868","key":"10_CR31","DOI":"10.1145\/3341105.3373868"},{"unstructured":"Taylor, A.: Anomaly-based detection of malicious activity in in-vehicle networks. Ph.D. thesis, Universit\u00e9 d\u2019Ottawa\/University of Ottawa (2017)","key":"10_CR32"},{"doi-asserted-by":"crossref","unstructured":"Taylor, A., Japkowicz, N., Leblanc, S.: Frequency-based anomaly detection for the automotive can bus. In: 2015 World Congress on Industrial Control Systems Security (WCICSS), pp. 45\u201349. IEEE (2015)","key":"10_CR33","DOI":"10.1109\/WCICSS.2015.7420322"},{"doi-asserted-by":"publisher","unstructured":"Wang, K., Zhang, A., Sun, H., Wang, B.: Analysis of recent deep-learning-based intrusion detection methods for in-vehicle network. IEEE Trans. Intell. Transp. Syst. 1\u201312 (2022). https:\/\/doi.org\/10.1109\/TITS.2022.3222486","key":"10_CR34","DOI":"10.1109\/TITS.2022.3222486"},{"issue":"7","key":"10_CR35","doi-asserted-by":"publisher","first-page":"4467","DOI":"10.1109\/TITS.2021.3055351","volume":"22","author":"G Xie","year":"2021","unstructured":"Xie, G., Yang, L.T., Yang, Y., Luo, H., Li, R., Alazab, M.: Threat analysis for automotive CAN networks: a GAN model-based intrusion detection technique. IEEE Trans. Intell. Transp. Syst. 22(7), 4467\u20134477 (2021). https:\/\/doi.org\/10.1109\/TITS.2021.3055351","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"6","key":"10_CR36","doi-asserted-by":"publisher","first-page":"48","DOI":"10.1109\/MDAT.2019.2899062","volume":"36","author":"C Young","year":"2019","unstructured":"Young, C., Zambreno, J., Olufowobi, H., Bloom, G.: Survey of automotive controller area network intrusion detection systems. IEEE Des. Test 36(6), 48\u201355 (2019). https:\/\/doi.org\/10.1109\/MDAT.2019.2899062","journal-title":"IEEE Des. Test"},{"key":"10_CR37","doi-asserted-by":"publisher","DOI":"10.1016\/j.dib.2020.105149","volume":"29","author":"M Zago","year":"2020","unstructured":"Zago, M., et al.: ReCAN-dataset for reverse engineering of controller area networks. Data Brief 29, 105149 (2020)","journal-title":"Data Brief"},{"unstructured":"Zhang, L., Shi, L., Kaja, N., Ma, D.: A two-stage deep learning approach for can intrusion detection (2018)","key":"10_CR38"},{"issue":"8","key":"10_CR39","doi-asserted-by":"publisher","first-page":"1707","DOI":"10.1109\/LWC.2021.3077946","volume":"10","author":"R Zhao","year":"2021","unstructured":"Zhao, R., et al.: An efficient intrusion detection method based on dynamic autoencoder. IEEE Wirel. Commun. Lett. 10(8), 1707\u20131711 (2021). https:\/\/doi.org\/10.1109\/LWC.2021.3077946","journal-title":"IEEE Wirel. Commun. Lett."}],"container-title":["Lecture Notes in Computer Science","Cyber Security, Cryptology, and Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-34671-2_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T12:20:41Z","timestamp":1710332441000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-34671-2_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031346705","9783031346712"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-34671-2_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"21 June 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CSCML","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Cyber Security, Cryptology, and Machine Learning","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Be'er Sheva","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Israel","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 June 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cscml2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.cscml.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Open","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"70","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"21","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"15","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}