{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T11:49:35Z","timestamp":1740138575875,"version":"3.37.3"},"reference-count":25,"publisher":"Walter de Gruyter GmbH","issue":"5-6","funder":[{"DOI":"10.13039\/100010661","name":"Horizon 2020 Framework Programme","doi-asserted-by":"publisher","award":["833742","786890","830927","823916"],"award-info":[{"award-number":["833742","786890","830927","823916"]}],"id":[{"id":"10.13039\/100010661","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,12,16]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>The Internet of Vehicle (IoV) is an extension of Vehicle-to-Vehicle (V2V) communication that can improve vehicles\u2019 fully autonomous driving capabilities. However, these communications are vulnerable to many attacks. Therefore, it is critical to provide run-time mechanisms to detect malware and stop the attackers before they manage to gain a foothold in the system. Anomaly-based detection techniques are convenient and capable of detecting off-nominal behavior by the component caused by zero-day attacks. One significant critical aspect when using anomaly-based techniques is ensuring the correct definition of the observed component\u2019s normal behavior. In this paper, we propose using the task\u2019s temporal specification as a baseline to define its normal behavior and identify temporal thresholds that give the system the ability to predict malicious tasks. By applying our solution on one use-case, we got temporal thresholds 20\u201340\u2009% less than the one usually used to alarm the system about security violations. Using our boundaries ensures the early detection of off-nominal temporal behavior and provides the system with a sufficient amount of time to initiate recovery actions.<\/jats:p>","DOI":"10.1515\/itit-2020-0009","type":"journal-article","created":{"date-parts":[[2020,12,14]],"date-time":"2020-12-14T10:19:49Z","timestamp":1607941189000},"page":"227-239","source":"Crossref","is-referenced-by-count":1,"title":["Temporal-based intrusion detection for IoV"],"prefix":"10.1515","volume":"62","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9049-7254","authenticated-orcid":false,"given":"Mohammad","family":"Hamad","sequence":"first","affiliation":[{"name":"28412 Technical University of Munich , Department of Electrical and Computer Engineering , Munich , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zain A.\u2009H.","family":"Hammadeh","sequence":"additional","affiliation":[{"name":"Institute for Software Technology , German Aerospace Center (DLR) , Cologne , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Selma","family":"Saidi","sequence":"additional","affiliation":[{"name":"Technical University of Dortmund , Department of Electrical Engineering and Information Technology , Dortmund , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vassilis","family":"Prevelakis","sequence":"additional","affiliation":[{"name":"26527 Technical University of Braunschweig , Institute of Computer and Network Engineering , Braunschweig , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"374","published-online":{"date-parts":[[2020,12,5]]},"reference":[{"key":"2023033120444148615_j_itit-2020-0009_ref_001_w2aab3b7d555b1b6b1ab2ab1Aa","doi-asserted-by":"crossref","unstructured":"Faraz Ahmed, Haider Hameed, M. Zubair Shafiq, and Muddassar Farooq. Using Spatio-temporal Information in API Calls with Machine Learning Algorithms for Malware Detection. In Proceedings of the 2nd ACM Workshop on Security and Artificial Intelligence, pages 55\u201362. ACM, 2009.","DOI":"10.1145\/1654988.1655003"},{"key":"2023033120444148615_j_itit-2020-0009_ref_002_w2aab3b7d555b1b6b1ab2ab2Aa","doi-asserted-by":"crossref","unstructured":"James P. Anderson. Computer Security Technology Planning Study. Volume 2. Technical report, DTIC Document, 1972.","DOI":"10.21236\/AD0772806"},{"key":"2023033120444148615_j_itit-2020-0009_ref_003_w2aab3b7d555b1b6b1ab2ab3Aa","doi-asserted-by":"crossref","unstructured":"Neil C. Audsley, Alan Burns, Robert I. Davis, Ken W. Tindell, and Andy J. Wellings. Fixed Priority Pre-emptive Scheduling: An Historical Perspective. Real-Time Systems, 8(2-3):173\u2013198, 1995.","DOI":"10.1007\/BF01094342"},{"key":"2023033120444148615_j_itit-2020-0009_ref_004_w2aab3b7d555b1b6b1ab2ab4Aa","doi-asserted-by":"crossref","unstructured":"Felice Balarin, Luciano Lavagno, Praveen Murthy, Alberto Sangiovanni-Vincentelli, et al. Scheduling for Embedded Real-time Systems. IEEE Design & Test of Computers, 15(1):71\u201382, 1998.","DOI":"10.1109\/54.655185"},{"key":"2023033120444148615_j_itit-2020-0009_ref_005_w2aab3b7d555b1b6b1ab2ab5Aa","doi-asserted-by":"crossref","unstructured":"Dominique Bertrand, S\u00e9bastien Faucou, and Yvon Trinquet. An Analysis of the AUTOSAR OS Timing Protection Mechanism. In IEEE Conference on Emerging Technologies & Factory Automation, 2009 (ETFA 2009), pages 1\u20138. IEEE, 2009.","DOI":"10.1109\/ETFA.2009.5347159"},{"key":"2023033120444148615_j_itit-2020-0009_ref_006_w2aab3b7d555b1b6b1ab2ab6Aa","unstructured":"R.\u2009I. Davis, K.\u2009W. Tindell, and A. Burns. Scheduling Slack Time in Fixed Priority Pre-emptive Systems. In Real-Time Systems Symposium, 1993, Proceedings, pages 222\u2013231, Dec. 1993."},{"key":"2023033120444148615_j_itit-2020-0009_ref_007_w2aab3b7d555b1b6b1ab2ab7Aa","doi-asserted-by":"crossref","unstructured":"Mohammad Hamad, Zain A.\u2009H. Hammadeh, Selma Saidi, Vassilis Prevelakis, and Rolf Ernst. Prediction of Abnormal Temporal Behavior in Real-time Systems. In Proceedings of the 33rd Annual ACM Symposium on Applied Computing, pages 359\u2013367, 2018.","DOI":"10.1145\/3167132.3167172"},{"key":"2023033120444148615_j_itit-2020-0009_ref_008_w2aab3b7d555b1b6b1ab2ab8Aa","doi-asserted-by":"crossref","unstructured":"Mohammad Hamad and Vassilis Prevelakis. Implementation and Performance Evaluation of Embedded IPsec in Microkernel OS. In 2015 World Symposium on Computer Networks and Information Security (WSCNIS), pages 1\u20137. IEEE, 2015.","DOI":"10.1109\/WSCNIS.2015.7368294"},{"key":"2023033120444148615_j_itit-2020-0009_ref_009_w2aab3b7d555b1b6b1ab2ab9Aa","unstructured":"Mohammad Hamad, Johannes Schlatow, Vassilis Prevelakis, and Rolf Ernst. A Communication Framework for Distributed Access Control in Microkernel-based Systems. In 12th Annual Workshop on Operating Systems Platforms for Embedded Real-Time Applications (OSPERT16), 2016."},{"key":"2023033120444148615_j_itit-2020-0009_ref_010_w2aab3b7d555b1b6b1ab2ac10Aa","doi-asserted-by":"crossref","unstructured":"Mohammad Hamad, Marinos Tsantekidis, and Vassilis Prevelakis. Red-Zone: Towards an Intrusion Response Framework for Intra-vehicle System. In Proceedings of the 5th International Conference on Vehicle Technology and Intelligent Transport Systems, VEHITS 2019, Heraklion, Crete, Greece, May 3\u20135, 2019, pages 148\u2013158. SciTePress, 2019.","DOI":"10.5220\/0007715201480158"},{"key":"2023033120444148615_j_itit-2020-0009_ref_011_w2aab3b7d555b1b6b1ab2ac11Aa","doi-asserted-by":"crossref","unstructured":"Moncef Hamdaoui and Parameswaran Ramanathan. A Dynamic Priority Assignement Technique for Streams with (m, k)-Firm Deadlines. IEEE Trans. Computers, 44(12):1443\u20131451, 1995.","DOI":"10.1109\/12.477249"},{"key":"2023033120444148615_j_itit-2020-0009_ref_012_w2aab3b7d555b1b6b1ab2ac12Aa","doi-asserted-by":"crossref","unstructured":"Hans Hansson, Mikael \u00c5kerholm, Ivica Crnkovic, and Martin Torngren. SaveCCM-a Component Model for Safety-critical Real-time Systems. In Proceedings. 30th Euromicro Conference, 2004, pages 627\u2013635. IEEE, 2004.","DOI":"10.1109\/EURMIC.2004.1333431"},{"key":"2023033120444148615_j_itit-2020-0009_ref_013_w2aab3b7d555b1b6b1ab2ac13Aa","unstructured":"Grant A. Jacoby, Randy Marchany, and Nathaniel J. Davis. Battery-based Intrusion Detection a First Line of Defense. In Proceedings from the Fifth Annual IEEE SMC Information Assurance Workshop, 2004, pages 272\u2013279. IEEE, 2004."},{"key":"2023033120444148615_j_itit-2020-0009_ref_014_w2aab3b7d555b1b6b1ab2ac14Aa","doi-asserted-by":"crossref","unstructured":"Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak Patel, Tadayoshi Kohno, Stephen Checkoway, Damon Mccoy, Brian Kantor, Danny Anderson, Hovav Shacham, and Stefan Savage. Experimental Security Analysis of a Modern Automobile. In Proceedings of IEEE Symposium on Security and Privacy, 2010.","DOI":"10.1109\/SP.2010.34"},{"key":"2023033120444148615_j_itit-2020-0009_ref_015_w2aab3b7d555b1b6b1ab2ac15Aa","doi-asserted-by":"crossref","unstructured":"Krutartha Patel and Sri Parameswaran. SHIELD: a Software Hardware Design Methodology for Security and Reliability of MPSoCs. In 45th ACM\/IEEE Design Automation Conference, 2008 (DAC 2008), pages 858\u2013861. IEEE, 2008.","DOI":"10.1145\/1391469.1391686"},{"key":"2023033120444148615_j_itit-2020-0009_ref_016_w2aab3b7d555b1b6b1ab2ac16Aa","unstructured":"Martin Pohlack, Bj\u00f6rn D\u00f6bel, and Adam Lackorzynski. Towards Runtime Monitoring in Real-time Systems."},{"key":"2023033120444148615_j_itit-2020-0009_ref_017_w2aab3b7d555b1b6b1ab2ac17Aa","doi-asserted-by":"crossref","unstructured":"Sophie Quinton, Matthias Hanke, and Rolf Ernst. Formal Analysis of Sporadic Overload in Real-time Systems. In 2012 Design, Automation & Test in Europe Conference & Exhibition (DATE 2012), Dresden, Germany, March 12\u201316, 2012, pages 515\u2013520, 2012.","DOI":"10.1109\/DATE.2012.6176523"},{"key":"2023033120444148615_j_itit-2020-0009_ref_018_w2aab3b7d555b1b6b1ab2ac18Aa","doi-asserted-by":"crossref","unstructured":"Lui Sha, Tarek Abdelzaher, Karl-Erik \u00c5rz\u00e9n, Anton Cervin, Theodore Baker, Alan Burns, Giorgio Buttazzo, Marco Caccamo, John Lehoczky, and Aloysius K. Mok. Real Time Scheduling Theory: A Historical Perspective. Real-Time Systems, 28(2-3):101\u2013155, 2004.","DOI":"10.1023\/B:TIME.0000045315.61234.1e"},{"key":"2023033120444148615_j_itit-2020-0009_ref_019_w2aab3b7d555b1b6b1ab2ac19Aa","doi-asserted-by":"crossref","unstructured":"Hyun Min Song, Ha Rang Kim, and Huy Kang Kim. Intrusion Detection System Based on the Analysis of Time Intervals of CAN Messages for In-vehicle Network. In 2016 International Conference on Information Networking (ICOIN), pages 63\u201368. IEEE, 2016.","DOI":"10.1109\/ICOIN.2016.7427089"},{"key":"2023033120444148615_j_itit-2020-0009_ref_020_w2aab3b7d555b1b6b1ab2ac20Aa","doi-asserted-by":"crossref","unstructured":"John A. Stankovic and Krithi Ramamritham. What is Predictability for Real-time Systems?, 1990.","DOI":"10.1007\/BF01995673"},{"key":"2023033120444148615_j_itit-2020-0009_ref_021_w2aab3b7d555b1b6b1ab2ac21Aa","doi-asserted-by":"crossref","unstructured":"A. Taylor, N. Japkowicz, and S. Leblanc. Frequency-based Anomaly Detection for the Automotive CAN Bus. In 2015 World Congress on Industrial Control Systems Security (WCICSS), pages 45\u201349, Dec. 2015, doi:10.1109\/WCICSS.2015.7420322.","DOI":"10.1109\/WCICSS.2015.7420322"},{"key":"2023033120444148615_j_itit-2020-0009_ref_022_w2aab3b7d555b1b6b1ab2ac22Aa","doi-asserted-by":"crossref","unstructured":"Hideyuki Tokuda, Makoto Kotera, and Clifford Mercer. A Real-time Monitor for a Distributed Real-time Operating System. In Proceedings of the 1988 ACM SIGPLAN and SIGOPS Workshop on Parallel and Distributed Debugging, pages 68\u201377, 1988.","DOI":"10.1145\/69215.69222"},{"key":"2023033120444148615_j_itit-2020-0009_ref_023_w2aab3b7d555b1b6b1ab2ac23Aa","doi-asserted-by":"crossref","unstructured":"Man-Ki Yoon, Sibin Mohan, Jaesik Choi, Mihai Christodorescu, and Lui Sha. Learning Execution Contexts from System Call Distribution for Anomaly Detection in Smart Embedded System. In Proceedings of the Second International Conference on Internet-of-Things Design and Implementation, pages 191\u2013196. ACM, 2017.","DOI":"10.1145\/3054977.3054999"},{"key":"2023033120444148615_j_itit-2020-0009_ref_024_w2aab3b7d555b1b6b1ab2ac24Aa","doi-asserted-by":"crossref","unstructured":"Clinton Young, Habeeb Olufowobi, Gedare Bloom, and Joseph Zambreno. Automotive Intrusion Detection Based on Constant CAN Message Frequencies Across Vehicle Driving Modes. In ACM Workshop on Automotive Cybersecurity (AutoSec \u201919), 2019.","DOI":"10.1145\/3309171.3309179"},{"key":"2023033120444148615_j_itit-2020-0009_ref_025_w2aab3b7d555b1b6b1ab2ac25Aa","doi-asserted-by":"crossref","unstructured":"Christopher Zimmer, Balasubramany Bhat, Frank Mueller, and Sibin Mohan. Intrusion Detection for CPS Real-time Controllers. In Cyber Physical Systems Approach to Smart Electric Power Grid, pages 329\u2013358. Springer, 2015.","DOI":"10.1007\/978-3-662-45928-7_12"}],"container-title":["it - Information Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.degruyter.com\/view\/journals\/itit\/62\/5-6\/article-p227.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2020-0009\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2020-0009\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T10:11:45Z","timestamp":1680343905000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2020-0009\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,1]]},"references-count":25,"journal-issue":{"issue":"5-6","published-online":{"date-parts":[[2020,10,7]]},"published-print":{"date-parts":[[2020,12,16]]}},"alternative-id":["10.1515\/itit-2020-0009"],"URL":"https:\/\/doi.org\/10.1515\/itit-2020-0009","relation":{},"ISSN":["2196-7032","1611-2776"],"issn-type":[{"type":"electronic","value":"2196-7032"},{"type":"print","value":"1611-2776"}],"subject":[],"published":{"date-parts":[[2020,12,1]]}}}