MIL-STD-1553 Intrusion Detection using CUSUM Algorithm
Date
2022-04-29
Authors
Sachdev, Krunal
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
MIL-STD-1553 is a military standard developed by the US department of defense for communication among military avionic platforms (e.g., F-35 and F-16). It has been widely accepted worldwide for more than five decades and is used in many applications other than military avionics. It follows a strict and deterministic procedure for communication among its components. However, research has suggested that it has many vulnerabilities associated with it that can be exploited to carry a range of attacks on it. And since numerous applications make use of this standard, it is crucial to protect MIL-STD-1553 networks. This project presents an unsupervised anomaly detection scheme using the CUSUM algorithm for the MIL-STD-1553 protocol. A dataset was collected in the ISOT lab by executing six attack vectors on a simulated MIL-STD-1553 network. We leverage the time-based properties of the communication bus to extract a set of relevant features that are fed to the CUSUM algorithm for detection. The experimental evaluation of the proposed detector using the aforementioned dataset yielded promising results, which are very encouraging considering the unsupervised nature of the underlying algorithm.
Description
Keywords
CUSUM, Intrusion Detection System, MIL-STD-1553, Unsupervised machine learning