PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 24, 2026Electronics0 citationsOpen Access

A Two-Stage Hybrid Intrusion Detection System for CAN Bus Based on Statistical Thresholds and Random Forest Classifiers

View Full Paper
LFLuis FerreiraUniversity of Trás-os-Montes and Alto DouroRARafael AbreuUniversity of Trás-os-Montes and Alto DouroFBFrederico BrancoUniversity of Trás-os-Montes and Alto Douro

Key Points

  • To develop a two-stage intrusion detection system for CAN Bus that effectively identifies injection attacks.
  • Developed a structured feature space from CAN traffic utilizing message offsets and inter-message intervals.
  • Applied unsupervised z-score statistical thresholding in the first stage and binary Random Forest classifiers in the second stage.
  • Assessed classifier performance based on F1-scores for different attack types with real-time hardware profiling.
  • System filtered 97% of legitimate traffic successfully.
  • Achieved F1-scores of 0.96 for Fuzzy, 0.77 for DoS, and 0.79 for Impersonation attacks.
  • Inferred latency of ∼0.018 ms with a computational footprint of 8.8–19.2 MB.

Abstract

This study proposes a two-stage Intrusion Detection System (IDS) for Controller Area Networks (CAN) that leverages protocol-specific timing characteristics. Modern vehicular networks are vulnerable to injection attacks due to the CAN protocol’s lack of built-in authentication. Our methodology transforms raw CAN traffic into a structured feature space consisting of CAN IDs, message offsets, and inter-message intervals derived from the CAN Remote Frame request–response mechanism. The first stage applies unsupervised z-score statistical thresholding, requiring no labeled attack data. The second stage employs three independent binary Random Forest (RF) classifiers for precise characterization. Individual classifiers achieve F1-scores of 0.96 (Fuzzy), 0.77 (DoS), and 0.79 (Impersonation). In the integrated end-to-end pipeline, while the system effectively filters 97% of legitimate traffic, a performance stratification is observed: high detection is maintained for timing-disruptive attacks (Fuzzy), whereas timing-preserving attacks (DoS, Impersonation) exhibit lower recall due to the restrictive nature of the timing-only first-stage gating mechanism. Hardware profiling confirmed an inference latency of ∼0.018 ms and footprint of 8.8–19.2 MB, offering a deployable, computationally efficient defense for legacy automotive environments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Ferreira et al. (2026) studied this question.

synapsesocial.com/papers/6a12969048a0ea16656737ddhttps://doi.org/10.3390/electronics15112239
Ask AI
Helpful
Bookmark
Share
View Full Paper