Preprint
Article

Enhancing Automotive Intrusion Detection Systems with CHERI-Based Memory Protection

Altmetrics

Downloads

6

Views

7

Comments

0

Submitted:

19 December 2024

Posted:

21 December 2024

You are already at the latest version

Alerts
Abstract
The automotive sector is changing fast with more integration of advanced communication technologies and further connectivity. The modern vehicle is already a collection of diverse Electronic Control Units (ECU) communicating over interconnected networks that decide critical functionalities such as engine control, braking, and entertainment. However, this increasing complexity also introduces major cybersecurity risks, including network vulnerabilities like IP spoofing, message replay, and denial-of-service(DoS) attacks, besides software vulnerabilities due to coding errors in unsafe languages like C/C++. These are serious threats to vehicle operational reliability, passenger safety, and data integrity, making robust automotive security a critical concern. This paper explores the application of CHERI(Capability Hardware Enhanced RISC Instructions) in enhancing the security of Intrusion Detection Systems(IDS) in automotive networks. CHERI introduces fine-grained memory protection mechanisms that mitigate software vulnerabilities by enforcing spatial memory safety and preventing unauthorized access to critical data. Moreover, CHERI secures IDS rule configurations from network-based threats, such as manipulation of rules and spoofing attacks, by utilizing strict memory bounds and capability-based access controls. This work experimentally demonstrates that CHERI-enhanced IDSs are highly effective in identifying and mitigating spoofing and IDS rule manipulation attacks, ensuring the integrity of rules even against attackers using forged traffic with legitimate-looking source IP addresses. The results highlight CHERI’s hardware-enforced security model as a robust solution for preventing network and software-level exploits without compromising performance while maintaining compatibility with automotive-friendly programming languages like C/C++. This study underscores the critical importance of integrating CHERI and other hardware-based security frameworks into connected and autonomous vehicles to address emerging cybersecurity challenges and build a safer automotive ecosystem.
Keywords: 
Subject: Computer Science and Mathematics  -   Security Systems
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

© 2024 MDPI (Basel, Switzerland) unless otherwise stated