Trusted CAN Identifier Inventory
An inventory of approved CAN message identifiers is established.
Define which CAN message types are authorized within the industrial communication environment.
Modern Industrial IoT, automotive, robotics, and Industry 4.0 environments use Controller Area Network (CAN) communication to exchange messages between controllers, sensors, actuators, gateways, and embedded devices.
CAN communication is designed for efficient and reliable message exchange between connected devices. However, traditional CAN communication does not inherently provide strong source authentication for individual messages. An unauthorized device or compromised gateway with access to the CAN network may therefore attempt to inject unauthorized CAN frames.
A CAN Bus Injection Attack can introduce unauthorized messages into the communication channel. Depending on the affected message identifier and system architecture, injected frames may interfere with legitimate device communication or cause unauthorized control actions.
In this use case, a controlled CAN-based Industrial IoT environment is created using Linux SocketCAN and a virtual CAN interface. The virtual CAN environment represents communication between industrial controllers, sensors, actuators, and an IoT gateway without requiring physical CAN hardware.
A legitimate CAN communication baseline is established by identifying approved CAN identifiers and normal message rates.
A controlled CAN Bus Injection Attack is then simulated by generating unauthorized CAN frames using the laboratory environment. No physical industrial equipment or real vehicle-control system is affected.
can-utils and python-can are used to generate and analyze controlled CAN traffic. SavvyCAN provides additional CAN traffic visualization and analysis.
The monitoring mechanism validates CAN message identifiers against an approved allowlist and analyzes message frequency to identify abnormal injection activity.
When unauthorized CAN identifiers or abnormal message rates are detected, a security alert is generated and the affected laboratory CAN interface or source is isolated according to the containment policy.
The legitimate CAN communication is then validated to confirm that authorized industrial messages continue to operate normally.
The complete defensive workflow is: Industrial IoT CAN Network → Trusted CAN Message Baseline → CAN Bus Injection → CAN Identifier Validation → Message-Rate Anomaly Detection → Security Alert → Unauthorized Source Containment → Trusted CAN Communication Validation.
Controller Area Network (CAN) is a communication protocol used by embedded and industrial systems to exchange messages between connected controllers and devices. CAN frames contain message identifiers and data fields that are interpreted by participating devices according to the system's communication design.
An unauthorized device or compromised gateway connected to a CAN network may attempt to transmit additional CAN frames. Because CAN communication does not inherently authenticate the physical sender of every message, a receiving device may process an injected frame if its identifier and message structure appear valid. If CAN traffic is not continuously monitored, unauthorized frames may be difficult to distinguish from legitimate industrial communication.
The security problem is therefore:
The proposed solution introduces CAN message allowlisting, message-rate baseline monitoring, CAN traffic analysis, anomaly detection, security alerting, and unauthorized-source containment.
The controlled attack scenario simulates unauthorized CAN frames being introduced into a laboratory CAN network. A legitimate CAN communication baseline is first established using approved message identifiers and normal message frequencies. A controlled laboratory source then generates additional CAN frames that do not belong to the trusted communication baseline. The objective is to determine whether the security controls can identify unauthorized CAN identifiers or abnormal message transmission rates.
The primary security concept is CAN Message Integrity and Behavioral Monitoring.
A trusted baseline is established containing approved CAN message identifiers and their expected communication behavior. CAN traffic is continuously analyzed to determine whether observed frames conform to the established communication policy. A legitimate CAN message should match an approved identifier and remain within the expected communication behavior. An unknown CAN identifier or significant deviation from the normal message-rate baseline should be treated as suspicious and investigated.
The secure processing flow is:
An inventory of approved CAN message identifiers is established.
Define which CAN message types are authorized within the industrial communication environment.
Observed CAN identifiers are compared against the approved identifier list.
Detect unauthorized CAN message types.
Normal message frequencies are established for approved CAN identifiers.
Determine expected communication behavior.
Observed CAN message frequency is compared against the established baseline.
Detect abnormal bursts or excessive CAN frame transmission.
CAN frames are continuously observed on the laboratory interface.
Provide visibility into industrial CAN communication.
The timing relationship between CAN frames is analyzed.
Identify unexpected changes in normal CAN communication behavior.
Unexpected CAN traffic sources or interfaces are identified where the laboratory architecture provides source information.
Detect unauthorized participants in the controlled CAN environment.
A security alert is generated when the configured CAN injection-detection condition is satisfied.
Provide immediate visibility into suspicious CAN communication.
The identified laboratory CAN source or interface can be restricted according to the containment policy.
Prevent continued unauthorized CAN traffic.
Legitimate CAN traffic is revalidated after containment.
Ensure that authorized industrial communication remains operational.
SocketCAN is the Linux kernel CAN networking framework used to create and manage the controlled CAN communication environment.
can-utils is an open-source collection of Linux CAN utilities used to generate, capture, inspect, and analyze CAN frames.
python-can is used to programmatically generate and monitor CAN messages.
SavvyCAN is used to visualize and analyze CAN communication.
iproute2 is used to configure and inspect the Linux CAN networking environment.
Ubuntu provides the controlled Industrial IoT security environment.
Kali Linux provides the controlled security-assessment environment.
VirtualBox provides the isolated laboratory infrastructure.