<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Research  of  the  model  for  detecting  UMV  interfaces  vulnerabilities based on information criterion </article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexey Bryukhovetskiy</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vera Miryanova</string-name>
          <email>VNMiryanova@sevsu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmitriy Moiseev</string-name>
          <email>dmitriymoiseev@mail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Sevastopol state university</institution>
          ,
          <addr-line>33 Universitetskaya str., Sevastopol, 299053</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>162</fpage>
      <lpage>168</lpage>
      <abstract>
        <p>   An approach related to the development of methods for ensuring unmanned vehicles computer security is considered. The approach is based on the statistical distance estimation between the probability distributions of a random variable. The Jensen-Shannon information criterion, which provides a symmetric version of the Kullback-Leibler divergence, is proposed as an evaluation criterion. Vulnerability detection is performed on the basis of processing the UMV resources state values. The features of UMV state monitoring give rise to new problems characterized by data flows with variable intensity, heterogeneous information flows in conditions of a lack of a priori information and noisy data. When solving this problem, there are problems of big data processing: high computational complexity due to the processing of huge data amounts; high dynamics of controlled objects; non-stationary information situation of the objects state and the environment; ensuring high speed of query processing; providing metrics of information resources in real time.</p>
      </abstract>
      <kwd-group>
        <kwd> 1  resources unmanned vehicles</kwd>
        <kwd>detection of vulnerabilities</kwd>
        <kwd>information criterion</kwd>
        <kwd>statistical distance</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction </title>
      <p>
        Car interfaces (CAN, LIN, FlexRay, and MOST) are vulnerable to various cybersecurity attacks.
Through the on-board diagnostic (OBD) port or USB port, attackers can stop the engine or affect the
vehicle's braking system and cause an accident [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. The "replay" attack and the "simulation" attack on
the CAN bus are described in [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. The authors [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] simulated a "Sybil" spoofing attack on the FlexRay
bus.
      </p>
      <p>
        Each incident that is recorded in the UMV is characterized by an entry point that the attacker uses
to perform the attack. Open ports are the main vulnerability point through which viruses penetrate and
spread. A port in network technologies refers to a virtual "door" that can be accessed. To fix the
vulnerability, identify suspicious processes that use ports [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Therefore, controlling them is a top
priority for security.
      </p>
      <p>
        Since different technologies are used in vehicles, therefore, there are relatively many interfaces for
both internal and external communication with the UMV. Due to the fact that the complexity of
interface technologies varies widely, therefore, knowledge of these technologies is necessary to
evaluate the methods of implementing attacks and, consequently, to determine the feasibility of attacks.
This is especially important also for assessing the possible damage caused by the implementation of the
attack [
        <xref ref-type="bibr" rid="ref5 ref6 ref7 ref8 ref9">5 - 13</xref>
        ].
      </p>
    </sec>
    <sec id="sec-2">
      <title>2. Problem statement </title>
      <p>
        The proposed method is intended for detecting vulnerabilities of UMV interfaces. The approach is
based on the estimation of the statistical distance between the probability distributions of a random
variable over different time intervals. The Jensen-Shannon information criterion [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], which provides a
symmetric and normalized version of the Kullback-Leibler divergence, is proposed as an evaluation
criterion. Vulnerability detection is carried out on the basis of processing UMV resources state values,
such as, communication channel, processor and memory. The monitored features include: resource
loading and the rate of change in resource loading.
      </p>
      <p>Let’s introduce the notation DKL (P, Q) to calculate the Kullback-Leibler divergence between two
distributions Q(x) and P(x). Then the divergence is defined as</p>
      <p>DKL (P, Q) = Pi x * (log (Рi (x) / Qi(x)))
It should be noted that the KL divergence value is not symmetric:</p>
      <p>DKL (P, Q) ≠ DKL (Q, P)</p>
      <p>Therefore, it is proposed to use the Jensen-Shannon – JS divergence, which allows us to estimate
the discrepancies between the two probability distributions. In this case, the divergence is used to
calculate the normalized estimate, which is symmetric. This means that the divergence of P from Q is
the same as Q from P, i.e.</p>
      <p>
        JS (P, Q) = JS (Q, P)
The JS divergence can be defined as follows [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]:
      </p>
      <p>JS (P, Q) = 1/2 * DKL (P, M) + 1/2 * DKL (Q, M)
where the distribution М is calculated as</p>
      <p>M = 1/2 * (P + Q).</p>
      <p>The Jensen — Shannon divergence is limited to the value of one for two probability distributions if
the Kullback-Leibler divergence uses the base 2 logarithm:</p>
      <p>0 &lt;= JS (P, Q) &lt;= 1</p>
      <p>The main advantage of the proposed method is that it provides a smoothed and normalized version
of the Kullback divergence with estimates from 0 (there is no discrepancy between the distributions)
up to 1 (maximum different distributions).</p>
      <p>The Jensen — Shannon divergence of the distribution P with respect to Q can be estimated as:</p>
      <p>JS (P, Q) &lt;= Z – no divergence,</p>
      <p>JS (P, Q) &gt; Z – observing sample divergence,
where Z is the limit value of the distance that depends on the criticality of the object parameter value
and is set by the expert. Then the null hypothesis H0 holds for JS (P, Q) &lt;= Z – no divergence. Otherwise,
the hypothesis H1 is accepted there is a qualitative change in the information state of the controlled
object parameter.</p>
      <p>In order to compare the estimates of divergences between the two probability distributions, a model
for detecting changes in resource state was studied. The Jensen — Shannon distance is used as an
information measure. We introduce the concept of the estimation zone of the divergence value. For the
sake of certainty, we will consider the following boundaries of the recognition zones: {0, Z1, Z2, 1}.
Then the zones are defined by the following intervals:</p>
      <p>[0; Z1), [Z1; Z2), [Z2;1].</p>
      <p>Depending on the belonging of the current distance value JS (P, Q) ∈ Zi (i=1, k) we will classify
the following object information states:
0 &lt;= JS (P, Q) &lt;Z1 – no divergence (normal state of the object),</p>
      <p>Z1&lt;= JS (P, Q) &lt;Z2 – unstable region (precritical state of the object),</p>
      <p>Z2&lt;= JS (P, Q) &lt;=1 – observation of divergence (critical condition of the object).</p>
      <p>In general, the number of Zi recognition zones is determined by the expert and depends on the object
criticality, the dynamics of its state, the requirements for the quality of its characteristics control,
possible losses during control, etc.</p>
      <p>The proposed model includes the following main modules:
 generating random samples according to a given distribution law with a priori specified
parameters,
 setting input data,
 setting the information criterion,
 training and configuring model parameters,
 processing of statistical data,
 plotting histograms,
 acceptance of the hypothesis H0 on the samples homogeneity or an alternative hypothesis H1,
confirming the samples heterogeneity.</p>
      <p>The problem of estimating the samples divergence is solved according to the following algorithmic
scheme:
 Input data is set: V – sample size, k – number of histogram intervals, [Zi; Zi+1] – width of
recognition zones, cr – information criterion.
 Sets the critical areas of the null hypothesis test criteria-areas of no divergences / unstable areas
of divergences / areas of divergences.
 Samples X of a given volume V are generated from a general population having a given
distribution law.
 Histograms of the distribution of the values of the controlled parameter are formed for two
given samples P and Q.
 The distance value is calculated as the square root of the information measure JS (P, Q) and its
belonging to the specified recognition zones is determined.</p>
      <p>The above steps are repeated for other values of the input data and a conclusion is made about the
evaluation of the homogeneity of other pairs of samples P and Q.</p>
      <p>In accordance with the tasks set, experiments were conducted, during which the influence of a
number of parameter values on changes in the state of resources was determined: the volume of samples
- V, the number of histogram intervals– k, the width of the zones [Zi; Zi+1] of the resource state
assessment. The simulation results are presented below.</p>
      <p>Research of the impact of sample size – V. Set: resource state classification zones [Zi;Zi+1] for three
states that differ in the width of the intervals. The intervals number k=3. We compared the estimates of
discrepancies for the distributions P and Q for cases where the boundaries of the recognition zones
differed slightly (homogeneous) and significantly (heterogeneous). The following recognition zone
boundaries were set:
 intervals-1 {0; 0.50; 0.80; 1},
 intervals -2 {0; 0.40; 0.60; 1},
 intervals -3 {0; 0.30; 0.70; 1},
 intervals -4 {0; 0.10; 0.50; 1}.</p>
      <p>The width of the intervals-1, 2, 3 differs slightly from each other, and the width of the intervals-4
differs significantly from the rest. Figure 1: shows the values of the distance JS (P, Q) when comparing
the sample distributions for different values of the intervals: exp 1-2, exp 1-4 at V=30.</p>
      <p>D i s t a n c e J S ( P , Q ) w h e n e s t i m a t i n g t h e d i s t r i b u t i o n s d i v e r g e n s e :</p>
      <p>k = 3 / V = 3 0
0,6
)0,4
Q
,
P
(
JS0,2
0
1
2
3
4
5
6
7
8
9</p>
      <p>In 20 experiments, when comparing the intervals 1-2-1-1-2, the maximum distance was 0.32, and
the minimum was 0.06, while in experiments 1-4 it was 0.58 and 0.33, respectively. Similar
experiments were performed when estimating discrepancies for samples V=40, 60, and 100.</p>
      <p>Figure 2: shows the values of the distance JS (P, Q) when comparing the sample distributions for
different intervals: exp 1-2, exp 2-3, exp 1-4 at V=100.</p>
      <p>D i s t a n c e J S ( P , Q ) w h e n e s t i m a t i n g t h e d i v e r g e n c e o f</p>
      <p>d i s t r i b u t i o n s : k = 3 / V = 1 0 0
0,6
0,5
)
Q
,
(P0,4
S
J
0,3
0,2</p>
      <p>N
O
I
ITA0,07
V
E
 D0,05
D
R
AD0,03
N
A
T
S
эксп 1‐2
эксп 2‐3
эксп 1‐4</p>
      <p>In 20 experiments exp1-2, exp2-3, the maximum distance was 0.28, and the minimum distance was
0.12, while in experiments 1-4 it was 0.51 and 0.35, respectively. Thus, as the sample size increases,
we observe an increase in the distance between homogeneous and inhomogeneous distributions. In this
case, max (JS (P, Q)) =0.28 for homogeneous distributions 1-2, 2-3 is less than the minimum distance
for inhomogeneous distributions 1-4: min (JS (P, Q)) =0.35. This fact indicates an increase in the
reliability of the classification of object states and a decrease in the number of errors of the first and
second kind.</p>
      <p>Figure 3: shows the dependence of the mean square deviation of the co-ordinate distance JS (P, Q)
between homogeneous 1-2, 2-3 and inhomogeneous 1-4 distributions, depending on the sample size at
k=3. The figure shows that there is a tendency to decrease the value of the standard deviation from the
sample size in all experiments.</p>
      <p>The value of the standard deviation of the distance JS (P,Q) between
homogeneous and inhomogeneous distributions depending on the sample</p>
      <p>size at k=3</p>
      <p>This trend is observed in other experiments when the number of intervals increases. Similar
experiments were performed when estimating discrepancies for samples V=30, 40, 60, and 100 and the
number of intervals k=5, 7, and others</p>
    </sec>
    <sec id="sec-3">
      <title>3. Conclusions  </title>
      <p>The results obtained allow us to state that the application of the model based on the Jensen —
Shannon information measure provides greater statistical stability in assessing changes in the UMV
resources state with an increase in the samples volume and the intervals number. In the conducted
experiments, the best estimates were obtained at V=100, K=5, and the worst at V=30, k=3. With a small
Figure 4: Distance JS (P, Q) when estimating  the divergence  of distributions exp 1‐2,  exp 1‐3: k=4 / 
V=100 
Table 1 
Distance values JS (P, Q) for k=4 and V=30, 100  
number of intervals and a small volume of samples, there were situations when individual intervals of
the histogram contained zero values.</p>
      <p>Thus, the obtained results of the study of the model based on the Jensen-Shannon information
measure confirm the facts of the presence of perturbations in the assessment of changes in the state of
objects. The main advantages of the proposed method for assessing the UMV resources state are:
sensitivity to changes in the resources state, low computational complexity, adaptability to external
influences. It is the assessment of the resources state heterogeneity over different time periods that can
be used to detect external influences on the UMV.</p>
      <p>Conducted to date in the field of vehicle protection has solved a number of safety problems and
offered a many solutions. However, there are still open problems that require further study. The need
to solve problems that ensure the security of the critical information infrastructure in the "smart city" is
due not only to the growth trends of traffic flows, but also to significant changes in the digital
technologies field used on vehicles, when interaction with the environment is carried out through the
network through interfaces: V2V, V2X, V2P ,V2G, V2D. The article considers a simulation model that
allows you to simulate the changes dynamics in the objects states and can be considered as one of the
possible approaches to improve the methods of protecting critical objects, in particular, intelligent
vehicles in VANET networks.</p>
      <p>
        Currently, the process of anomalies rapid detection in the monitoring data of critical infrastructure
objects is a complex, time-consuming and difficult to formalize task. Intrusion detection systems (IDS)
are the most effective counter-measure and the most reliable approach to ensure the protection of
automotive networks or traditional computer networks [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. In complex information systems for
monitoring critical objects, a decision-making support mechanism is implemented to identify the
control object critical state. The combined use of operational monitoring tools, simulation modeling,
and probabilistic models allows us to predict the dynamics of state changes and proactively perform
corrective actions, thereby preventing the emergencies occurrence.
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Acknowledgements </title>
      <p>The research was carried out with the financial support of the RFBR in the framework of scientific
projects № 19-29-06015 and № 19-29-06023.</p>
    </sec>
    <sec id="sec-5">
      <title>5. References </title>
      <p>[10] L. Kleinrock, Queueing theory / from Engl I I Grushko / V I Neiman. M Mashinostroenie, p. 432,
1979.
[11] S. A. Aivazian, V. S. Mhitaryan, Applied statistics and fundamentals of econometrics. M: High</p>
      <p>School, Publ «Yunity», p. 1000, 1998.
[12] A. Skatkov, A. Bryukhovetskiy, V. Shevchenko, Monitoring of qualitative changes of network
traffic states based on the heteroscedasticity effect, Application of Information and
Communication Technologies, AICT 2016 - Conference Proceedings, Baku (2016) 7991765.
[13] A. V. Skatkov, A. A. Bryukhovetskiy, D. V. Moiseev, Intelligent monitoring system for solving
large-scale scientific problems in cloud computing environments, Information and control systems
2(87) (2017) 19–25.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>L.</given-names>
            <surname>Pan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Zheng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Chen</surname>
          </string-name>
          , et al.,
          <article-title>Cyber security attacks to modern vehicular systems</article-title>
          ,
          <source>Journal of Information Security and Applications</source>
          <volume>36</volume>
          (
          <year>2017</year>
          )
          <fpage>90</fpage>
          -
          <lpage>100</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Markovitz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Wool</surname>
          </string-name>
          ,
          <article-title>Field classification, modeling and anomaly detection in unknown can bus networks</article-title>
          ,
          <source>Vehicular Communications</source>
          <volume>9</volume>
          (
          <year>2017</year>
          )
          <fpage>43</fpage>
          -
          <lpage>52</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>D. K.</given-names>
            <surname>Nilsson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>U. E.</given-names>
            <surname>Larson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Picasso</surname>
          </string-name>
          , et al.,
          <article-title>A first simulation of attacks in the automotive network communications protocol flexray</article-title>
          ,
          <source>Proceedings of the International Workshop on Computational Intelligence in Security for Information Systems CISIS'08</source>
          . Springer (
          <year>2009</year>
          )
          <fpage>84</fpage>
          -
          <lpage>91</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <article-title>[4] Тop 20 and 200 most scanned ports in the cybersecurity industry, SecurityTrails blog (</article-title>
          <year>2019</year>
          <article-title>) securitytrails team</article-title>
          . https://securitytrails.com/blog/top-scanned-ports.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S.</given-names>
            <surname>Checkoway</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>McCoy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Kantor</surname>
          </string-name>
          , et al.,
          <article-title>Comprehensive Experimental Analyses of Automotive Attack Surfaces</article-title>
          . https://web.archive.org/web/20150221064614/http://www.autose c.org/pubs/cars-usenixsec2011.
          <fpage>pdf</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>F.</given-names>
            <surname>Nielsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Nock</surname>
          </string-name>
          ,
          <article-title>Total Jensen divergences: definition, properties and clustering</article-title>
          ,
          <source>In 2015 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)</source>
          <year>2016</year>
          -
          <fpage>2020</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>I.</given-names>
            <surname>Butun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. D.</given-names>
            <surname>Morgera</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Sankar</surname>
          </string-name>
          ,
          <article-title>A survey of intrusion detection systems in wireless sensor networks</article-title>
          ,
          <source>IEEE communications surveys &amp; tutorials 16(1)</source>
          (
          <year>2014</year>
          )
          <fpage>266</fpage>
          -
          <lpage>282</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Mohammed</given-names>
            <surname>Ali Hezam Al Junaid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Syed</surname>
          </string-name>
          , et al.,
          <article-title>Classification of Security Attacks in VANET: A Review of Requirements and Perspectives</article-title>
          ,
          <source>MATEC Web of Conferences 150</source>
          <volume>06038</volume>
          (
          <year>2018</year>
          ), MUCET 201. https://doi.org/10.1051/matecconf/201815006038.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>V. D.</given-names>
            <surname>Boev</surname>
          </string-name>
          ,
          <article-title>Conceptual system design in Anylogic 7</article-title>
          and
          <string-name>
            <given-names>GPSS</given-names>
            <surname>World</surname>
          </string-name>
          , Moscow, NOI, p.
          <fpage>556</fpage>
          ,
          <year>2016</year>
          .
          <source>ISBN: 978-5-9556-0161-8</source>
          .
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>