Skip to content

Author

Younis A. M. Al Shojaa

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Conference Aug 2026

A Progressive Machine Learning Framework for Intrusion Prevention in Controller Area Networks: Multi-Scenario Evaluation for Secure Automotive Systems

Modern vehicles rely heavily on in-vehicle Controller Area Network (CAN) communication to coordinate safety-critical electronic control units (ECUs). However, the CAN protocol was not originally designed with authentication, encryption, or message integrity mechanisms, making it vulnerable to injection, spoofing, fuzzy, and denial-of-service attacks. Although machine learning-based intrusion detection systems have achieved high detection accuracy on CAN traffic, detection alone is not sufficient for safety-critical automotive environments where malicious messages may affect ECUs before a response is triggered. This paper presents a progressive machine learning-based framework for prevention-oriented CAN bus security. The framework analyzes statistical and temporal CAN traffic features and evaluates multiple machine learning models under three scenarios: binary attack detection, attack-type classification, and prevention-oriented allow/block decision evaluation. The study uses the Car-Hacking dataset and compares several supervised and anomaly-detection models, including tree-based ensembles, linear models, probabilistic models, neural models, and anomaly detectors. The results show that tree-based models achieve the strongest overall performance, with Random Forest reaching 99.6% accuracy in binary detection. The proposed prevention layer is evaluated as a software-level decision mechanism that converts model outputs into allow/block decisions, while CAN-aware blocking mechanisms are discussed only as architectural deployment options for future inline gateway implementation. The findings indicate that lightweight tree-based machine learning models can support real-time prevention-oriented decisions in CAN security, while further validation on hardware testbeds, realistic CAN bus-load conditions, and cross-dataset settings remains necessary.

Younis A. M. Al Shojaa, Redhwan M. A. Saad, Khaled A. M. Al Soufy · 0 citations