Vehicle Security: A Survey of Security Issues and Vulnerabilities, Malware Attacks and Defenses

Vehicle Security: A Survey of Security Issues and Vulnerabilities, Malware Attacks and Defenses
复制标题

DOI:
10.1109/access.2021.3130495
复制
发表时间:
2021-01-01
期刊:
影响因子:
3.9
通讯作者:
Malik, Hafiz
Malik, Hafiz
中科院分区:
计算机科学3区
文献类型:
--
作者:
Abu Elkhail, Abdulrahman;Refat, Rafi Ud Daula;Malik, Hafiz

文献摘要

被引文献

相似文献

近年来引领了汽车技术的发展,随着这些新的发展,现代汽车变得越来越精明,并提供越来越多的涵盖各种功能的创新应用。这些功能由数百个电子控制单元(ECU)控制,这些ECU通过控制区域网络(CAN)总线相互连接。虽然ECU旨在提供与现代车辆相关的各种便利设施,包括舒适性,但这些功能暴露了攻击者可以利用的新攻击面。这一趋势因许多ECU依赖无线通信与外界交互而加剧。因此,使它们容易受到常见威胁的影响,例如恶意软件注入,这可能会危及现代车辆的整体安全性。在本文中,我们提供了与智能车辆相关的体系结构的详细描述,并确定各种安全问题和漏洞,影响这样的系统。我们概述了不同的恶意软件类型以及它们用来感染现代车辆的攻击载体。这项工作还详细调查了针对此类攻击的可用防御措施,包括:签名,行为,启发式,云和基于机器学习的检测措施。此外,本文旨在帮助研究人员熟悉可用的防御措施,以及如何将其应用于保护智能车辆免受可能危及当今车辆安全的新兴恶意软件威胁。它还为有兴趣开发新防御系统的研究人员提供了未来的方向,这些防御系统可以保护智能车辆系统免受恶意软件攻击。
Recent years have led the path to the evolution of automotive technology and with these new developments, modern vehicles are getting increasingly astute and offering growing quantities of innovative applications that cover various functionalities. These functionalities are controlled by hundreds of Electronic Control Units (ECUs) which are connected to each other via the Control Area Network (CAN) bus. Although ECUs are designed to offer various amenities that are associated with modern vehicles including comfort, such features expose new attack surfaces that can be harnessed by attackers. This trend is exacerbated by the fact that many of these ECUs rely on wireless communication for interacting with the outside world. Therefore, making them vulnerable to common threats such as malware injection that can compromise the overall security of modern vehicles. In this paper, we provide a detailed description of the architecture associated with intelligent vehicles, and identify various security issues and vulnerabilities that impact such systems. We provide an overview of different malware types and the vectors of attacks they leverage for infecting modern vehicles. This work also presents a detailed survey of available defenses against such attacks including: signature, behavior, heuristic, cloud, and machine learning-based detection measures. Furthermore, this paper intends to assist researchers in becoming familiar with the available defenses and how they can be applied to secure intelligent vehicles against emerging malware threats that can compromise the security of today's vehicles. It also provides future directions for researchers who are interested in developing new defenses that can safeguard intelligent vehicles systems against malware attacks.