Vulnerability of Controller Area Network to Schedule-Based Attacks

Vulnerability of Controller Area Network to Schedule-Based Attacks
复制标题

DOI:
10.1109/rtss52674.2021.00051
复制
发表时间:
2021-12
期刊:
2021 IEEE Real-Time Systems Symposium (RTSS)
影响因子:
--
通讯作者:
Sena Hounsinou;Mark Stidd;Uchenna Ezeobi;Habeeb Olufowobi;M. Nasri;Gedare Bloom
Sena Hounsinou;Mark Stidd;Uchenna Ezeobi;Habeeb Olufowobi;M. Nasri;Gedare Bloom
中科院分区:
其他
文献类型:
--
作者:
Sena Hounsinou;Mark Stidd;Uchenna Ezeobi;Habeeb Olufowobi;M. Nasri;Gedare Bloom

文献摘要

被引文献

相似文献

汽车系统的安全运行对乘客和其他道路使用者的安全至关重要。安全的关键功能之一是控制器局域网(CAN),它将大多数地面车辆中的安全关键电子控制单元(ECU)互连。不幸的是,CAN容易受到几种攻击。一种这样的攻击是总线关闭攻击,其可用于使受害ECU将其自身从CAN总线断开,并且随后使攻击者伪装成该ECU。总线关闭攻击的一个局限性是,它要求攻击者在受害者的传输和攻击者注入的消息之间实现紧密同步。在本文中,我们介绍了一个基于时间表的攻击框架的CAN总线关闭攻击,使用CAN总线的实时时间表来预测更多的攻击机会比以前已知的。我们描述了一个排名方法,攻击者选择和优化其攻击注入的标准,如攻击成功率,总线扰动,或攻击延迟。结果表明,基于调度的攻击可以增强CAN总线的脆弱性。
The secure functioning of automotive systems is vital to the safety of their passengers and other roadway users. One of the critical functions for safety is the controller area network (CAN), which interconnects the safety-critical electronic control units (ECUs) in the majority of ground vehicles. Unfortunately CAN is known to be vulnerable to several attacks. One such attack is the bus-off attack, which can be used to cause a victim ECU to disconnect itself from the CAN bus and, subsequently, for an attacker to masquerade as that ECU. A limitation of the bus-off attack is that it requires the attacker to achieve tight synchronization between the transmission of the victim and the attacker's injected message. In this paper, we introduce a schedule-based attack framework for the CAN bus-off attack that uses the real-time schedule of the CAN bus to predict more attack opportunities than previously known. We describe a ranking method for an attacker to select and optimize its attack injections with respect to criteria such as attack success rate, bus perturbation, or attack latency. The results show that vulnerabilities of the CAN bus can be enhanced by schedule-based attacks.