How to Hack Your Mini Cooper: Reverse Engineering CAN Messages on Passenger Automobiles

How to Hack Your Mini Cooper: Reverse Engineering CAN Messages on Passenger Automobiles
复制标题

如何破解您的 Mini Cooper:乘用车上的 CAN 消息逆向工程

DOI:
--
复制
发表时间:
2013
期刊:
影响因子:
--
通讯作者:
Jason Staggs
Jason Staggs
中科院分区:
--
文献类型:
--
作者:
Jason Staggs

文献摘要

被引文献

相似文献

随着现代车辆技术的出现,乘用车的计算机化组件变得越来越互连,以提高汽车效率、驾驶体验和排放控制。控制器区域网络 (CAN) 非常适合这些称为电子控制单元 (ECU) 的组件之间的相互通信。 ECU 用于与汽车上的关键控制系统进行通信,包括变速箱、制动、车身控制,甚至车辆信息娱乐系统。 CAN 网络专为在恶劣环境下运行的 ECU 组件之间进行高速、可靠的通信而设计。不幸的是,底层协议的安全性充其量是值得怀疑的。博世 CAN 标准不包括用于对通过 CAN 网络发送到各种 ECU 的消息进行身份验证和验证的固有安全机制。目前,乘用车 CAN 网络的唯一数据安全方法是使用专有的 CAN 消息 ID 以及 CAN 总线与外界之间的物理边界。这带来了严重的安全问题,因为任何能够物理访问车辆数据总线的人都可能生成发往各种 ECU 的欺骗性 CAN 流量,其中一些 ECU 可能负责关键的车辆操作,例如制动系统或发动机控制单元。为了防止这种情况发生,乘用车制造商不会发布车辆网络上各种组件的专有 CAN 消息 ID。然而,专有消息 ID 可以通过逆向工程过程来识别。本文介绍了对乘用车 CAN 消息进行逆向工程的技术,展示了攻击者可以轻松操纵支持 CAN 的汽车组件。逆向工程方法通过将 2003 Mini Cooper 的速度计和转速计(仪表组)转换为通过 Arduino 微控制器发送的欺骗性 CAN 消息控制的功能时钟来演示。
With the advent of modern vehicular technology, the computerized components of passenger vehicles have become increasingly interconnected to facilitate automotive efficiency, driving experience, and emissions control. Controller Area Networks (CANs) are well suited for intercommunications among these components, called electronic control units (ECUs). ECUs are used to communicate with critical control systems on automobiles including transmissions, braking, body control, and even vehicle infotainment systems. CAN networks are designed for high speed, reliable communications between ECU components operating in harsh environments. Unfortunately, the security of the underlying protocol is dubious at best. The Bosch CAN standard does not include inherent security mechanisms for authentication and validation of messages sent to various ECUs over a CAN network. Currently the only data security methods for CAN networks on passenger vehicles are the use of proprietary CAN message IDs and a physical boundary between the CAN bus and the outside world. This presents a serious security issue, because anyone with physical access to the vehicle's data bus could generate spoofed CAN traffic destined for various ECUs, some of which could be responsible for critical vehicle operations such as the braking system or engine control unit. To prevent this, manufactures of passenger vehicles do not publish the proprietary CAN message IDs for various components on the vehicle network. However, proprietary message IDs can be identified through a reverse engineering process. This paper identifies techniques for reverse engineering CAN messages on passenger vehicles, demonstrating the ease with which an attacker could manipulate CAN-enabled components of an automobile. The reverse engineering methodology is demonstrated by the transformation of the speedometer and tachometer (instrument cluster) of a 2003 Mini Cooper into a functional clock controlled via spoofed CAN messages sent by an Arduino microcontroller.