Fast and Vulnerable: A Story of Telematic Failures

Fast and Vulnerable: A Story of Telematic Failures
复制标题

DOI:
--
复制
发表时间:
2015-08
期刊:
--
影响因子:
--
通讯作者:
Ian D. Foster;Andrew Prudhomme;Karl Koscher;Stefan Savage
Ian D. Foster;Andrew Prudhomme;Karl Koscher;Stefan Savage
中科院分区:
其他
文献类型:
--
作者:
Ian D. Foster;Andrew Prudhomme;Karl Koscher;Stefan Savage

文献摘要

被引文献

相似文献

现代汽车是复杂的分布式系统,其中几乎所有的功能-从加速和制动到照明和HVAC -都由计算机控制器介导。这些系统的相互关联的性质引起了明显的安全问题,先前的工作已经表明,任何单个组件中的漏洞都可能提供危及整个系统的手段。因此,添加新组件,特别是具有外部联网能力的新组件,会产生必须仔细考虑的风险。在本文中,我们研究了一种流行的售后远程信息处理控制单元(TCU),它通过标准的OBD-II端口连接到车辆。我们表明,这些设备可以被发现,有针对性的,并受到远程攻击者的危害,我们证明,这样的妥协允许任意远程控制的车辆。这个问题特别具有挑战性,因为这是售后设备,汽车制造商本身无法很好地解决这个问题。
Modern automobiles are complex distributed systems in which virtually all functionality--from acceleration and braking to lighting and HVAC -- is mediated by computerized controllers. The interconnected nature of these systems raises obvious security concerns and prior work has demonstrated that a vulnerability in any single component may provide the means to compromise the system as a whole. Thus, the addition of new components, and especially new components with external networking capability, creates risks that must be carefully considered. In this paper we examine a popular aftermarket telematics control unit (TCU) which connects to a vehicle via the standard OBD-II port. We show that these devices can be discovered, targeted, and compromised by a remote attacker and we demonstrate that such a compromise allows arbitrary remote control of the vehicle. This problem is particularly challenging because, since this is aftermarket equipment, it cannot be well addressed by automobile manufacturers themselves.