CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive Microcontrollers

CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive Microcontrollers
复制标题

CANNON:通过未更改的汽车微控制器进行可靠且隐秘的远程关闭攻击

DOI:
--
复制
发表时间:
2021
期刊:
IEEE Symposium on Security and Privacy
影响因子:
--
通讯作者:
Vyas Sekar
Vyas Sekar
中科院分区:
--
文献类型:
--
作者:
Sekar Kulandaivel;Shalabh Jain;J. Guajardo;Vyas Sekar

文献摘要

参考文献

被引文献

相似文献

现代车辆中的电子控制单元(ECU)最近成为停机攻击的目标,这些停机攻击可以使关键安全的车辆功能失效,并被用作发动更危险攻击的手段。现有攻击要么通过物理操作总线信号,要么通过消息注入操作。然而,我们认为这些不可能同时是远程的、隐蔽的和可靠的。例如,消息注入是由现代入侵检测系统(IDS)提议检测到的,并且需要严格的同步,而这是无法远程实现的。在这项工作中,我们引入了一类新的攻击,利用现代汽车微控制器单元(MCU)的外围时钟门控功能。通过使用此功能,具有纯软件控制的远程攻击者可以可靠地“冻结”受损ECU的输出,以便在任何时间插入任意比特。利用这一洞察力,我们开发了远程关闭的大炮攻击。由于大炮攻击产生的错误模式与自然错误无法区分,并且不需要插入消息,因此使用现有技术很难检测到它。我们演示了对现代乘用车ECU中使用的两个汽车MCU的攻击。我们讨论了针对此类攻击的潜在缓解策略和对策。
Electronic Control Units (ECUs) in modern vehicles have recently been targets for shutdown attacks, which can disable safety-critical vehicle functions and be used as means to launch more dangerous attacks. Existing attacks operate either by physical manipulation of the bus signals or message injection. However, we argue that these cannot simultaneously be remote, stealthy, and reliable. For instance, message injection is detected by modern Intrusion Detection System (IDS) proposals and requires strict synchronization that cannot be realized remotely. In this work, we introduce a new class of attacks that leverage the peripheral clock gating feature in modern automotive microcontroller units (MCUs). By using this capability, a remote adversary with purely software control can reliably "freeze" the output of a compromised ECU to insert arbitrary bits at any time instance. Utilizing on this insight, we develop the CANnon attack for remote shutdown. Since the CANnon attack produces error patterns indistinguishable from natural errors and does not require message insertion, detecting it with current techniques is difficult. We demonstrate this attack on two automotive MCUs used in modern passenger vehicle ECUs. We discuss potential mitigation strategies and countermeasures for such attacks.
DOI: 10.1145/3359789.3359834
发表时间: 2019-12
期刊: Proceedings of the 35th Annual Computer Security Applications Conference
影响因子: --
作者:
M. Foruhandeh;Yanmao Man;Ryan M. Gerdes;Ming Li;Thidapat Chantem
通讯作者: M. Foruhandeh;Yanmao Man;Ryan M. Gerdes;Ming Li;Thidapat Chantem
基于跨车辆驾驶模式的恒定 CAN 消息频率的汽车入侵检测
DOI: 10.1145/3309171.3309179
发表时间: 2019
期刊: Proceedings of the ACM Workshop on Automotive Cybersecurity
影响因子: --
作者:
Young, Clinton;Olufowobi, Habeeb;Bloom, Gedare;Zambreno, Joseph
通讯作者: Zambreno, Joseph