Automated Reverse Engineering and Attack for CAN Using OBD-II

Automated Reverse Engineering and Attack for CAN Using OBD-II
复制标题

使用 OBD-II 对 CAN 进行自动逆向工程和攻击

DOI:
10.1109/vtcfall.2018.8690781
复制
发表时间:
2018
期刊:
2018 IEEE 88th Vehicular Technology Conference (VTC-Fall)
影响因子:
--
通讯作者:
H. Kim
H. Kim
中科院分区:
--
文献类型:
--
作者:
Tae Un Kang;Hyun Min Song;S. Jeong;H. Kim

文献摘要

被引文献

相似文献

控制器局域网(CAN)是最流行的车载网络之一。 CAN 允许电子控制单元 (ECU) 相互通信。 ECU 控制车辆系统的各种功能,例如发动机和变速箱控制。因此,CAN和ECU是黑客的首要目标。如果CAN及其连接的部件受到攻击,车辆可能会导致严重故障和致命事故。然而,很难找到黑客想要发送和控制车辆的确切 CAN 消息。同样,车辆安全研究人员也面临同样的问题,需要找出 CAN 消息的确切含义,以检测复杂的攻击和攻击者。检测简单的攻击模式(例如拒绝服务 (DoS) 攻击)相对容易。然而,CAN规范信息属于汽车主机厂的私有信息,要揭示CAN报文的确切含义,需要通过逆向工程技术对报文进行分析,费时费力。为了解决这个问题,我们开发了自动化 CAN 分析仪 (ACA)。 ACA 具有自动逆向工程功能,可以帮助分析车载诊断 II (OBD-II) 诊断查询的响应数据与相关 CAN 流量数据之间的关系。此外,它还支持自动攻击功能,可以根据预先分析的CAN报文信息向CAN总线注入虚假报文。通过提供的自动攻击功能,研究人员可以轻松确认逆向工程结果是否正确工作。因此,ACA 可以降低车载网络研究的准入门槛。为了评估 ACA,我们将我们的方法应用于两辆真实车辆:现代 YF Sonata(2010 款)和起亚 Soul(2014 款)。在本文中,我们可以借助 ACA 找出两辆车上 CAN 消息的含义。此外,由于现代车辆都配备了OBD-II,因此我们的方法可以广泛应用于大多数车辆。
Controller area network (CAN) is one of the most popular in-vehicle networks. CAN allows electronic control units (ECUs) to communicate with each other. ECUs control various function of vehicle systems such as engine and transmission control. Therefore, CAN and ECUs are the high priority targets by hackers. If the CAN and the connected components are attacked, the vehicle may cause serious malfunction and fatal accidents. However, it is hard to find out the exact CAN messages to send and control the vehicle as intended by hackers. Likewise, vehicle security researchers have the same problem to find out the exact meaning of CAN messages to detect sophisticated attacks as well as attackers. It is relatively easy to detect the simple pattern of attacks such as denial of service (DoS) attack. However, CAN specification information is private information of car OEMs, to reveal the exact meaning of CAN messages, we need to analyze the messages by reverse engineering techniques, which is time-consuming and laborious tasks. To solve this problem, we developed the Automated CAN Analyzer (ACA). The ACA has automated reverse engineering functions which can help to analyze the relationship between the response data from a diagnostic query of on-board diagnostics II (OBD-II) and the related CAN traffic data. Furthermore, it supports the automated attack function that can inject fake messages into CAN bus based on pre-analyzed CAN message information. Researchers can easily confirm whether the reverse engineering results are correctly working or not through the provided automated attack function. As a result, the ACA could lower the barriers to entry to in-vehicle network research. To evaluate the ACA, we applied our approach to two real vehicles, Hyundai YF Sonata (2010 model) and KIA Soul (2014 model). In this paper, we can find out the meaning of CAN messages on both vehicles with the help of the ACA. Additionally, since modern vehicles are all equipped with OBD-II, our approach can be applied to most vehicle widely.