Plug-N-Pwned: Comprehensive Vulnerability Analysis of OBD-II Dongles as A New Over-the-Air Attack Surface in Automotive IoT

Plug-N-Pwned: Comprehensive Vulnerability Analysis of OBD-II Dongles as A New Over-the-Air Attack Surface in Automotive IoT
复制标题

DOI:
--
复制
发表时间:
2020
影响因子:
5.8
通讯作者:
Haohuang Wen;Qi Alfred Chen;Zhiqiang Lin
Haohuang Wen;Qi Alfred Chen;Zhiqiang Lin
中科院分区:
环境科学与生态学3区
文献类型:
--
作者:
Haohuang Wen;Qi Alfred Chen;Zhiqiang Lin

文献摘要

被引文献

相似文献

随着物联网趋势的不断发展,大量无线OBD-II加密狗被开发出来,只需将其插入车辆即可实现复杂的车辆控制和状态监控等远程功能。然而,由于这些加密狗直接与车载网络连接,它们可能会为车辆打开一个新的空中攻击面。在本文中,我们对2019年2月在美国亚马逊上提供的所有无线OBD-II加密狗进行了首次全面的安全分析,共有77个。为了系统地进行分析,我们设计并实现了一个自动化工具DONGLESCOPE,动态测试这些加密狗从所有可能的攻击阶段对真实的汽车。使用DONGLESCOPE,我们已经确定了5种不同类型的漏洞,其中4种是新发现的。我们的研究结果显示,77个加密狗中的每一个都暴露了至少两种类型的漏洞,这表明当今市场上的无线OBD-II加密狗中存在广泛的漏洞暴露。为了证明攻击的严重性,我们进一步构建了4类具体的攻击,这些攻击具有各种实际意义,例如隐私泄露,财产盗窃,甚至安全威胁。并探讨了其产生的根源和可行的对策,并进行了相应的责任披露。
With the growing trend of the Internet of Things, a large number of wireless OBD-II dongles are developed, which can be simply plugged into vehicles to enable remote functions such as sophisticated vehicle control and status monitoring. However, since these dongles are directly connected with in-vehicle networks, they may open a new over-the-air attack surface for vehicles. In this paper, we conduct the first comprehensive security analysis on all wireless OBD-II dongles available on Amazon in the US in February 2019, which were 77 in total. To systematically perform the analysis, we design and implement an automated tool DONGLESCOPE that dynamically tests these dongles from all possible attack stages on a real automobile. With DONGLESCOPE, we have identified 5 different types of vulnerabilities, with 4 being newly discovered. Our results reveal that each of the 77 dongles exposes at least two types of these vulnerabilities, which indicates a widespread vulnerability exposure among wireless OBD-II dongles on the market today. To demonstrate the severity, we further construct 4 classes of concrete attacks with a variety of practical implications such as privacy leakage, property theft, and even safety threat. We also discuss the root causes and feasible countermeasures, and have made corresponding responsible disclosure.