ShadowAuth: Backward-Compatible Automatic CAN Authentication for Legacy ECUs
ShadowAuth: Backward-Compatible Automatic CAN Authentication for Legacy ECUs
复制标题
DOI:
10.1145/3488932.3523263
复制
发表时间:
2022-05
期刊:
影响因子:
--
通讯作者:
Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian
中科院分区:
文献类型:
--
作者:
Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian
Controller Area Network (CAN) is the de-facto standard in-vehicle network system. Despite its wide adoption by automobile manufacturers, the lack of security design makes it vulnerable to attacks. For instance, broadcasting packets without authentication allows the impersonation of electronic control units (ECUs). Prior mitigations, such as message authentication or intrusion detection systems, fail to address the compatibility requirement with legacy ECUs, stealthy and sporadic malicious messaging, or guaranteed attack detection. We propose a novel authentication system called ShadowAuth that overcomes the aforementioned challenges by offering backwardcompatible packet authentication to ECUs without requiring ECU firmware source code. Specifically, our authentication scheme provides transparent CAN packet authentication without modifying existing CAN packet definitions (e.g., J1939) via automatic ECU firmware instrumentation technique to locate CAN packet transmission code, and instrument authentication code based on the CAN packet behavioral transmission patterns. ShadowAuth enables vehicles to detect state-of-the-art CAN attacks, such as busoff and packet injection, responsively within 60ms without false positives. ShadowAuth provides a sound and deployable solution for real-world ECUs.