ShadowAuth: Backward-Compatible Automatic CAN Authentication for Legacy ECUs

ShadowAuth: Backward-Compatible Automatic CAN Authentication for Legacy ECUs
复制标题

DOI:
10.1145/3488932.3523263
复制
发表时间:
2022-05
期刊:
Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian
Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian
中科院分区:
其他
文献类型:
--
作者:
Sungwoo Kim;Gisu Yeo;Taegyu Kim;J. Rhee;Yuseok Jeon;Antonio Bianchi;Dongyan Xu;D. Tian

文献摘要

相似文献

控制器局域网(CAN)是事实上的标准车载网络系统。尽管它被汽车制造商广泛采用,但缺乏安全设计使其容易受到攻击。例如,在没有认证的情况下广播数据包允许冒充电子控制单元(ECU)。之前的缓解措施(例如消息身份验证或入侵检测系统)无法满足与传统ECU、隐蔽和零星恶意消息传递或有保证的攻击检测的兼容性要求。我们提出了一种称为ShadowAuth的新型身份验证系统,该系统通过向ECU提供向后兼容的数据包身份验证来克服上述挑战,而无需ECU固件源代码。具体来说,我们的认证方案提供透明的CAN数据包认证,而无需修改现有的CAN数据包定义(例如,J1939)通过自动ECU固件检测技术定位CAN数据包传输代码,并基于CAN数据包行为传输模式检测仪器认证代码。ShadowAuth使车辆能够在60 ms内检测最先进的CAN攻击,例如busoff和数据包注入,而不会出现误报。ShadowAuth为现实世界的ECU提供了一个可靠且可部署的解决方案。
Controller Area Network (CAN) is the de-facto standard in-vehicle network system. Despite its wide adoption by automobile manufacturers, the lack of security design makes it vulnerable to attacks. For instance, broadcasting packets without authentication allows the impersonation of electronic control units (ECUs). Prior mitigations, such as message authentication or intrusion detection systems, fail to address the compatibility requirement with legacy ECUs, stealthy and sporadic malicious messaging, or guaranteed attack detection. We propose a novel authentication system called ShadowAuth that overcomes the aforementioned challenges by offering backwardcompatible packet authentication to ECUs without requiring ECU firmware source code. Specifically, our authentication scheme provides transparent CAN packet authentication without modifying existing CAN packet definitions (e.g., J1939) via automatic ECU firmware instrumentation technique to locate CAN packet transmission code, and instrument authentication code based on the CAN packet behavioral transmission patterns. ShadowAuth enables vehicles to detect state-of-the-art CAN attacks, such as busoff and packet injection, responsively within 60ms without false positives. ShadowAuth provides a sound and deployable solution for real-world ECUs.