Cyberattacks and Countermeasures for In-Vehicle Networks

Cyberattacks and Countermeasures for In-Vehicle Networks
复制标题

DOI:
10.1145/3431233
复制
发表时间:
2021-04-01
影响因子:
16.6
通讯作者:
Burnap, Peter
Burnap, Peter
中科院分区:
计算机科学1区
文献类型:
--
作者:
Aliwa, Emad;Rana, Omer;Burnap, Peter

文献摘要

被引文献

相似文献

随着车辆之间和车辆内部连通性的增加,人们对安全和安保的担忧也在增加。在车辆内部使用各种汽车串行协议,如控制器局域网(CAN)、本地互连网络(LIN)和FlexRay。CAN总线是目前应用最广泛的车载网络协议,用于支持电子控制单元(ECU)之间的车辆参数交换。该协议在设计上缺乏安全机制,因此容易受到各种攻击。此外,车辆的连通性使CAN总线不仅从车内而且从外部都容易受到攻击。随着联网汽车的兴起,车载车辆上引入了更多的入口点和接口,从而也导致了更广泛的潜在攻击面。现有的安全机制集中于加密、认证和车辆入侵检测系统(IDS)的使用,这些系统在诸如低带宽、小帧大小(例如,在CAN协议中)、有限的计算资源可用性和实时敏感度等各种约束下运行。我们对当前的加密和入侵检测方法进行了调查和分类,并根据实时约束、使用的硬件类型、CAN总线行为的变化、攻击缓解类型以及用于验证这些方法的软件/硬件等标准对这些方法进行了比较。最后,我们总结了缓解策略、局限性和未来的研究挑战。
As connectivity between and within vehicles increases, so does concern about safety and security. Various automotive serial protocols are used inside vehicles such as Controller Area Network (CAN), Local Interconnect Network (LIN), and FlexRay. CAN Bus is the most used in-vehicle network protocol to support exchange of vehicle parameters between Electronic Control Units (ECUs). This protocol lacks security mechanisms by design and is therefore vulnerable to various attacks. Furthermore, connectivity of vehicles has made the CAN Bus vulnerable not only from within the vehicle but also from outside. With the rise of connected cars, more entry points and interfaces have been introduced on board vehicles, thereby also leading to a wider potential attack surface. Existing security mechanisms focus on the use of encryption, authentication, and vehicle Intrusion Detection Systems (IDS), which operate under various constraints such as low bandwidth, small frame size (e.g., in the CAN protocol), limited availability of computational resources, and real-time sensitivity. We survey and classify current cryptographic and IDS approaches and compare these approaches based on criteria such as real-time constraints, types of hardware used, changes in CAN Bus behaviour, types of attack mitigation, and software/ hardware used to validate these approaches. We conclude with mitigation strategies limitations and research challenges for the future.