课题基金 / 基金详情

EAGER: Collaborative: Toward a Test Bed for Heavy Vehicle Cyber Security Experimentation

EAGER: Collaborative: Toward a Test Bed for Heavy Vehicle Cyber Security Experimentation
EAGER:协作:迈向重型车辆网络安全实验的试验台
批准号:
1619690
负责人:
Rosanne Gamble
金额:
$17.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2016
资助国家:
美国
项目状态:
已结题
起止时间:
2016-01-01 至 2018-12-31

项目摘要

项目成果

Rosanne Gamble的其他基金

相似基金

相关文献

中文摘要
翻译
卡车和公共汽车等重型车辆是美国关键基础设施的一部分,承担着相当大一部分商业和私人商业运营。在这些资产的网络安全方面投入的努力很少。如果对手获得车辆的控制器区域网络(CAN)的访问权限,就可以发起攻击,从而影响关键的车辆电子部件。传统上,接触到重型车辆才能接触到罐头。然而,重型车辆上也安装了无线设备,这可以打开卡车和公交车进行远程无线网络攻击。该项目探索与在CAN上通信的无线设备相关的网络安全漏洞。对于已识别的威胁,研究人员确定适当的缓解策略,包括在哪里以及如何最好地部署这些策略。为了展示潜在的漏洞和对提出的缓解策略的后续信任,该项目设计并实施了一个可扩展的高保真试验台,使用实际的重型车辆电子控制单元,如发动机和刹车控制器。试验台包括用于远程访问和安全信息传递的内置机制,以允许不同地点的研究人员之间进行合作。这项研究的结果,包括使用其他组件扩展试验台的可能性,可能会影响其他使用CAN的行业的网络安全分析,如建筑自动化、医疗器械和制造业。重型车辆中的SAE J1939通信网络基于CAN,并具有开放的数据包定义和传输文档。此漏洞可被利用来创建伪造的J1939消息。重型车辆车主使用第三方系统,如远程远程信息处理,这些系统引入了支持J1939的新模块,这些模块可能会被对手颠覆。该项目利用这些系统获得远程访问,并攻击另一个与CAN连接的电子控制单元。当远程信息处理系统无线连接到CAN以确定是否可以插入虚假分组时,执行分组嗅探。研究包括使用开发的试验台检查入侵检测系统的不同设计、配置和部署,以最好地挫败此类远程攻击。其中一个挑战是开发能够与已部署的试验台硬件实时操作的算法。研究包括开发科学策略来测量试验台中网络操作的时间响应和任何入侵检测系统的反应时间,以便可以根据在J1939网络上进行远程网络操作的能力来确定界限。
英文摘要
Heavy vehicles, such as trucks and buses, are part of the US critical infrastructure and carry out a significant portion of commercial and private business operations. Little effort has been invested in cyber security for these assets. If an adversary gains access to the vehicle's Controller Area Network (CAN), attacks can be launched that can affect critical vehicle electronic components. Traditionally, physical access to a heavy vehicle was required to access the CAN. However, wireless devices are also installed on heavy vehicles, which open trucks and busses to remote wireless cyber attacks. This project explores cyber security vulnerabilities related to wireless devices that communicate on the CAN. For identified threats, researchers determine the proper mitigation strategies, including where and how they are best deployed. To demonstrate potential exploits and subsequent trust in proposed mitigation strategies, this project designs and implements a scalable, high-fidelity test bed using actual heavy vehicle electronic control units, such as engine and brake controllers. The test bed includes built-in mechanisms for remote access and secure information delivery to allow for collaboration among researchers at different sites. The results of the research, including the potential to extend the test bed with other components, can impact cyber security analysis for other industries that use CAN, such as building automation, medical devices, and manufacturing. The SAE J1939 communication network in heavy vehicles is based on CAN and has open documentation for packet definition and transmission. This openness may be exploited for creating spoofed J1939 messages. Heavy vehicle owners utilize third-party systems, such as remote telematics, that introduce new J1939 enabled modules, which can potentially be subverted by an adversary. This project uses these systems to gain remote access and attack another CAN connected electronic control unit. Packet sniffing is performed as the telematics system connects wirelessly to the CAN to determine if fake packets can be inserted. Research includes examining different designs, configurations, and deployments of intrusion detection systems to best thwart such remote attacks using the developed test bed. One challenge is to develop algorithms that can act in real-time with deployed test bed hardware. Research includes developing scientific strategies to measure the temporal response of the cyber actions in the test bed and the reaction time of any intrusion detection system, so that bounds can be determined based on the ability to conduct a remote cyber operation on a J1939 network.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
An Instructional Tool to Foster Creativity in the Software Engineering Process
  • 批准号:
    0757434
  • 项目类别:
    Standard Grant
  • 资助金额:
    $0.0万
  • 财政年份:
    2008
  • 负责人:
    Rosanne Gamble
  • 依托单位:
Integration Architecture Theory
  • 批准号:
    9988320
  • 项目类别:
    Standard Grant
  • 资助金额:
    $20.0万
  • 财政年份:
    2000
  • 负责人:
    Rosanne Gamble
  • 依托单位:
Experimentation Platform for Detecting and Resolving Interoperability Problems
  • 批准号:
    9708643
  • 项目类别:
    Standard Grant
  • 资助金额:
    $4.0万
  • 财政年份:
    1997
  • 负责人:
    Rosanne Gamble
  • 依托单位:
海外基金