Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle Protocols

Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle Protocols
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Shengtuo Hu;Qi Alfred Chen;Jiachen Sun;Yiheng Feng;Z. Morley Mao;Henry X. Liu
Shengtuo Hu;Qi Alfred Chen;Jiachen Sun;Yiheng Feng;Z. Morley Mao;Henry X. Liu
中科院分区:
其他
文献类型:
--
作者:
Shengtuo Hu;Qi Alfred Chen;Jiachen Sun;Yiheng Feng;Z. Morley Mao;Henry X. Liu

文献摘要

被引文献

相似文献

随着新兴的互联车辆(CV)技术的发展,车辆可以与交通基础设施和其他车辆进行无线通信,以真实的实时交换安全和移动信息。然而,综合通信能力不可避免地增加了车辆的攻击面,这可以被利用来造成道路上的安全隐患。因此,非常希望系统地了解当前CV网络堆栈以及CV应用中的设计级防火墙以及相应的安全性/安全后果,以便可以在大规模部署之前主动发现和解决这些防火墙。在本文中,我们设计了CVAnalyzer,一个系统,用于发现CV网络堆栈的可用性违规的设计级别的警告,以及量化相应的安全/安全后果。为了实现这一目标,CVAna-lyzer结合了一般模型检查器的攻击发现能力和概率模型检查器的定量威胁评估能力。使用CVAnalyzer,我们成功地发现了4个新的拒绝服务(拒绝服务)漏洞的最新CV网络协议和14个新的拒绝服务漏洞的两个CV排管理协议。我们的量化结果表明,这些攻击的成功率高达99%,在最坏的情况下,数据包处理的延迟至少会增加一倍,违反了CV通信的延迟要求。我们在真实世界的测试平台上实现并验证了所有攻击,并分析了根本原因,提出了潜在的解决方案。我们已经向IEEE 1609工作组报告了我们在CV网络协议中的发现,该工作组已经承认了发现的漏洞,并计划采用我们的解决方案。
With the development of the emerging Connected Vehicle (CV) technology, vehicles can wirelessly communicate with traffic infrastructure and other vehicles to exchange safety and mobility information in real time. However, the integrated communication capability inevitably increases the attack surface of vehicles, which can be exploited to cause safety hazard on the road. Thus, it is highly desirable to systematically understand design-level flaws in the current CV network stack as well as in CV applications, and the corresponding security/safety consequences so that these flaws can be proactively discovered and addressed before large-scale deployment. In this paper, we design CVAnalyzer , a system for discovering design-level flaws for availability violations of the CV network stack, as well as quantifying the corresponding security/safety consequences. To achieve this, CVAna-lyzer combines the attack discovery capability of a general model checker and the quantitative threat assessment capability of a probabilistic model checker. Using CVAnalyzer , we successfully uncovered 4 new DoS (Denial-of-Service) vulnerabilities of the latest CV network protocols and 14 new DoS vulnerabilities of two CV platoon management protocols. Our quantification results show that these attacks can have as high as 99% success rates, and in the worst case can at least double the delay in packet processing, violating the latency requirement in CV communication. We implemented and validated all attacks in a real-world testbed, and also analyzed the fundamental causes to propose potential solutions. We have reported our findings in the CV network protocols to the IEEE 1609 Working Group, and the group has acknowledged the discovered vulnerabilities and plans to adopt our solutions.