首页> 外文会议>IEEE Vehicular Technology Conference >CANDY: A Social Engineering Attack to Leak Information from Infotainment System
【24h】

CANDY: A Social Engineering Attack to Leak Information from Infotainment System

机译:CANDY:一项社会工程学攻击,旨在从信息娱乐系统泄漏信息

获取原文

摘要

The introduction of Information and Communications Technologies (ICT) systems into vehicles make them more prone to cyber-security attacks that may impact of vehicles capability and, consequently, on the safety of drivers, passengers. In this paper, we focus on how to exploit security vulnerabilities affecting user-to-vehicle and intra- vehicle communications to hack the infotainment system to retrieve information about both vehicle and driver. Indeed, we designed and developed CANDY, a set of malicious APP injecting in a genuine Android APP, acting as a Trojan-horse on the Android In-Vehicle infotainment system. It opens a back-door that allows an attacker to remotely access to the infotainment system. We use this back-door to hit the privacy of the driver by recording her voice and collect information circulating on the CAN bus about the vehicle. CANDY is distributed by using social engineering techniques.
机译:在车辆中引入信息和通信技术(ICT)系统使它们更容易受到网络安全攻击,这可能会影响车辆的性能,进而影响驾驶员,乘客的安全。在本文中,我们专注于如何利用影响用户到车辆和车辆内通信的安全漏洞来入侵信息娱乐系统,以获取有关车辆和驾驶员的信息。实际上,我们设计并开发了CANDY,这是一组注入到真正的Android APP中的恶意APP,它充当Android车载信息娱乐系统上的特洛伊木马。它打开了后门,使攻击者可以远程访问信息娱乐系统。我们使用后门通过记录驾驶员的声音来打扰驾驶员的私密性,并收集在CAN总线上流通的有关车辆的信息。通过使用社会工程技术来分发CANDY。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号