首页> 外文会议>IEEE Symposium on Security and Privacy >CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive Microcontrollers
【24h】

CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive Microcontrollers

机译:Cannon:通过未改变的汽车微控制器可靠和隐秘的远程关闭攻击

获取原文

摘要

Electronic Control Units (ECUs) in modern vehicles have recently been targets for shutdown attacks, which can disable safety-critical vehicle functions and be used as means to launch more dangerous attacks. Existing attacks operate either by physical manipulation of the bus signals or message injection. However, we argue that these cannot simultaneously be remote, stealthy, and reliable. For instance, message injection is detected by modern Intrusion Detection System (IDS) proposals and requires strict synchronization that cannot be realized remotely. In this work, we introduce a new class of attacks that leverage the peripheral clock gating feature in modern automotive microcontroller units (MCUs). By using this capability, a remote adversary with purely software control can reliably "freeze" the output of a compromised ECU to insert arbitrary bits at any time instance. Utilizing on this insight, we develop the CANnon attack for remote shutdown. Since the CANnon attack produces error patterns indistinguishable from natural errors and does not require message insertion, detecting it with current techniques is difficult. We demonstrate this attack on two automotive MCUs used in modern passenger vehicle ECUs. We discuss potential mitigation strategies and countermeasures for such attacks.
机译:现代车辆中的电子控制单元(ECU)最近一直是关机攻击的目标,可以禁用安全关键车辆功能,并用作发射更危险的攻击的手段。现有攻击通过物理操纵总线信号或消息注入操作。但是,我们认为这些不能同时远程,隐秘,可靠。例如,通过现代入侵检测系统(IDS)提案来检测消息注入,并且需要远程实现无法实现的严格同步。在这项工作中,我们介绍了一种新的攻击,利用现代汽车微控制器单元(MCU)中的外围时钟门控功能。通过使用此功能,可以可靠地“冻结”软件控件的远程对手,“冻结”ECU的输出以在任何时间实例插入任意位。利用这一洞察力,我们开发了远程关机的大炮攻击。由于炮攻击产生了从自然错误中无法区分的错误模式,并且不需要消息插入,以便通过当前技术检测到困难。我们展示了在现代乘用车Ecus中使用的两个汽车MCU的攻击。我们讨论了这种袭击的潜在缓解策略和对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号