PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 22, 20260 citationsOpen Access

AI-assisted Vulnerability Analysis and Classification Framework for UDS on CAN-bus Fuzzer

View Full Paper
GKGolam KayasZPZachariah PelletierDGDouglas Gordon

Key Points

  • The aim is to automate the analysis of security vulnerabilities identified during fuzz testing of the CAN bus system.
  • Developed a testing architecture for automated log analysis of fuzz test cases.
  • Classified various types of vulnerabilities in in-vehicle networks.
  • Created a risk scoring system based on failure class and severity.
  • Proposed techniques to assess the robustness of potential failures.
  • Automated determination of security vulnerabilities from large fuzz testing logs.
  • Generated risk scores correlating to the severity and robustness of failures.
  • Improved efficiency in identifying critical vulnerabilities compared to manual analysis.

Abstract

Controller area network (CAN) bus system is widely accepted for connecting Electronic Control Units (ECUs) on in-vehicle networks. Fuzz-testing (i.e., testing with anomalous input data, often pseudo-random) over the CAN-bus is considered a proven method to detect security vulnerabilities within the in-vehiclenetwork. The automatic execution of the test cases and checking the robustness makes CAN-bus fuzzing a popular choice in the automotive testing community. However, due to the large number of fuzz testcases, the execution logs are often large for CAN-bus fuzzing. Root cause analysis of these logs is not a trivial task and requires expert manual effort as not all the failures are security critical and some failures can be contextual issues or false positives. Thus, automatic determination of the class, relative severity, and robustness of a potential failure is desirable for prompt analysis of the vulnerabilities. In this workwe propose a testing architecture to automate the determination of the potential security vulnerabilities from the vast fuzz testing logs and generate a risk score associated with the failure class, relative severity, and robustness of the failure. We also identify different classes of the vulnerabilities can be found in the in-vehicle networks, with the techniques to measure the relative severity, and robustness of the failures. In addition, we provide direction to implement a scoring system to quantify the risk associated with a potential vulnerability.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Kayas et al. (2023) studied this question.

synapsesocial.com/papers/699a9ded482488d673cd42f5https://doi.org/10.5281/zenodo.18714708
Ask AI
Helpful
Bookmark
Share
View Full Paper