PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 9, 2024ACM Journal on Autonomous Transportation Systems4 citationsOpen Access

CANdid : A Stealthy Stepping-Stone Attack to Bypass Authentication on ECUs

View Full Paper
SKSekar KulandaivelSJShalabh JainJGJorge Guajardo

Key Points

Key points are not available for this paper at this time.

Abstract

A high-entropy source of randomness is an essential component in any secure protocol, required to ensure that protocol elements, such as cryptographic keys, nonces, or salts, are unpredictable for the attackers. Resource-constrained embedded devices, such as Electronic Control Units (ECUs) in modern vehicles, often utilize weak sources of randomness due to the unavailability of true sources of randomness. In this article, we illustrate the ability of a relatively simple adversary to exploit this weakness within ECUs of vehicles produced by major manufacturers. We demonstrate that the weakness can be exploited by the adversary on a real ECU to breach the protection of Unified Diagnostic Services (UDS) Security Access service and access restricted functionality of the UDS protocol. We develop CANdid, a stepping-stone attack strategy where an adversary with access to a non-critical ECU can utilize this weakness to maliciously reprogram an arbitrary critical ECU over the CAN bus.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Kulandaivel et al. (2024) studied this question.

synapsesocial.com/papers/68e5cdb7b6db643587563ea8https://doi.org/10.1145/3657645
Ask AI
Helpful
Bookmark
Share
View Full Paper