An Overview of Attacks and Defences on Intelligent Connected Vehicles
Total Page:16
File Type:pdf, Size:1020Kb
Load more
										Recommended publications
									
								- 
												  Intrusion Detection System for Automotive Controller Area Network (CAN) Bus System: a Review Siti-Farhana Lokman* , Abu Talib Othman and Muhammad-Husaini Abu-BakarLokman et al. EURASIP Journal on Wireless Communications and Networking (2019) 2019:184 https://doi.org/10.1186/s13638-019-1484-3 REVIEW Open Access Intrusion detection system for automotive Controller Area Network (CAN) bus system: a review Siti-Farhana Lokman* , Abu Talib Othman and Muhammad-Husaini Abu-Bakar Abstract The modern vehicles nowadays are managed by networked controllers. Most of the networks were designed with little concern about security which has recently motivated researchers to demonstrate various kinds of attacks against the system. In this paper, we discussed the vulnerabilities of the Controller Area Network (CAN) within in- vehicle communication protocol along with some potential attacks that could be exploited against it. Besides, we present some of the security solutions proposed in the current state of research in order to overcome the attacks. However, the main goal of this paper is to highlight a holistic approach known as intrusion detection system (IDS) which has been a significant tool in securing networks and information systems over the past decades. To the best of our knowledge, there is no recorded literature on a comprehensive overview of IDS implementation specifically in the CAN bus network system. Thus, we proposed an in-depth investigation of IDS found in the literature based on the following aspects: detection approaches, deployment strategies, attacking techniques, and finally technical challenges. In addition, we also categorized the anomaly-based IDS according to these methods, e.g., frequency- based, machine learning-based, statistical-based, and hybrid-based as part of our contributions. Correspondingly, this study will help to accelerate other researchers to pursue IDS research in the CAN bus system.
- 
												  Automotive Cybersecurity: Foundations for Next-Generation VehiclesAutomotive Cybersecurity: Foundations for Next-Generation Vehicles Michele Scalas, Student Member, IEEE Giorgio Giacinto, Senior Member, IEEE Department of Electrical and Electronic Engineering Department of Electrical and Electronic Engineering University of Cagliari University of Cagliari Cagliari, Italy Cagliari, Italy [email protected] [email protected] Abstract—The automotive industry is experiencing a serious Vehicle-to-Vehicle), with a generic infrastructure (V2I) or with transformation due to a digitalisation process and the transition pedestrians (V2P). The typical application of these models is to the new paradigm of Mobility-as-a-Service. The next-generation smart cities, with the aim of optimising traffic management, vehicles are going to be very complex cyber-physical systems, whose design must be reinvented to fulfil the increasing demand sending alerts in case of incidents, coordinating a fleet of of smart services, both for safety and entertainment purposes, vehicles. causing the manufacturers’ model to converge towards that of As regards autonomous driving, it consists in expanding the IT companies. Connected cars and autonomous driving are the current Advanced Driver Assistance Systems (ADASs), such preeminent factors that drive along this route, and they cause the as lane keeping and braking assistants, in order to obtain a necessity of a new design to address the emerging cybersecurity issues: the ”old” automotive architecture relied on a single closed fully autonomous driverless car. The Society of Automotive network, with no external communications; modern vehicles are Engineers (SAE) provides, in fact, six possible levels of going to be always connected indeed, which means the attack autonomy, from level 0, with no assistance, to level 5, where surface will be much more extended.
- 
												  Securing the Modern Vehicle: a Study of Automotive Industry Cybersecurity PracticesSecuring the Modern Vehicle: A Study of Automotive Industry Cybersecurity Practices An independent study commissioned by and Table of Contents Executive Summary ............................................................................................ 1 Organizational Dynamics and Challenges ........................................................... 3 Technical Dynamics and Challenges .................................................................... 6 Product Development and Security Testing Practices ......................................... 9 Supply Chain and Third-Party Component Challenges ........................................ 13 Conclusions ........................................................................................................ 14 Methods ............................................................................................................. 15 Appendix: Detailed Survey Results ..................................................................... 18 Ponemon Institute .............................................................................................. 29 Executive Summary Today’s vehicle is a connected, mobile computer, which has introduced an issue the automotive industry has little experience dealing with: cybersecurity risk. Automotive manufacturers have become as much software as transportation companies, facing all the challenges inherent to software security. Synopsys and SAE International partnered to commission this independent survey of the current cybersecurity practices in the automotive
- 
												  2002 Nissan Xterra Owners ManualThe inside pages of this manual contain a minimum of 50% recycled fibers, Foreword including 10% post-consumer fibers. Welcome to the growing family of new NISSAN familiarity with controls and maintenance For descriptions specified for four-wheel owners. This vehicle has been delivered to you requirements, assisting you in the safe op- drive models, a mark is placed at with confidence. It was produced using the eration of your vehicle. the beginning of the applicable latest techniques and strict quality control. sections/items. This manual was prepared to help you under- WARNING As with other vehicles with features for stand the operation and maintenance of your IMPORTANT SAFETY INFORMATION vehicle so that you may enjoy many miles off-road use, failure to operate four- (kilometers) of driving pleasure. Please read REMINDERS FOR SAFETY! wheel drive models correctly may result through this manual before operating your in loss of control or an accident. Be sure vehicle. Follow these important driving rules to to read ‘‘Driving safety precautions’’ in help ensure a safe and complete trip for the ‘‘Starting and driving’’ section of this In the U.S., a separate Warranty Informa- you and your passengers! tion Booklet or in Canada, a Warranty and manual. Roadside Assistance Information Book- ² NEVER drive under the influence of let explains details about the warranties alcohol or drugs. ON-PAVEMENT AND OFF-ROAD DRIV- covering your vehicle. The “NISSAN Ser- ING vice and Maintenance Guide” explains ² ALWAYS observe posted speed lim- its and never drive too fast for con- This vehicle will handle and maneuver details about maintaining and servicing differently from an ordinary passenger your vehicle.
- 
												  Relay Attack Resistant Passive Keyless Entry Securing PKE Systems with Immobility DetectionDEGREE PROJECT IN MECHANICAL ENGINEERING, FIRST CYCLE, 15 CREDITS STOCKHOLM, SWEDEN 2020 Relay Attack Resistant Passive Keyless Entry Securing PKE Systems with Immobility Detection ABEL VALKO KTH ROYAL INSTITUTE OF TECHNOLOGY SCHOOL OF INDUSTRIAL ENGINEERING AND MANAGEMENT Relay Attack Resistant Passive Keyless Entry ABEL VALKO Bachelor’s Thesis at ITM Supervisor and Examiner: Nihad Subasic TRITA-ITM-EX 2020:48 Abstract A significant security risk of modern vehicles is their vulner- ability to relay attacks, due to challenge-response methods, such as those employed in Passive Keyless Entry (PKE) used by most commercial cars, being inherently exposed. This class of attacks are where communication between a vehicle and its key is relayed by an attacker over long range - thereby bypassing any encryption and unlocking the ve- hicle without requiring direct access to the key. While a multitude of defenses have been proposed in recent years, many lack either robustness or practicality. Any viable sys- tem will likely have to rely on an environmental parameter which is not easily manipulated. Moreover, the system has to be: cost effective; easily implementable; and take user comfort, such as the key’s battery life, into account. This thesis implements and evaluates a PKE system re- sistant to relay attacks, analyses a multitude of proposed strategies in literature for feasibility, as well as suggests a novel method: Approach Curve Matching. It is concluded that the most promising strategies are: Immobility Detec- tion, Distance Bounding Protocols, and Approach Curve Matching - the first of which is chosen to be implemented in the prototype PKE system. The project develops a PKE system and implements the communication protocol using Bluetooth, as opposed to the conventional RFID.
- 
												  Linux from Scratch 版本 R11.0-36-中⽂翻译版 发布于 2021 年 9 ⽉ 21 ⽇Linux From Scratch 版本 r11.0-36-中⽂翻译版 发布于 2021 年 9 ⽉ 21 ⽇ 由 Gerard Beekmans 原著 总编辑:Bruce Dubbs Linux From Scratch: 版本 r11.0-36-中⽂翻译版 : 发布于 2021 年 9 ⽉ 21 ⽇ 由 由 Gerard Beekmans 原著和总编辑:Bruce Dubbs 版权所有 © 1999-2021 Gerard Beekmans 版权所有 © 1999-2021, Gerard Beekmans 保留所有权利。 本书依照 Creative Commons License 许可证发布。 从本书中提取的计算机命令依照 MIT License 许可证发布。 Linux® 是Linus Torvalds 的注册商标。 Linux From Scratch - 版本 r11.0-36-中⽂翻译版 ⽬录 序⾔ .................................................................................................................................... viii i. 前⾔ ............................................................................................................................ viii ii. 本书⾯向的读者 ............................................................................................................ viii iii. LFS 的⽬标架构 ............................................................................................................ ix iv. 阅读本书需要的背景知识 ................................................................................................. ix v. LFS 和标准 ..................................................................................................................... x vi. 本书选择软件包的逻辑 .................................................................................................... xi vii. 排版约定 .................................................................................................................... xvi viii. 本书结构 .................................................................................................................
- 
												  Sevice Munual for CHERY QQ6Foreword ADVICE This Service Manual clearly defines the agreement between CHERY Automobile Co., Ltd. and its customers on the product quality assurance, and the establishment and termination of rights and bligations on after-sales service. Please carefully read this Service Manual before using the parts manufactured by the CHERY Company. Sevice Munual for CHERY QQ6 You are sincerely congratulated to be an owner of CHERY QQ6! Thank you for your belief for Chery Automobile Co., Ltd and your choice for Chery products! You will receive the high quality services from Chery Authorized Sales and Service Station whose employees have been trained well and specially. State-of-art technology offers CHERY QQ6 the excellent performance. Selecting CHERY QQ6 shows that you have very high requireements on the performance and style of a vehicle. Prior to using this car, please carefully read this service manual because the information hereto enables you to know how to properly manipulate and maintain this vehicle, and get the maximum enjoyable driving experience. This Service Manual is applied to the CHERY QQ6 only. Chery Automobile Co., LTD 1 Foreword This manualis compiled in accordance Important Declaration service station. with the structural features of QQ6 Before operating the products, please manufactured by CHERY Automobile Co., carefully read the Manual, which your Ltd.. This manual is applied to the QQ6. rights for enjoy services of warranty from In case that abnormality occurs to your This manual covers the latest information our corporation are lost due to the vehicle during the operation, it must be until it is printed. Chery Automobile Co., violation of the operational provisions.
- 
												  A PRACTICAL METHOD of IDENTIFYING CYBERATTACKS February 2018 INDEXIn Collaboration With A PRACTICAL METHOD OF IDENTIFYING CYBERATTACKS February 2018 INDEX TOPICS EXECUTIVE SUMMARY 4 OVERVIEW 5 THE RESPONSES TO A GROWING THREAT 7 DIFFERENT TYPES OF PERPETRATORS 10 THE SCOURGE OF CYBERCRIME 11 THE EVOLUTION OF CYBERWARFARE 12 CYBERACTIVISM: ACTIVE AS EVER 13 THE ATTRIBUTION PROBLEM 14 TRACKING THE ORIGINS OF CYBERATTACKS 17 CONCLUSION 20 APPENDIX: TIMELINE OF CYBERSECURITY 21 INCIDENTS 2 A Practical Method of Identifying Cyberattacks EXECUTIVE OVERVIEW SUMMARY The frequency and scope of cyberattacks Cyberattacks carried out by a range of entities are continue to grow, and yet despite the seriousness a growing threat to the security of governments of the problem, it remains extremely difficult to and their citizens. There are three main sources differentiate between the various sources of an of attacks; activists, criminals and governments, attack. This paper aims to shed light on the main and - based on the evidence - it is sometimes types of cyberattacks and provides examples hard to differentiate them. Indeed, they may of each. In particular, a high level framework sometimes work together when their interests for investigation is presented, aimed at helping are aligned. The increasing frequency and severity analysts in gaining a better understanding of the of the attacks makes it more important than ever origins of threats, the motive of the attacker, the to understand the source. Knowing who planned technical origin of the attack, the information an attack might make it easier to capture the contained in the coding of the malware and culprits or frame an appropriate response. the attacker’s modus operandi.
- 
												  Basic Performance Measurements of the Intel Optane DC Persistent Memory ModuleBasic Performance Measurements of the Intel Optane DC Persistent Memory Module Or: It’s Finally Here! How Fast is it? Joseph Izraelevitz Jian Yang Lu Zhang Juno Kim Xiao Liu Amirsaman Memaripour Yun Joon Soh Zixuan Wang Yi Xu Subramanya R. Dulloor Jishen Zhao Steven Swanson* Computer Science & Engineering University of California, San Diego arXiv:1903.05714v3 [cs.DC] 9 Aug 2019 *Correspondence should be directed to [email protected]. Copyright © 2019 the authors. 1 2019-08-09 7041bc9 Abstract After nearly a decade of anticipation, scalable nonvolatile memory DIMMs are finally commercially available with the release of the Intel® Optane™ DC Persistent Memory Module (or just “Optane DC PMM”). This new nonvolatile DIMM supports byte-granularity accesses with access times on the order of DRAM, while also providing data storage that survives power outages. This work comprises the first in-depth, scholarly, performance review of Intel’s Optane DC PMM, exploring its capabilities as a main memory device, and as persistent, byte-addressable memory exposed to user-space applications. For the past several months, our group has had access to machines with Optane DC memory and has investigated the Optane DC PMM’s performance characteristics. This report details the chip’s performance under a number of modes and scenarios, and across a wide variety of both micro- and macro-scale benchmarks. In total, this report represents approximately 330 hours of machine time. Optane DC memory occupies a tier in-between SSDs and DRAM. It has higher latency (346 ns) than DRAM but lower latency than an SSD. Unlike DRAM, its bandwidth is asymmetric with respect to access type: for a single Optane DC PMM, its max read bandwidth is 6.6 GB/s, whereas its max write bandwidth is 2.3 GB/s.
- 
												  Fingerprint Identification Keyless Entry SystemWorld Academy of Science, Engineering and Technology International Journal of Electronics and Communication Engineering Fingerprint Identification Vol:2, No:8, 2008 Keyless Entry System Chih-Neng Liang, Huang-Bin Huang, and Bo-Chiuan Chen palm print, voice, vein and multi-pattern identification. Abstract—Nowadays, keyless entry systems are widely adopted According to International Biometric Group (IBG) [3], for vehicle immobilizer systems due to both advantages of security and AFIS/Live-Scan accounts for the highest share in biometric convenience. Keyless entry systems could overcome brute-force key identification market in 2007 with 33.6%, followed by guessing attack, statistics attack and masquerade attack, however, fingerprint ID (25.3%), face profile 12.9%), intermediate they can't prevent from thieves stealing behavior. In this paper, we proposed a new architecture try to improve the existent flaws. The software (5.4%), iris ID (5.1%), palm print (4.7%), voice integration of the keyless entry system and the fingerprint (audio) (3.2%), vein patterns (3.0%), multi-pattern ID (2.9%) identification technology is more suitable to implement on the and other types of identification (4.0%). Among all, portable transponder to achieve higher security needs. We also adopt AFIS/Live-Scan and fingerprint ID account for 58.9% of all and modify AES security protocol for life expectancy and security of identification methods. It is clear that fingerprint ID has the portable transponder. In addition, the identification of a driver's become the mainstream of biometric identification. The reason fingerprint makes the service of automatic reinstatement of a driver's is that it costs less and requires less calculation compared to preferences become possible.
- 
												  Specification-Based Automotive Intrusion Detection Using Controller Area NetworkThis is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TVT.2019.2961344 IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, VOL. XX, NO. XX, XXX 2019 1 SAIDuCANT: Specification-based Automotive Intrusion Detection using Controller Area Network (CAN) Timing Habeeb Olufowobi, Clinton Young, Joseph Zambreno, Senior Member, IEEE, and Gedare Bloom, Senior Member, IEEE Abstract—The proliferation of embedded devices in modern and attacks [2]. Vulnerabilities across the autonomous vehi- vehicles has opened the traditionally-closed vehicular system to cles, vehicular ad-hoc networks, vehicle-to-vehicle, vehicle-to- the risk of cybersecurity attacks through physical and remote infrastructure, connected car, intelligent transportation system, access to the in-vehicle network such as the controller area network (CAN). The CAN bus does not implement a security and even traditional (non-connected) automobiles motivate protocol that can protect the vehicle against the increasing cyber adversaries to launch cyberattacks against vehicles [3]. Unfor- and physical attacks. To address this risk, we introduce a novel tunately, today’s car lacks the necessary security mechanisms algorithm to extract the real-time model parameters of the CAN to protect the vehicular system from attack. bus and develop SAIDuCANT, a specification-based intrusion A critical asset to secure is the automotive in-vehicle detection system (IDS) using anomaly-based supervised learning with the real-time model as input. We evaluate the effectiveness of network, which facilitates communication between ECUs over SAIDuCANT with real CAN logs collected from two passenger multiple physical networks and protocols, with the most preva- cars and on an open-source CAN dataset collected from real- lent being the controller area network (CAN).
- 
												  INSTALLATION GUIDE Table of Contents415 INSTALLATION GUIDE Table of Contents Installation Points to Remember . .2 Plug-In Harnesses . .16 Super Bright LED . .16 Tools Required . .3 Valet/Program Switch . .16 Deciding on Component Location . .3 On-Board Dual Stage Shock Sensor . .16 Siren . 3 Control Module . 4 Internal Programming Jumper . .17 Valet®/Program Switch . 4 Light Flash Jumper . .17 Status LED . 4 Starter Kill Relay . 5 System Features Learn Routine . .18 System Feature Menu . .19 Connecting Your Wires . .5 To Access Another Feature . .19 Constant 12V . 5 To exit the learn routine . .19 Switched Ignition . .5 Parking Light Wire . 6 Feature Descriptions . 20 Door Switch Circuit . 6 Starter Wire . 7 Table of Zones . .21 Making Your Connections . .7 Rapid Resume Logic . .22 Primary Harness Diagram . .8 Troubleshooting . .22 Wire Connection Guide . .9 Primary Harness . .9 5-Pin Auxiliary Plug . .12 Door Lock Learn Routine . .16 ® PART NO. 415 Directed Electronics, Inc. © 1999 Directed Electronics, Inc. Vista, CA 1 N415A 2/99 Primary Control Module Harness Plug H1 514T Revenger 2-pin Soft Chirp micro siren LED plug Shock Sensor DRW-101 Adjustment 2-pin-mini blue valet/program plug 4-pin 5-pin optional auxiliary sensor plug plug Also Included: Plug-in Status LED Plug in Valet/program switch Primary Harness (H1) 5-Pin Auxiliary Harness Pre-wired Starter Kill Relay INSTALLATION POINTS TO REMEMBER Before beginning the installation: • Check with the customer on Status LED location. • Use seat and fender covers to protect the vehicle. • Remove the domelight fuse. This prevents accidentally draining the battery. • Roll down a window to avoid being locked out of the car.