Skip to main content
QUICK REVIEW

[论文解读] Who Killed My Parked Car?

Kyong-Tak Cho, Yuseung Kim|arXiv (Cornell University)|Jan 23, 2018
Vehicular Ad Hoc Networks (VANETs)参考文献 10被引用 7
一句话总结

本文揭示了两种新型网络攻击——电池耗尽攻击与拒绝车身控制(DoB)攻击——攻击者可利用标准化的车载唤醒功能,在点火开关关闭的情况下使停泊中的车辆瘫痪。通过注入唤醒消息,攻击者可激活电子控制单元(ECU),并操控其导致电池耗尽或强制进入无法恢复的总线关闭(bus-off)状态,从而使车辆无法使用,且无需物理接触车辆。

ABSTRACT

We find that the conventional belief of vehicle cyber attacks and their defenses---attacks are feasible and thus defenses are required only when the vehicle's ignition is turned on---does not hold. We verify this fact by discovering and applying two new practical and important attacks: battery-drain and Denial-of-Body-control (DoB). The former can drain the vehicle battery while the latter can prevent the owner from starting or even opening/entering his car, when either or both attacks are mounted with the ignition off. We first analyze how operation (e.g., normal, sleep, listen) modes of ECUs are defined in various in-vehicle network standards and how they are implemented in the real world. From this analysis, we discover that an adversary can exploit the wakeup function of in-vehicle networks---which was originally designed for enhanced user experience/convenience (e.g., remote diagnosis, remote temperature control)---as an attack vector. Ironically, a core battery-saving feature in in-vehicle networks makes it easier for an attacker to wake up ECUs and, therefore, mount and succeed in battery-drain and/or DoB attacks. Via extensive experimental evaluations on various real vehicles, we show that by mounting the battery-drain attack, the adversary can increase the average battery consumption by at least 12.57x, drain the car battery within a few hours or days, and therefore immobilize/cripple the vehicle. We also demonstrate the proposed DoB attack on a real vehicle, showing that the attacker can cut off communications between the vehicle and the driver's key fob by indefinitely shutting down an ECU, thus making the driver unable to start and/or even enter the car.

研究动机与目标

  • 挑战传统观点,即车辆网络攻击仅在点火开启时才可实施。
  • 探究为提升便利性而设计的车载网络唤醒功能,是否可能被滥用为攻击向量。
  • 展示即使在车辆停泊且断电状态下,仍可实施实际攻击,从而破坏车辆可用性。
  • 评估电池耗尽与DoB攻击在真实车辆上的可行性及其影响。
  • 提出缓解措施,并强调需重新评估标准ECU行为与恢复策略。

提出的方法

  • 分析车载网络标准(如ISO 11898-1)及真实ECU实现,识别唤醒功能漏洞。
  • 通过逆向工程与模糊测试,发现可触发ECU唤醒与控制功能的消息ID。
  • 设计基于驱动上下文的方案,以减少识别电池耗尽攻击控制消息所需的工作量。
  • 在点火关闭状态下注入唤醒消息,激活ECU后发送控制消息,触发电池耗尽或总线关闭状态。
  • 利用部分ECU未按ISO 11898-1标准从总线关闭状态恢复的事实,实现持久性DoB攻击效果。
  • 在2017款真实车辆上评估攻击效果,测量电池消耗增加情况及车辆瘫痪成功率。

实验结果

研究问题

  • RQ1是否可在点火关闭状态下成功实施车辆网络攻击,从而挑战传统认知?
  • RQ2标准化唤醒功能在多大程度上可被滥用,从而危及车辆可用性?
  • RQ3电池耗尽与DoB攻击在耗尽电池或禁用关键ECU方面的有效性如何?
  • RQ4ECU配置,尤其是总线关闭恢复行为,在DoB攻击成功中的作用是什么?
  • RQ5现有安全机制(如入侵检测系统IDS)能否在不增加电池消耗的前提下,检测此类攻击?

主要发现

  • 电池耗尽攻击使平均电池消耗增加至少12.57倍,可在数小时或数天内耗尽电池。
  • DoB攻击成功阻止了远程控制模块(RCM)在总线关闭状态后的恢复,导致遥控钥匙通信被阻断。
  • 配备更多待机功能的新款车型更为脆弱,因为可被唤醒和控制的ECU数量更多。
  • 本应提升能效与用户便利性的唤醒功能,被攻击者作为主要攻击向量加以利用。
  • DoB攻击的成功高度依赖于OEM特定的总线关闭恢复策略,而这些策略通常未被实现或无法恢复。
  • 缓解措施如基于模式的IDS唤醒机制与定期电池荷电状态(SoC)检查,可在不持续运行的前提下检测异常活动。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。