Investigating the Security of EV Charging Mobile Applications as an Attack Surface

被引:14
作者
Sarieddine, Khaled [1 ]
Sayed, Mohammad Ali [1 ]
Torabi, Sadegh [2 ]
Atallah, Ribal [3 ]
Assi, Chadi [1 ]
机构
[1] Concordia Univ, Secur Res Ctr, 1515 St Catherine St W, Montreal H3G IS6, PQ, Canada
[2] George Mason Univ, Ctr Secure Informat Syst, 10401 York River Rd, Fairfax, VA 22030 USA
[3] Hydro Quebec Res Inst, 1800 Bd Lionel Boulet, Varennes J3X IS1, PQ, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Electric vehicle charging; cyber-physical systems; security analysis; mobile application; TOPOLOGY; IMPACT;
D O I
10.1145/3609508
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The adoption rate of EVs has witnessed a significant increase in recent years driven by multiple factors, chief among which is the increased flexibility and ease of access to charging infrastructure. To improve user experience and increase system flexibility, mobile applications have been incorporated into the EV charging ecosystem. EV charging mobile applications allow consumers to remotely trigger actions on charging stations and use functionalities such as start/stop charging sessions, pay for usage, and locate charging stations, to name a few. In this article, we study the security posture of the EV charging ecosystem against a new type of remote that exploits vulnerabilities in the EV charging mobile applications as an attack surface. We leverage a combination of static and dynamic analysis techniques to analyze the security of widely used EV charging mobile applications. Our analysis was performed on 31 of the most widely used mobile applications including their interactions with various components such as cloud management systems. The attack scenarios that exploit these vulnerabilities were verified on a real-time co-simulation test bed. Our discoveries indicate the lack of user/vehicle verification and improper authorization for critical functions, which allow adversaries to remotely hijack charging sessions and launch attacks against the connected critical infrastructure. The attacks were demonstrated using the EVCS mobile applications showing the feasibility and the applicability of our attacks. Indeed, we discuss specific remote attack scenarios and their impact on EV users. More importantly, our analysis results demonstrate the feasibility of leveraging existing vulnerabilities across various EV charging mobile applications to perform wide-scale coordinated remote charging/discharging attacks against the connected critical infrastructure (e.g., power grid), with significant economical and operational implications. Finally, we propose countermeasures to secure the infrastructure and impede adversaries from performing reconnaissance and launching remote attacks using compromised accounts.
引用
收藏
页数:28
相关论文
共 65 条
[11]  
Azim T, 2013, ACM SIGPLAN NOTICES, V48, P641, DOI [10.1145/2509136.2509549, 10.1145/2544173.2509549]
[12]  
Baker R, 2019, PROCEEDINGS OF THE 28TH USENIX SECURITY SYMPOSIUM, P407
[13]  
California ISO, 2021, Demand Trend
[14]   Inverter Probing for Power Distribution Network Topology Processing [J].
Cavraro, Guido ;
Kekatos, Vassilis .
IEEE TRANSACTIONS ON CONTROL OF NETWORK SYSTEMS, 2019, 6 (03) :980-992
[15]   Real-Time Identifiability of Power Distribution Network Topologies With Limited Monitoring [J].
Cavraro, Guido ;
Bernstein, Andrey ;
Kekatos, Vassilis ;
Zhang, Yingchen .
IEEE CONTROL SYSTEMS LETTERS, 2020, 4 (02) :325-330
[16]   Ensemble machine learning-based algorithm for electric vehicle user behavior prediction [J].
Chung, Yu-Wei ;
Khaki, Behnam ;
Li, Tianyi ;
Chu, Chicheng ;
Gadh, Rajit .
APPLIED ENERGY, 2019, 254
[17]   The Impact of Charging Plug-In Hybrid Electric Vehicles on a Residential Distribution Grid [J].
Clement-Nyns, Kristien ;
Haesen, Edwin ;
Driesen, Johan .
IEEE TRANSACTIONS ON POWER SYSTEMS, 2010, 25 (01) :371-380
[18]   Topology Estimation Using Graphical Models in Multi-Phase Power Distribution Grids [J].
Deka, Deepjyoti ;
Chertkov, Michael ;
Backhaus, Scott .
IEEE TRANSACTIONS ON POWER SYSTEMS, 2020, 35 (03) :1663-1673
[19]   Electric Vehicle Charging on Residential Distribution Systems: Impacts and Mitigations [J].
Dubey, Anamika ;
Santoso, Surya .
IEEE ACCESS, 2015, 3 :1871-1893
[20]  
DuncanGlover J., 2012, Power System Analysis& Design, SI Version