Cyberattacks and Countermeasures for In-Vehicle Networks

被引:106
作者
Aliwa, Emad [1 ]
Rana, Omer [1 ]
Perera, Charith [1 ]
Burnap, Peter [1 ]
机构
[1] Cardiff Univ, 5 Parade, Cardiff CF24 3AA, Wales
基金
英国工程与自然科学研究理事会;
关键词
CAN bus; cybersecurity; intrusion detection systems; INTRUSION DETECTION; DETECTION SYSTEM; ARCHITECTURE; POWER;
D O I
10.1145/3431233
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
As connectivity between and within vehicles increases, so does concern about safety and security. Various automotive serial protocols are used inside vehicles such as Controller Area Network (CAN), Local Interconnect Network (LIN), and FlexRay. CAN Bus is the most used in-vehicle network protocol to support exchange of vehicle parameters between Electronic Control Units (ECUs). This protocol lacks security mechanisms by design and is therefore vulnerable to various attacks. Furthermore, connectivity of vehicles has made the CAN Bus vulnerable not only from within the vehicle but also from outside. With the rise of connected cars, more entry points and interfaces have been introduced on board vehicles, thereby also leading to a wider potential attack surface. Existing security mechanisms focus on the use of encryption, authentication, and vehicle Intrusion Detection Systems (IDS), which operate under various constraints such as low bandwidth, small frame size (e.g., in the CAN protocol), limited availability of computational resources, and real-time sensitivity. We survey and classify current cryptographic and IDS approaches and compare these approaches based on criteria such as real-time constraints, types of hardware used, changes in CAN Bus behaviour, types of attack mitigation, and software/ hardware used to validate these approaches. We conclude with mitigation strategies limitations and research challenges for the future.
引用
收藏
页数:37
相关论文
共 157 条
[31]  
ETSI, 2001, 35201 ETSI 3GPP TS
[32]  
Farag W.A., 2017, Modeling, Simulation, and Applied Optimization (ICMSAO), 2017 7th International Conference on, P1
[33]  
Fassak Samir, 2017, P 2017 INT C WIR NET
[34]  
Forsberg Andreas, TECHNICAL REPORT
[35]   Fuzz Testing for Automotive Cyber-security [J].
Fowler, Daniel ;
Bryans, Jeremy ;
Shaikh, Siraj Ahmed ;
Wooderson, Paul .
2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W), 2018, :239-246
[36]  
Gmbh R. B., 1991, ROBERT BOSCH GMBH CA
[37]  
Gmiden Mabrouka, 2017, P 2016 17 INT C SCI, P176
[38]  
Groza B., 2012, Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), Proceedings of the 11th International Conference, CANS 2012, Darmstadt, Germany, 1214 December 2012, P185, DOI 10.1007/978-3-642-35404-5_15
[39]   LiBrA-CAN: Lightweight Broadcast Authentication for Controller Area Networks [J].
Groza, Bogdan ;
Murvay, Stefan ;
Van Herrewege, Anthony ;
Verbauwhede, Ingrid .
ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2017, 16 (03)
[40]   Efficient Protocols for Secure Broadcast in Controller Area Networks [J].
Groza, Bogdan ;
Murvay, Stefan .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2013, 9 (04) :2034-2042