Towards an Integrated Penetration Testing Environment for the CAN Protocol

11/23/2021
by   Giampaolo Bella, et al.
0

The Controller Area Network (CAN) is the most common protocol interconnecting the various control units of modern cars. Its vulnerabilities are somewhat known but we argue they are not yet fully explored – although the protocol is obviously not secure by design, it remains to be thoroughly assessed how and to what extent it can be maliciously exploited. This manuscript describes the early steps towards a larger goal, that of integrating the various CAN pentesting activities together and carry them out holistically within an established pentesting environment such as the Metasploit Framework. In particular, we shall see how to build an exploit that upsets a simulated tachymeter running on a minimal Linux machine. While both portions are freely available from the authors' Github shares, the exploit is currently subject to a Metasploit pull request.

READ FULL TEXT

page 4

page 7

page 8

research
11/20/2021

TOUCAN: A proTocol tO secUre Controller Area Network

Modern cars are no longer purely mechanical devices but shelter so much ...
research
02/20/2019

Identification of Bugs and Vulnerabilities in TLS Implementation for Windows Operating System Using State Machine Learning

TLS protocol is an essential part of secure Internet communication. In p...
research
11/15/2017

Security Issues in Controller Area Networks in Automobiles

Modern vehicles may contain a considerable number of ECUs (Electronic Co...
research
12/15/2021

EXT-TAURUM P2T: an Extended Secure CAN-FD Architecture for Road Vehicles

The automobile industry is no longer relying on pure mechanical systems;...
research
06/06/2022

CAN-MM: Multiplexed Message Authentication Code for Controller Area Network message authentication in road vehicles

The automotive market is increasingly profitable for cyberattacks with t...
research
10/02/2019

Sensor Networks in Healthcare: Ensuring Confidentiality and User Anonymity in WBAN

Wireless body area network(WBAN) is becoming more popular in recent year...

Please sign up or login with your details

Forgot password? Click here to reset