USENIX Security2022Top-tier venue
Towards Automatically Reverse Engineering Vehicle Diagnostic Protocols
Le Yu, Yangyang Liu, Pengfei Jing, Xiapu Luo, Lei Xue, Kaifa Zhao, Yajin Zhou, Ting Wang, Guofei Gu, Sen Nie, Shi Wu
Abstract
In-vehicle protocols are very important to the security assessment and protection of modern vehicles since they are used in communicating with, accessing, and even manipulating ECUs (Electronic Control Units) that control various vehicle components. Unfortunately, the majority of in-vehicle protocols are proprietary without publicly available documents. Although recent studies proposed methods to reverse engineer the CAN protocol used in the communication among ECUs, they cannot be applied to vehicle diagnostics protocols, which have been widely exploited by attackers to launch remote attacks. In this paper, we propose a novel framework for automatically reverse engineering the diagnostic protocols of vehicles by leveraging professional diagnostic tools. Specifically, we design and develop a new cyber-physical system that uses a set of algorithms to control a programmable robotics arm with the aid of cameras to automatically trigger and capture the messages of diagnostics protocols as well as reverse engineer their formats, semantic meanings, and proprietary formulas required for processing the response messages. We perform a large-scale experiment to evaluate our prototype using 18 real vehicles. It successfully reverse engineers 570 messages (446 for reading sensor values and 124 for controlling components). The experimental results show that our framework achieves high precision in reverse engineering proprietary formulas and obtains much more messages than the prior approach based on app analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0c4206e7-5c7f-4df4-9c6d-d5d915120f5eCited by top-tier papers4
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu et al.S&P 2024 · 16 citations
- Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization FailuresYangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin et al.USENIX Security 2026
- SAID: State-aware Defense Against Injection Attacks on In-vehicle NetworkLei Xue, Yangyang Liu, Tianqi Li, Kaifa Zhao et al.USENIX Security 2022
- Recovering Process Variables from Industrial Network Traffic via Search-Based OptimizationChuan Sheng, Shan Jiang, Jianming Zhao, Yu YaoCCS 2026
Builds on7
- TriggerScope: Towards Detecting Logic Bombs in Android ApplicationsYanick Fratantonio, Antonio Bianchi, William K. Robertson, Engin Kirda et al.S&P 2016 · 161 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted PerturbationsPengfei Jing, Qiyi Tang, Yuefeng Du, Lei Xue et al.USENIX Security 2021 · 79 citations
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry et al.CCS 2019 · 76 citations
- Layout and Image Recognition Driving Cross-Platform Automated Mobile TestingShengcheng Yu, Chunrong Fang, Yexiao Yun, Yang FengICSE 2021 · 40 citations
Related papers
- On Bit-level Reverse Engineering of Vehicular CAN BusYunlang Cai, Hanxue Shi, Xiaohang Wang, Haoting Shen et al.DAC 2025 · 2 citations
- Reverse Engineering Industrial Protocols Driven By Control FieldsZhen Qin, Zeyu Yang, Yangyang Geng, Xin Che et al.INFOCOM 2024 · 17 citations
- CANvas: Fast and Inexpensive Automotive Network MappingSekar Kulandaivel, Tushar Goyal, Arnav Kumar Agrawal, Vyas SekarUSENIX Security 2019 · 49 citations
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
- Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksMarcel Kneib, Christopher HuthCCS 2018 · 162 citations
