USENIX Security2019Top-tier venue
CANvas: Fast and Inexpensive Automotive Network Mapping
Sekar Kulandaivel, Tushar Goyal, Arnav Kumar Agrawal, Vyas Sekar
Abstract
Modern vehicles contain tens of Electronic Control Units (ECUs), several of which communicate over the Controller Area Network (CAN) protocol. As such, in-vehicle networks have become a prime target for automotive network attacks. To understand the security of these networks, we argue that we need tools analogous to network mappers for traditional networks that provide an in-depth understanding of a network's structure. To this end, our goal is to develop an automotive network mapping tool that assists in identifying a vehicle's ECUs and their communication with each other. A significant challenge in designing this tool is the broadcast nature of the CAN protocol, as network messages contain no information about their sender or recipients. To address this challenge, we design and implement CANvas, an automotive network mapper that identifies transmitting ECUs with a pairwise clock offset tracking algorithm and identifies receiving ECUs with a forced ECU isolation technique. CANvas generates network maps in under an hour that identify a previously unknown ECU in a 2009 Toyota Prius and identify lenient message filters in a 2017 Ford Focus.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 40f9903c-810a-4b9d-891d-6ef3cba42475Cited by top-tier papers5
- CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive MicrocontrollersSekar Kulandaivel, Shalabh Jain, Jorge Guajardo, Vyas SekarS&P 2021 · 35 citations
- Exposing New Vulnerabilities of Error Handling Mechanism in CANKhaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik et al.USENIX Security 2021 · 30 citations
- CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksAlvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino et al.CCS 2022 · 21 citations
- Constraint-Guided Clustering for Identifying in-Vehicle Electronic Control Units from Voltage DataBogdan Groza, Patricia Iosif, Lucian PopaAAAI 2026
- RIDAS: Real-time identification of attack sources on controller area networksJiwoo Shin, Hyunghoon Kim, Seyoung Lee, Wonsuk Choi et al.USENIX Security 2023
Builds on2
Related papers
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry et al.CCS 2019 · 76 citations
- Vulnerability of Controller Area Network to Schedule-Based AttacksSena Hounsinou, Mark Stidd, Uchenna Ezeobi, Habeeb Olufowobi et al.RTSS 2021 · 16 citations
- Evading Voltage-Based Intrusion Detection on Automotive CANRohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik et al.NDSS 2021
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 218 citations
- Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksMarcel Kneib, Christopher HuthCCS 2018 · 162 citations
