Evading Voltage-Based Intrusion Detection on Automotive CAN
Rohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik, Mathias Payer, Dongyan Xu
Abstract
—The controller area network (CAN) is widely adopted in modern automobiles to enable communications among in-vehicle electronic control units (ECUs). Lacking mainstream network security capabilities due to resource constraints, the CAN is susceptible to the ECU masquerade attack in which a compromised (attacker) ECU impersonates an uncompromised (victim) ECU and spoofs the latter’s CAN messages. A cost-effective state-of-the-art defense against such attacks is the CAN bus voltage-based intrusion detection system (VIDS), which identifies the source of each message using its voltage fingerprint on the bus. Since the voltage fingerprint emanates from an ECU’s hardware characteristics, an attacker ECU by itself cannot controllably modify it. As such, VIDS has been proved effective in detecting masquerade attacks that each involve a single attacker. In this paper, we discover a novel voltage corruption tactic that leverages the capabilities of two compromised ECUs (i.e., an attacker ECU working in tandem with an accomplice ECU) to corrupt the bus voltages recorded by the VIDS. By exploiting this tactic along with the fundamental deficiencies of the CAN protocol, we propose a novel masquerade attack called D UET , which evades all existing VIDS irrespective of the features and classification algorithms employed in them. D UET follows a two-stage attack strategy to first manipulate a victim ECU’s voltage fingerprint during VIDS retraining mode, and then impersonate the manipulated fingerprint during VIDS operation mode. Our evaluation of D UET on real CAN buses (including three in two real cars) demonstrates an impersonation success rate of at least 90% in evading two state-of-the-art VIDS
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- Exposing New Vulnerabilities of Error Handling Mechanism in CANKhaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik et al.USENIX Security 2021 · 30 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersAnna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren et al.CCS 2025 · 5 citations
- PhyScout: Detecting Sensor Spoofing Attacks via Spatio-temporal ConsistencyYuan Xu, Gelei Deng, Xingshuo Han, Guanlin Li et al.CCS 2024 · 2 citations
- ZBCAN: A Zero-Byte CAN Defense SystemKhaled Serag, Rohit Bhatia, Akram Faqih, Muslum Ozgur Ozmen et al.USENIX Security 2023
Builds on11
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Fingerprinting Electronic Control Units for Vehicle Intrusion DetectionKyong-Tak Cho, Kang G. ShinUSENIX Security 2016 · 524 citations
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 218 citations
- Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksMarcel Kneib, Christopher HuthCCS 2018 · 162 citations
Related papers
- EdgeTDC: On the Security of Time Difference of Arrival Measurements in CAN Bus SystemsMarc Roeschlin, Giovanni Camurati, Pascal Brunner, Mridula Singh et al.NDSS 2023
- RIDAS: Real-time identification of attack sources on controller area networksJiwoo Shin, Hyunghoon Kim, Seyoung Lee, Wonsuk Choi et al.USENIX Security 2023
- Vulnerability of Controller Area Network to Schedule-Based AttacksSena Hounsinou, Mark Stidd, Uchenna Ezeobi, Habeeb Olufowobi et al.RTSS 2021 · 16 citations
- CANvas: Fast and Inexpensive Automotive Network MappingSekar Kulandaivel, Tushar Goyal, Arnav Kumar Agrawal, Vyas SekarUSENIX Security 2019 · 49 citations
- ERACAN: Defending Against an Emerging CAN Threat ModelZhaozhou Tang, Khaled Serag, Saman A. Zonouz, Z. Berkay Celik et al.CCS 2024 · 5 citations
