USENIX Security2026Top-tier venue
A Formal Security Analysis of CAN XL
Zhaozhou Tang, Khaled Serag, Z. Berkay Celik, Vijay Ganesh, Saman Zonouz, Raheem Beyah
Abstract
For decades, the Controller Area Network (CAN) has been the backbone of in-vehicle communication. As modern vehicles integrate cameras, LiDARs, and AI components, classic CAN (CAN CC) faces growing limitations in bandwidth, functionality, and security. To fill these gaps, CAN XL was introduced as the next generation of CAN, aiming to offer longer payloads, higher bandwidth, and enhanced security.
CAN XL makes significant standard-level changes across multiple stack layers. It also introduces several security features, but it is unclear whether these are mere add-on extensions or whether the standard redesign itself tackles CAN's chronic security weakness: the MAC sub-layer. This sub-layer governs frame formats and error handling and has historically enabled many CAN CC attacks. As the industry transitions to CAN XL, the security posture of its yet-unexplored MAC sub-layer must be understood before widespread deployment.
This paper presents the first security analysis of the CAN XL standard, focusing on its MAC sub-layer. We develop a bit-precise CAN XL formal model and release it to facilitate future research. We design a formal analysis workflow guided by CAN XL's field-oriented structure to uncover vulnerabilities. Contrary to expectations, our analysis shows that CAN XL remains vulnerable to all known CAN CC MAC sub-layer issues while introducing seven new vulnerabilities, arguably worsening security. We validate them using commercial CAN XL controllers and demonstrate exploitability via two multi-stage attacks on a testbed simulating real vehicle traffic. Finally, we propose mitigations including formally verifying standard revisions that could prevent several attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 87526b5b-5448-430f-be05-9dda7da249c2Builds on8
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
- CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive MicrocontrollersSekar Kulandaivel, Shalabh Jain, Jorge Guajardo, Vyas SekarS&P 2021 · 35 citations
- Exposing New Vulnerabilities of Error Handling Mechanism in CANKhaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik et al.USENIX Security 2021 · 30 citations
- CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksAlvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino et al.CCS 2022 · 21 citations
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu et al.S&P 2024 · 16 citations
Related papers
- ERACAN: Defending Against an Emerging CAN Threat ModelZhaozhou Tang, Khaled Serag, Saman A. Zonouz, Z. Berkay Celik et al.CCS 2024 · 5 citations
- ZBCAN: A Zero-Byte CAN Defense SystemKhaled Serag, Rohit Bhatia, Akram Faqih, Muslum Ozgur Ozmen et al.USENIX Security 2023
- On Bit-level Reverse Engineering of Vehicular CAN BusYunlang Cai, Hanxue Shi, Xiaohang Wang, Haoting Shen et al.DAC 2025 · 2 citations
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry et al.CCS 2019 · 76 citations
- Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle ProtocolsShengtuo Hu, Qi Alfred Chen, Jiachen Sun, Yiheng Feng et al.USENIX Security 2021 · 18 citations
