Revisiting Automotive Attack Surfaces: a Practitioners' Perspective
Pengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu, Yuefeng Du, Wenkai Zhang, Chenxiong Qian, Xiapu Luo, Sen Nie, Shi Wu
Abstract
As modern vehicles become increasingly complex in terms of both external attack surfaces and internal in-vehicle network (IVN) topology, ensuring their cybersecurity remains a challenge. Existing standards and regulations, such as WP29 R155e and ISO 21434, attempt to establish a baseline for automotive cybersecurity, but their sufficiency in addressing the evolving threats is unclear. To fill in this gap, we first carried out an in-depth interview study with 15 experts in automotive cybersecurity, uncovering the particular challenges encountered during security activities and the limitations of current regulations. We identified 20 key insights from the interview data, ranging from the challenges and gaps in the existing automotive security industry to the limitations and recommendations for current regulations. Notably, we discovered that the quality of threat cases provided by existing regulations is unsatisfactory, and the Threat Analysis and Risk Assessment (TARA) process is often highly inefficient due to the lack of automatic tools. In response to the above limitations, we first built an improved threat database for automotive systems using the collected interview data, which enhanced the existing database both quantitatively and qualitatively. Additionally, we present CarVal, a datalog-based approach designed to infer multi-stage attack paths in IVNs and calculate risk values, thereby making TARA more efficient for automotive systems. By applying CarVal to five real vehicles, we performed extensive security analysis based on the generated attack paths and successfully exploited the corresponding attack chains in the newly gateway-segmented IVN, uncovering new automotive attack surfaces that previous research failed to cover, including the in-vehicle browser, official mobile app, backend server, and in-vehicle malware.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f5f72489-3308-46f3-b31e-7fe0882755b8Cited by top-tier papers8
- Automating Function-Level TARA for Automotive Full-Lifecycle SecurityYuqiao Yang, Yongzhao Zhang, Wenhao Liu, Jun Li et al.NDSS 2026 · 5 citations
- A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersAnna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren et al.CCS 2025 · 5 citations
- SECV: Securing Connected Vehicles with Hardware Trust AnchorsMartin Kayondo, Junseung You, Eunmin Kim, Jiwon Seo et al.NDSS 2026 · 1 citation
- Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization FailuresYangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin et al.USENIX Security 2026
- Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World ExploitsYuelin Wang, Yuqiao Ning, Yanbang Sun, Xiaofei Xie et al.ICSE 2026
Builds on14
- DolphinAttack: Inaudible Voice CommandsGuoming Zhang, Chen Yan, Xiaoyu Ji, Tianchen Zhang et al.CCS 2017 · 753 citations
- Hidden Voice CommandsNicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang et al.USENIX Security 2016 · 672 citations
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World AttacksYulong Cao, Ningfei Wang, Chaowei Xiao, Dawei Yang et al.S&P 2021 · 309 citations
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
Related papers
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry et al.CCS 2019 · 76 citations
- The Challenges and Opportunities with Cybersecurity Regulations: A Case Study of the US Electric Power SectorSena Sahin, Burak Sahin, Robin Berthier, Kate Davis et al.CCS 2025 · 1 citation
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
- Losing the Car Keys: Wireless PHY-Layer Insecurity in EV ChargingRichard Baker, Ivan MartinovicUSENIX Security 2019 · 67 citations
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland SecurityWilliam P. Maxam III, James C. DavisUSENIX Security 2024 · 14 citations
