Automated Cross-Platform Reverse Engineering of CAN Bus Commands From Mobile Apps
Haohuang Wen, Qingchuan Zhao, Qi Alfred Chen, Zhiqiang Lin
摘要
In modern automobiles, CAN bus commands are necessary for a wide range of applications such as diagnosis, security monitoring, and recently autonomous driving. However, only a small portion of CAN bus commands is standardized, and a vast majority of them is developed privately by car manufacturers. Today, the most effective way of revealing the proprietary CAN bus commands is to reverse engineer with real cars, which unfortunately is time-consuming and costly. In this paper, we propose a cost-effective (no real car needed) and automatic (no human intervention required) system, CANHUNTER, for reverse engineering of CAN bus commands using just car companion mobile apps. To achieve high effectiveness, we design an efficient technique to uncover the syntactics of CAN bus commands with backward slicing and dynamic forced execution, and a novel algorithm to uncover the semantics of CAN bus commands by leveraging code-level semantic clues. We have implemented a prototype of CANHUNTER for both Android and iOS platforms, and tested it with all free car companion apps (236 in total) from both Google Play and Apple App Store. Among these apps, CANHUNTER discovered 182, 619 unique CAN bus commands with 86.1% of them revealed with semantics, covering 360 car models from 21 car manufactures. We have also evaluated their correctness (both syntactics and semantics) using public resources, cross-platform and cross-app validation, and also realcar testing, with which over 70% of all the uncovered commands are validated. We observe no inconsistency in cross-platform and cross-app validation. While there are 3 semantic inconsistency among 241 manually validated CAN bus commands from public resources and real-car testing, we find that these three cases are actually caused by mistakes from app developers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Diane: Identifying Fuzzing Triggers in Apps to Generate Under-constrained Inputs for IoT DevicesNilo Redini, Andrea Continella, Dipanjan Das, Giulio De Pasquale 等S&P 2021 · 被引用 72 次
- IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App AnalysisDavid Schmidt, Carlotta Tagliaro, Kevin Borgolte, Martina LindorferCCS 2023 · 被引用 13 次
- From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverXingli Zhang, Yazhou Tu, Yan Long, Liqun Shan 等S&P 2024 · 被引用 6 次
- BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface LayerWenqiang Li, Haohuang Wen, Zhiqiang LinCCS 2024 · 被引用 1 次
- Towards Automatically Reverse Engineering Vehicle Diagnostic ProtocolsLe Yu, Yangyang Liu, Pengfei Jing, Xiapu Luo 等USENIX Security 2022
它引用的顶会 Paper8
- Fingerprinting Electronic Control Units for Vehicle Intrusion DetectionKyong-Tak Cho, Kang G. ShinUSENIX Security 2016 · 被引用 524 次
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang 等USENIX Security 2017 · 被引用 231 次
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang 等S&P 2019 · 被引用 160 次
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 被引用 123 次
- Automatic Fingerprinting of Vulnerable BLE IoT Devices with Static UUIDs from Mobile AppsChaoshun Zuo, Haohuang Wen, Zhiqiang Lin, Yinqian ZhangCCS 2019 · 被引用 77 次
相关 Paper
- On Bit-level Reverse Engineering of Vehicular CAN BusYunlang Cai, Hanxue Shi, Xiaohang Wang, Haoting Shen 等DAC 2025 · 被引用 2 次
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry 等CCS 2019 · 被引用 76 次
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 被引用 238 次
- Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksMarcel Kneib, Christopher HuthCCS 2018 · 被引用 162 次
- Obfuscated Priority Assignment to CAN-FD Messages with Dependencies: A Swapping-based and Affix-Matching ApproachGuoqi Xie, Debayan Roy, Yawen Zhang, Renfa Li 等DAC 2021 · 被引用 1 次
