Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization Failures
Yangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin, Xiapu Luo
摘要
Modern connected vehicles increasingly rely on cloud-centric telematics backends to provide remote control, telemetry, media access, and other software-defined functionality. Although these platforms commonly employ endpoint hardening and encrypted communication, such measures do not ensure correct backend authorization. Across the platforms we evaluated, cloud services often accepted a valid vehicle identity without consistently binding that identity to the specific topic, object, or command target being accessed. We investigate this failure mode by recovering reusable authentication material from a seed vehicle and testing whether backend authorization remains properly scoped to vehicle-specific resources across MQTT, HTTPS, and SMS. On several legacy platforms, process-memory inspection exposed client certificates, private keys, tokens, or session artifacts sufficient to authenticate to backend services. Using this material, we established authenticated backend sessions and then modified logical vehicle identifiers, such as Vehicle Identification Numbers (VINs), at the application layer. We discovered previously unknown authorization vulnerabilities in telematics platforms used by three major OEMs. Starting from a single seed vehicle under the attacker's control, we demonstrate cross-vehicle privilege escalation without physical access to victim vehicles and without OEM-internal privileges. These flaws enable remote vehicle control, unauthorized access to private surveillance media, and spoofed fallback commands. We conclude with root-cause analysis informed by coordinated disclosure and derive mitigation lessons for identity-bound, Zero-Trust-style telematics authorization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- Lock It and Still Lose It - on the (In)Security of Automotive Remote Keyless Entry SystemsFlavio D. Garcia, David F. Oswald, Timo Kasper, Pierre PavlidèsUSENIX Security 2016 · 被引用 151 次
- Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted PerturbationsPengfei Jing, Qiyi Tang, Yuefeng Du, Lei Xue 等USENIX Security 2021 · 被引用 79 次
- CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksAlvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino 等CCS 2022 · 被引用 21 次
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu 等S&P 2024 · 被引用 16 次
- ERACAN: Defending Against an Emerging CAN Threat ModelZhaozhou Tang, Khaled Serag, Saman A. Zonouz, Z. Berkay Celik 等CCS 2024 · 被引用 5 次
相关 Paper
- BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control SystemsJerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani 等USENIX Security 2026
- BACHunter: Detecting Broken Access Control Vulnerabilities in Intelligent Connected VehiclesYanbang Sun, Xiaohong Li, Quanzhou Wang, Hebo Leng 等S&P 2026
- Shadow Tokens: Uncovering the Broken Permission Revocation Vulnerability in Intelligent Connected VehiclesYanbang Sun, Hebo Leng, Qiang Hu, Xiaofei Xie 等CCS 2026
- Head Unit at Risk: Cross-Domain Attacks via In-Vehicle Infotainment SystemsYanbo Xu, Yan Meng, Guoxing Chen, Haojin ZhuCCS 2026
- SECV: Securing Connected Vehicles with Hardware Trust AnchorsMartin Kayondo, Junseung You, Eunmin Kim, Jiwon Seo 等NDSS 2026 · 被引用 1 次
