Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle Protocols
Shengtuo Hu, Qi Alfred Chen, Jiachen Sun, Yiheng Feng, Z. Morley Mao, Henry X. Liu
摘要
With the development of the emerging Connected Vehicle (CV) technology, vehicles can wirelessly communicate with traffic infrastructure and other vehicles to exchange safety and mobility information in real time. However, the integrated communication capability inevitably increases the attack surface of vehicles, which can be exploited to cause safety hazard on the road. Thus, it is highly desirable to systematically understand design-level flaws in the current CV network stack as well as in CV applications, and the corresponding security/safety consequences so that these flaws can be proactively discovered and addressed before large-scale deployment. In this paper, we design CVAnalyzer, a system for discovering design-level flaws for availability violations of the CV network stack, as well as quantifying the corresponding security/safety consequences. To achieve this, CVAnalyzer combines the attack discovery capability of a general model checker and the quantitative threat assessment capability of a probabilistic model checker. Using CVAnalyzer, we successfully uncovered 4 new DoS (Denial-of-Service) vulnerabilities of the latest CV network protocols and 14 new DoS vulnerabilities of two CV platoon management protocols. Our quantification results show that these attacks can have as high as 99% success rates, and in the worst case can at least double the delay in packet processing, violating the latency requirement in CV communication. We implemented and validated all attacks in a real-world testbed, and also analyzed the fundamental causes to propose potential solutions. We have reported our findings in the CV network protocols to the IEEE 1609 Working Group, and the group has acknowledged the discovered vulnerabilities and plans to adopt our solutions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- On the (In)Security of Secure ROS2Gelei Deng, Guowen Xu, Yuan Zhou, Tianwei Zhang 等CCS 2022 · 被引用 31 次
- A Critical Revisit of Adversarial Robustness in 3D Point Cloud Recognition with Diffusion-Driven PurificationJiachen Sun, Jiongxiao Wang, Weili Nie, Zhiding Yu 等ICML 2023 · 被引用 24 次
- A Sea of Cyber Threats: Maritime Cybersecurity from the Perspective of MarinersAnna Raymaker, Akshaya Kumar, Miuyin Yong Wong, Ryan Pickren 等CCS 2025 · 被引用 5 次
- Batten the Hatches: Cybersecurity with Military MarinersRyan Von Brock, Anna Raymaker, Animesh Chhotaray, Frank Li 等CCS 2026
- Automata-Based Automated Detection of State Machine Bugs in Protocol ImplementationsPaul Fiterau-Brostean, Bengt Jonsson, Konstantinos Sagonas, Fredrik TåquistNDSS 2023
它引用的顶会 Paper3
- A Formal Analysis of 5G AuthenticationDavid A. Basin, Jannik Dreier, Lucca Hirschi, Sasa Radomirovic 等CCS 2018 · 被引用 428 次
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 被引用 225 次
- Exposing Congestion Attack on Emerging Connected Vehicle based Traffic Signal ControlQi Alfred Chen, Yucheng Yin, Yiheng Feng, Z. Morley Mao 等NDSS 2018 · 被引用 107 次
相关 Paper
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 被引用 238 次
- Cyber-Physical Inconsistency Vulnerability Identification for Safety Checks in Robotic VehiclesHongjun Choi, Sayali Kate, Yousra Aafer, Xiangyu Zhang 等CCS 2020 · 被引用 22 次
- Towards Understanding and Characterizing Vulnerabilities in Intelligent Connected Vehicles through Real-World ExploitsYuelin Wang, Yuqiao Ning, Yanbang Sun, Xiaofei Xie 等ICSE 2026
- Vehicle-to-Nothing? Securing C-V2X Against Protocol-Aware DoS AttacksGeoff Twardokus, Hanif RahbariINFOCOM 2022 · 被引用 28 次
- ERACAN: Defending Against an Emerging CAN Threat ModelZhaozhou Tang, Khaled Serag, Saman A. Zonouz, Z. Berkay Celik 等CCS 2024 · 被引用 5 次
