CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive Networks
Alvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino, Stefano Zanero
摘要
Current research in the automotive domain has proven the limitations of the Controller Area Network (CAN) protocol from a security standpoint. Application-layer attacks, which involve the creation of malicious packets, are deemed feasible from remote but can be easily detected by modern Intrusion Detection Systems (IDSs). On the other hand, more recent link-layer attacks are stealthier and possibly more disruptive but require physical access to the bus. In this paper, we present CANflict, a software-only approach that allows reliable manipulation of the CAN bus at the data link layer from an unmodified microcontroller, overcoming the limitations of state-of-the-art works. We demonstrate that it is possible to deploy stealthy CAN link-layer attacks from a remotely compromised ECU, targeting another ECU on the same CAN network. To do this, we exploit the presence of pin conflicts between microcontroller peripherals to craft polyglot frames, which allows an attacker to control the CAN traffic at the bit level and bypass the protocol's rules. We experimentally demonstrate the effectiveness of our approach on high-, mid-, and low-end microcontrollers, and we provide the ground for future research by releasing an extensible tool that can be used to implement our approach on different platforms and to build CAN countermeasures at the data link layer. CCS CONCEPTS • Security and privacy → Hardware attacks and countermeasures; • Networks → Cyber-physical networks;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Cloud-Native Carjacking: Fleet-wide Compromise via Telematics Authorization FailuresYangyang Liu, Zhengjie Du, Xiaofang Wang, Yang Yin 等USENIX Security 2026
- A Formal Security Analysis of CAN XLZhaozhou Tang, Khaled Serag, Z. Berkay Celik, Vijay Ganesh 等USENIX Security 2026
- BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnetQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang 等NDSS 2026
它引用的顶会 Paper4
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 被引用 238 次
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 被引用 218 次
- CANvas: Fast and Inexpensive Automotive Network MappingSekar Kulandaivel, Tushar Goyal, Arnav Kumar Agrawal, Vyas SekarUSENIX Security 2019 · 被引用 49 次
- CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive MicrocontrollersSekar Kulandaivel, Shalabh Jain, Jorge Guajardo, Vyas SekarS&P 2021 · 被引用 35 次
相关 Paper
- Vulnerability of Controller Area Network to Schedule-Based AttacksSena Hounsinou, Mark Stidd, Uchenna Ezeobi, Habeeb Olufowobi 等RTSS 2021 · 被引用 16 次
- ZBCAN: A Zero-Byte CAN Defense SystemKhaled Serag, Rohit Bhatia, Akram Faqih, Muslum Ozgur Ozmen 等USENIX Security 2023
- Evading Voltage-Based Intrusion Detection on Automotive CANRohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik 等NDSS 2021
- EdgeTDC: On the Security of Time Difference of Arrival Measurements in CAN Bus SystemsMarc Roeschlin, Giovanni Camurati, Pascal Brunner, Mridula Singh 等NDSS 2023
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry 等CCS 2019 · 被引用 76 次
