A Formal Security Analysis of CAN XL
Zhaozhou Tang, Khaled Serag, Z. Berkay Celik, Vijay Ganesh, Saman Zonouz, Raheem Beyah
摘要
For decades, the Controller Area Network (CAN) has been the backbone of in-vehicle communication. As modern vehicles integrate cameras, LiDARs, and AI components, classic CAN (CAN CC) faces growing limitations in bandwidth, functionality, and security. To fill these gaps, CAN XL was introduced as the next generation of CAN, aiming to offer longer payloads, higher bandwidth, and enhanced security.
CAN XL makes significant standard-level changes across multiple stack layers. It also introduces several security features, but it is unclear whether these are mere add-on extensions or whether the standard redesign itself tackles CAN's chronic security weakness: the MAC sub-layer. This sub-layer governs frame formats and error handling and has historically enabled many CAN CC attacks. As the industry transitions to CAN XL, the security posture of its yet-unexplored MAC sub-layer must be understood before widespread deployment.
This paper presents the first security analysis of the CAN XL standard, focusing on its MAC sub-layer. We develop a bit-precise CAN XL formal model and release it to facilitate future research. We design a formal analysis workflow guided by CAN XL's field-oriented structure to uncover vulnerabilities. Contrary to expectations, our analysis shows that CAN XL remains vulnerable to all known CAN CC MAC sub-layer issues while introducing seven new vulnerabilities, arguably worsening security. We validate them using commercial CAN XL controllers and demonstrate exploitability via two multi-stage attacks on a testbed simulating real vehicle traffic. Finally, we propose mitigations including formally verifying standard revisions that could prevent several attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 被引用 238 次
- CANNON: Reliable and Stealthy Remote Shutdown Attacks via Unaltered Automotive MicrocontrollersSekar Kulandaivel, Shalabh Jain, Jorge Guajardo, Vyas SekarS&P 2021 · 被引用 35 次
- Exposing New Vulnerabilities of Error Handling Mechanism in CANKhaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik 等USENIX Security 2021 · 被引用 30 次
- CANflict: Exploiting Peripheral Conflicts for Data-Link Layer Attacks on Automotive NetworksAlvise de Faveri Tron, Stefano Longari, Michele Carminati, Mario Polino 等CCS 2022 · 被引用 21 次
- Revisiting Automotive Attack Surfaces: a Practitioners' PerspectivePengfei Jing, Zhiqiang Cai, Yingjie Cao, Le Yu 等S&P 2024 · 被引用 16 次
相关 Paper
- ERACAN: Defending Against an Emerging CAN Threat ModelZhaozhou Tang, Khaled Serag, Saman A. Zonouz, Z. Berkay Celik 等CCS 2024 · 被引用 5 次
- ZBCAN: A Zero-Byte CAN Defense SystemKhaled Serag, Rohit Bhatia, Akram Faqih, Muslum Ozgur Ozmen 等USENIX Security 2023
- On Bit-level Reverse Engineering of Vehicular CAN BusYunlang Cai, Hanxue Shi, Xiaohang Wang, Haoting Shen 等DAC 2025 · 被引用 2 次
- LibreCAN: Automated CAN Message TranslatorMert D. Pesé, Troy Stacer, C. Andrés Campos, Eric Newberry 等CCS 2019 · 被引用 76 次
- Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle ProtocolsShengtuo Hu, Qi Alfred Chen, Jiachen Sun, Yiheng Feng 等USENIX Security 2021 · 被引用 18 次
