Who Killed My Parked Car?
نویسندگان
چکیده
We find that the conventional belief of vehicle cyber attacks and their defenses—attacks are feasible and thus defenses are required only when the vehicle’s ignition is turned on—does not hold. We verify this fact by discovering and applying two new practical and important attacks: battery-drain and Denial-of-Body-control (DoB). The former can drain the vehicle battery while the latter can prevent the owner from starting or even opening/entering his car, when either or both attacks are mounted with the ignition off. We first analyze how operation (e.g., normal, sleep, listen) modes of ECUs are defined in various in-vehicle network standards and how they are implemented in the real world. From this analysis, we discover that an adversary can exploit the wakeup function of in-vehicle networks—which was originally designed for enhanced user experience/convenience (e.g., remote diagnosis, remote temperature control)—as an attack vector. Ironically, a core battery-saving feature in in-vehicle networks makes it easier for an attacker to wake up ECUs and, therefore, mount and succeed in batterydrain and/or DoB attacks. Via extensive experimental evaluations on various real vehicles, we show that by mounting the battery-drain attack, the adversary can increase the average battery consumption by at least 12.57x, drain the car battery within a few hours or days, and therefore immobilize/cripple the vehicle. We also demonstrate the proposed DoB attack on a real vehicle, showing that the attacker can cut off communications between the vehicle and the driver’s key fob by indefinitely shutting down an ECU, thus making the driver unable to start and/or even enter the car.
منابع مشابه
Experimental and Numerical Investigation of Air Temperature Distribution inside a Car under Solar Load Condition
In this work both experimental and numerical analysis are carried out to investigate the effect of solar radiation on the cabin air temperature of Maruti Suzuki Celerio car parked for 90 min under solar load condition. The experimental and numerical analysis encompasses on temperature increment of air at various locations ins...
متن کاملAugmented Reality-based Guidance for Indoor Parked-car Search Using Omni-vision Techniques
Many people have the experience of getting lost in large parking lots when trying to find their parked cars. To solve this problem, an augmented reality (AR)-based automatic guidance system is proposed to help a user to find his/her parked car quickly. With multiple fisheye cameras affixed to the ceiling of the parking lot for image acquisition, the proposed system includes four major functions...
متن کاملResearch Proposal: Rendevous Problems and Search Games on Planar Graphs
Since seeing a couple very simple graph theory problems in middle school, graph theory has captured my attention. My first algorithms course was last year and it was one of my favorite classes. I’m currently taking Extremal Combinatorics which has covered a variety of graph theory problems. Last summer, I also was in an REU which worked on a graph theory problem and really enjoyed working on pr...
متن کاملMarkov chain of distances between parked cars
We describe the distribution of distances between parked cars as a solution of certain Markov process and show that its solution is obtained with the help of a distributional fixed point equation. Under certain conditions the process is solved explicitly. The resulting probability density is compared with the actual parking data measured in the city. We focus on the spacing distribution between...
متن کاملA second row Parking Paradox
We consider two variations of the discrete car parking problem where at every vertex of Z a car arrives with rate one, now allowing for parking in two lines. a) The car parks in the first line whenever the vertex and all of its nearest neighbors are not occupied yet. It can reach the first line if it is not obstructed by cars already parked in the second line (“screening”). b) The car parks acc...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1801.07741 شماره
صفحات -
تاریخ انتشار 2018