Connected Cars: Generic Hacking and Threat Model

In previous posts, we talked about what threatens the owners of connected cars and discussed ways to hack such vehicles. In this post, we will discuss the generalized hacking method and threat model for smart vehicles, resulting from the third part of our study, Driving Security Into Connected Cars: Threat Model and Recommendations .





Screenshot of an interactive illustration for the study with examples of DREAD attacks from the Trend Micro study at the link above
Screenshot of an interactive illustration for the study with examples of DREAD attacks from the Trend Micro study at the link above

Generalized remote hacking method

Jeep Cherokee, BMW Tesla. , , , CAN- .





A universal template for a remote attack on a connected car.  Source: Trend Micro
. : Trend Micro

:





  1.  β€” Wi‑Fi‑. Β« Β» (MitM) , Wi-Fi.





  2. , - . . , .





  3. - -, , WebKit. , Linux shell .





  4. , shell, , . root- . Linux, , , .





  5. , , , . CAN- , , CAN- . , .





  6. , . «» , .





  7. , CAN- . / CAN-. , CAN- CAN-.





  8. CAN- ID CAN-, .





, , . . .





, (Intelligent Transportation System, ITS). , , - / . :





  • V2X, ;





  • V2X, ;





  • ITS;





  • MitM- ITS;





  • ITS;





  • / ;





  • ITS;





  • MitM- ;





  • , ;





  • ;





  • CAN;





  • «» ;





  • - ;





  • ;





  • ;





  • , ;





  • ;





  • ;





  • ;





  • Shodan;





  • , , RDS-TMC, «» .





  • Β« Β» (DDoS) ITS;





  • DDoS- ITS;





  • ;





  • ;





  • , , SQL-, (XSS), DNS;





  • V2X;





  • ;





  • V2X .





β€” , V2X- ITS ITS. , , β€” , .





.





, , , . , .





. DREAD, :





  • (Damage potential): , ?





  • (Reproducibility): ?





  • (Exploitability): ?





  • (Affected users): ?





  • (Discoverability): , ?





, , .





DREAD threat model.  Source: Trend Micro
DREAD. : Trend Micro

, DREAD . :





  • , 12 15;





  •  β€” 8 11;





  •  β€” 5 7.





DREAD, . , , .





Most Dangerous Threats to Connected Cars.  Source: Trend Micro
. : Trend Micro

, :





  • 29 66% , 17% β€” 17% β€” .





  • , , , , , , .





  • . , / , β€” .





  • .





  • DDoS Shodan .





  • -, , , ITS, V2X, . , , .





  • ITS . , , .





ITS, V2X, . , , . , , , , SaaS, , . , ITS , , .








All Articles