Advanced CAN Injection Techniques for Vehicle Networks

Black Hat USA 2016

Presented by: ChrisValasek, Charlie Miller
Date: Thursday August 04, 2016
Time: 09:45 - 10:35
Location: Mandalay Bay GH

The end goal of a remote attack against a vehicle is physical control, usually by injecting CAN messages onto the vehicle's network. However, there are often many limitations on what actions the vehicle can be forced to perform when injecting CAN messages. While an attacker may be able to easily change the speedometer while the car is driving, she may not be able to disable the brakes or turn the steering wheel unless the car she is driving meets certain prerequisites, such as traveling below a certain speed. In this talk, we discuss how physical, safety critical systems react to injected CAN messages and how these systems are often resilient to this type of manipulation. We will outline new methods of CAN message injection which can bypass many of these restrictions and demonstrate the results on the braking, steering, and acceleration systems of an automobile. We end by suggesting ways these systems could be made even more robust in future vehicles.

Charlie Miller

Charlie Miller is a security engineer at Uber ATC, a hacker, and a gentleman.Back when he still had time to research, he was the first with a public remoteexploit for both the iPhone and the G1 Android phone. He is a four-time winnerof the CanSecWest Pwn2Own competition. He has authored three informationsecurity books and holds a PhD from the University of Notre Dame. He hashacked browsers, phones, cars, and batteries. Charlie spends his free timetrying to get back together with Apple, but sadly they still list theirrelationship status as 'it's complicated'.

ChrisValasek

Chris Valasek is security lead for Uber ATC. Mr. Valasek was one of the firstresearchers to publicly discuss automotive security issues in detail. Hereleased code, data, and tools that allowed vehicles to be physicallycontrolled through the vehicle's CAN bus. Valasek specializes in offensiveresearch methodologies with a focus on reverse engineering and exploitation.He is also the Chairman of SummerCon, the United States' longest standinghacker conference.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats