CANCAN: CAN-IN-CAN Attack for Bypassing Security

  Переглядів 922

Automotive Security Research Group

Automotive Security Research Group

Рік тому

CANCAN: CAN-IN-CAN Attack for Bypassing Security - “Don’t look at the ‘CANCAN’ (Hebrew: pitcher), look at what’s contained inside” is a Hebrew idiom, equivalent to the English idiom “Don’t judge a book by its cover”.
The Controller Area Network (CAN) bus protocol allows communication between various components inside most modern-day vehicles. The introduction of the new Controller Area Network Flexible Data-Rate (CAN-FD) protocol allows for faster communication with a larger number of data bytes per message. As these protocols are used for passing critical messages between different components, many attacks were found, and many security measures were proposed to solve or restrict them.
In this talk, a new way of compromising systems utilizing the CAN-FD protocol is presented. By introducing a crafted CAN-FD message encapsulating a legal CAN or CAN-FD message, components could potentially be made to accept the encapsulated internal message instead of the external message that was, in fact, sent on the bus. Furthermore, this talk will show how existing security solutions do not mitigate this attack and will propose effective mitigation solutions against it.
PRESENTER:
Matan Ziv is a Principal Cyber Security Researcher at Cymotive Technologies specializing in vulnerability research. Matan has over 15 years of experience in the embedded security field. His work for the last 8 years has been focused on automotive security, firmware binary analysis and tool development. As part of his contribution to the research community he has developed an open-source IDA plugin tool called "Oregami", helping with the handling of information flow through registers in the disassembly code of embedded systems.

КОМЕНТАРІ: 2
@shkaf4ik
@shkaf4ik Рік тому
Great presentation ! Thanks Matan
@guzh
@guzh Рік тому
very confusing
NodeJS 22 Just Dropped, Here's Why I'm Hyped
14:31
Theo - t3․gg
Переглядів 71 тис.
CompTIA Network+ Certification Video Course
3:46:51
PowerCert Animated Videos
Переглядів 6 млн
Підставка для яєць
00:37
Afinka
Переглядів 94 тис.
ВИРУСНЫЕ ВИДЕО / Мусорка 😂
00:34
Светлый Voiceover
Переглядів 8 млн
GADGETS VS HACKS || Random Useful Tools For your child #hacks #gadgets
00:35
How to think like a Security and a Safety Manager
1:14:19
Automotive Security Research Group
Переглядів 1 тис.
On the Insecurity of Vehicles Against Protocol-Level Bluetooth Threats
55:38
Automotive Security Research Group
Переглядів 907
Create your own CUSTOMIZED Llama 3 model using Ollama
12:55
DevTechBytes
Переглядів 8 тис.
Remotely Hacking a car through an OBD-II Bluetooth Dongle
39:32
Automotive Security Research Group
Переглядів 3,6 тис.
New Boston Dynamics HUMANOID Robot ATLAS SHOCKS The World!
11:39
AI Uncovered
Переглядів 7 тис.
Introduction to Artificial Intelligence (AI) | Google AI Essentials
19:52
Google Career Certificates
Переглядів 4,5 тис.
Mysterious AI Robot "Astribot S1" SHOCKS Everyone
16:18
AI Search
Переглядів 22 тис.
Google Data Center 360° Tour
8:29
Google Cloud Tech
Переглядів 5 млн
I Was Never Meant to Have This Prototype CPU
21:53
Linus Tech Tips
Переглядів 823 тис.
У Nokia 3310 появился конкурент
0:36
AndroHack
Переглядів 1,8 млн
All New Atlas | Boston Dynamics
0:40
Boston Dynamics
Переглядів 5 млн
Photo Changing Replace And Edit Backgrounds 65mn With These 10 Tips
0:53
Irfan AN Tech
Переглядів 260 тис.
Лучший телефон на андроиде?
0:25
Опросный
Переглядів 100 тис.