Advanced electronic units inside modern vehicles have enhanced the driving experience, but also introduced a myriad of security problems due to the inherent limitations of the internal communication protocol. In the last two decades, a number of security threats have been identified and accordingly, security measures have been proposed. While a large body of research on the vehicular security domain is focused on exposing vulnerabilities and proposing counter measures, there is an apparent paucity of research aimed at reviewing existing works on automotive security and at extracting insights. This paper provides a systematic review of security threats and countermeasures for the ubiquitous CAN bus communication protocol. It further exposes the limitations of the existing security measures, and discusses a seemingly-overlooked, simple, cost-effective and incrementally deployable solution which can provide a reasonable defense against a major class of packet injection attacks and many denial of service attacks.
翻译:现代车辆内的先进电子设备增强了驾驶经验,但也由于内部通信协议的内在局限性而带来了许多安全问题。在过去二十年中,查明了一些安全威胁,并据此提出了安全措施。虽然对车辆安全领域的大量研究侧重于暴露弱点和提出反措施,但显然缺乏旨在审查汽车安全现有工程和提取见解的研究。本文件系统地审查了安全威胁和对无处不在的CAN公共汽车通信协议的对策。本文件进一步揭示了现有安全措施的局限性,并讨论了一种看似过眼的、简单、成本效益高和可逐步部署的解决办法,它能够为大规模包装注射袭击和许多拒绝服务袭击提供合理的辩护。