Showing posts with label ConnectedVehicle. Show all posts
Showing posts with label ConnectedVehicle. Show all posts

Tuesday, May 4, 2021

Interesting new Tesla Hack!

 This is from the “What will they think of next” file. Imagine you have just purchased your dream car-the Tesla Model X. You drive it home, with the windows down and the music on. Life is good. You park in the driveway and start to walk up to your house with a smile on your face. Just before you unlock the door, you look back at your new purchase. There’s an annoying drone nearby. Your new pride and joy starts acting odd, especially since you are not in the vehicle. The doors begin to open together, then one at a time. The trunk opens and closes rhythmically with the doors. 


As odd as this sounds, this is possible and has been done. Researchers presented this work at the CanSecWest conference (virtual) on April 29, 2021. The researchers used two vulnerabilities to attack the Tesla vehicle. Their new exploit was termed TBONE. 


Method

The Tesla uses ConnMan in their network. The researchers focused on this point for their attack. To design portions of the attack, the researchers used a ConnMan emulation tool, KunnaEmu. With this, they did not require access and use of Tesla at all times when testing. What makes this a bit different and interesting is the configuration. 


ConnMan is used to manage the network connections. The attack itself combined a stack buffer overflow when processing DNS requests vulnerability (CVE-2021-26675) with a loophole in the DHCP stack (CVE-2021-26676). 


For the attack hardware, the equipment is easy to source. All the attacker needs is a Wi Fi dongle and a drone. Nothing too complicated. There is also no user interaction required. The complete attack can be done in three minutes. Once done, the attacker can, among other things, inject malicious code. 


Result 

Once exploited, the attacker can do most things a driver can, except start the vehicle. This includes unlocking the doors, unlocking the trunk, changing seat positions, changing steering modes, and changing acceleration modes. This allows full access to the vehicle. This isn’t a thought experiment. The researchers had a full recording of the attack, which they played during the presentation. 


On a tangent, they could have weaponized this. The vehicle could have uploaded the malware, and be used as an access point to infect other Teslas. This is a big deal since this could compromise any Tesla Model X that has not received the patch, even the parked ones. What makes it worse is the system is used by other OEMs who may not have patched this yet. 


Responsible Disclosure 

The vulnerability and attack weren’t sprung on the interested parties a week prior to the conference. They did inform Intel, who created ConnMan. The vulnerability was remediated with FOTA update 2020.44 by Tesla in late October 2020. 




Resources 

https://www.forbes.com/sites/thomasbrewster/2021/04/29/watch-a-tesla-have-its-doors-hacked-open-by-a-drone/?sh=d6f4c271a2bd 


https://flipboard.com/@HotCars2020/aerial-attack-cybersecurity-researchers-managed-to-hack-tesla-with-a-drone/a-li8iYV-aTQC9yfvTZ3ivig%3Aa%3A3466759924-982d88ebd6%2Fhotcars.com 


https://securityaffairs.co/wordpress/117441/hacking/tesla-model-x-hacking.html?utm_source=rss&utm_medium=rss&utm_campaign=tesla-model-x-hacking 


https://www.autoevolution.com/news/hackers-break-into-tesla-using-a-drone-flying-over-the-car-160447.html 


https://www.deskvip.com/a-tesla-car-has-its-doors-hacked-open-by-a-drone 


https://www.torquenews.com/1/tesla-hacked-drone-company-informed-and-fixed-loophole 


https://www.hackread.com/tesla-cars-remotely-hacked-with-drone/ 


https://dronedj.com/2021/04/30/german-pilots-film-their-drone-hack-of-a-tesla/ 


https://www.hotcars.com/aerial-attack-cybersecurity-researchers-managed-to-hack-tesla-with-a-drone/ 


https://kunnamon.io/tbone/ 


Monday, April 20, 2020

Vehicle cybersecurity still lacking: Ford Focus and Volkswagen Polo


Vehicles are becoming increasingly connected and complicated. The modules/equipment in the vehicle along with the connectivity makes the newer vehicles targets with many attack vectors. With these advances, the consumer would think cybersecurity would be the first thing on the engineer’s mind. Unfortunately, this is not always the case. It is likewise notable, there are many laws and statutes directed at the vehicles for emissions and other aspects of the vehicle. While these are indeed needed, there are no laws focused on the cybersecurity applied to vehicles. There is a handful of these in the works, however, at this stage, these are more voluntary and may be presented as more of a standard versus legislative action.

Successful breach
While these are noteworthy, generally, if an automobile the manufacturer does not have to or is strongly encouraged to, it is difficult to get the issue resolved and feature in the vehicle. A recent case in point involved a For Focus Titanium Automatic 1.0L and a Volkswagen Polo SEL TSI Manual 1.0L. These are both gas-powered vehicles and are very popular in Europe.
Researchers at Context Information Security were tasked with conducting a pentest of sorts on these two vehicles.

The research indicated there were rather serious cybersecurity flaws with the test vehicles. The researchers have reported these and are waiting until providing their test to the public as part of the responsible vulnerability disclosure process. This provides the manufactures time to correct or mitigate the issue, prior to sending the vulnerability, and how to attack it to anyone who has an internet connection.

Researcher’s attacks generalized
While the specifics are not available, the researchers did release general information regarding their successful attacks. As a recap, the subject vehicles, and nearly all others at this point use the Controller Area Network (CAN) to communicate between the modules in each vehicle. These communications are relevant for tire pressure, driving controls, braking, steering, etc. If this is successfully attacked, the driver and passengers assuredly are going to have a bad day. This area was one where the researchers were able to successfully access the Polo.

There was also another vulnerability with OTA (over the air) updates. The vehicles have a number of computers and programs located with the vehicle’s system. These at times need to be updated. Think of it like when you turn off your computer and the system warns you there are patches that need to be uploaded for your system. To have the owners all make appointments to drive their vehicles in every time there is an update is not a workable solution and would halt any work that would need to be done in the repair/maintenance portion of the garages at the dealerships. The researchers were able to tamper with these updates, thus adding the malicious functionality of changing the official update to whatever they would want.

The researchers also found a vulnerability with the infotainment unit in the vehicle. This, when successfully attacked, would enable or disable the vehicle’s traction control, tamper with the headlights, and holds a large amount of personal data (e.g. phone contacts, and location history). This attack was accomplished with a simple command. For this attack, the researchers or bad actors would need to have physical access. While this is a hurdle, it is not impossible, especially since this would only take approximately five minutes.

There were other tests done, with mixed results.

The researchers, curiously, were able to find the Wi-Fi credentials that apparently were for the computer systems on the Ford production line. This is a rather significant and truly bad thing to have that easily accessible.

Resources
Chllingsworth, L. (2020, April 15). Which? Identifies security risk in these road vehicles as hackers may steal your data. Retrieved from https://www.express.co.uk/life-style/cars/1269260/which-ford-volkswagen-car-security-safety-hackers-crime
Forrester, N. (2020, April 15). Latest ford and Volkswagen smart cars pose ‘serious’ privacy and security risk. Retrieved from https://securitybrief.asia/story/latest-ford-and-volkswagen-smart-cars-pose-serious-privacy-and-security-risk
Hull, R. (2020, April 8). Popular ford and vw cars found to have ‘serious security flaws’ with their connected systems putting personal data and safety at risk. Retrieved from https://www.thisismoney.co.uk/money/cars/article-8201733/Popular-Fords-VWs-security-flaws-connected-tech.html
Laughlin, A. (2020, April 9). We hacked ford focus and a volkswagen polo. Retrieved from https://www.which.co.uk/news/2020/04/we-hacked-a-ford-focus-and-a-volkswagen-polo/
Thomas, P. (2020, April 10). Popular ford and vw cars found to have ‘serious security flaws’ with their connected systems putting personal data and safety at risk. Retrieved from https://www.iaati.org/news/entry/popular-ford-and-vw-cars-found-to-have-serious-security-flaws-with-their-co


Thursday, April 16, 2020

4CAN as another vehicle cybersecurity testing tool

Vehicle cybersecurity continues to grow in pertinence. This is especially the case with the CAV (connected and autonomous vehicle) as these advancements in technology application and improves in performance. The connected vehicles are already in place and used on the road. The autonomous vehicles are still being developed and tested. There will be a time when the scenes in movies, e.g. iRobot with the fleets of self-driving cars, are in place with the vehicles communicating with each other and the infrastructure (V2V, and V2I). 

As the prominence continues to grow, so does the potential for attack. This may be from the bad actors looking for their 15 minutes of fame, malicious attackers, or cybersecurity researchers. In each of these vehicles are also vastly more attack points than in prior years. The modern vehicles have hundreds of sensors feeding data to the vehicle regarding the vehicle and also the environment in which it is driving. These may be LiDAR, radar, cameras, microphones, and other sensors. These sensors provide real-time data to the vehicle and end-users on the vehicle’s operations, which is processed immediately dependent on the criticality. 

The attackers may have access to the vehicle’s computers through the vehicle’s WiFi, Bluetooth, or cellular means. While this is notable, the controller area network (CAN) is what carries the messages through the vehicle. 

4CAN
To better protect the vehicle, better tools have to be created, which is what was done in 3Q2019 by Cisco. 4CAN was originated by George Tarnovsky, who is a member of Cisco Customer Experience Assessment and Penetration Team (CX APT). This is a hardware tool and was released as open-source. This is a PiHat, meaning the 4CAN is attached on top of the Raspberry Pi. This was engineered to be used by all automobile security researchers. The focus is to test the sensors and computers within the vehicle to check for vulnerabilities. As noted, the bench setup is much cleaner, simpler, and easier to use. This changes a 4 piece set up, including two Beaglebone boards, to two pieces of equipment.  This also lessens the setup time for the lab staff. 

The 4CAN tool works to validate the communication policy for intra-CAN bus communication, fuzzing the sensors and modules to detect vulnerabilities, and use various CAN commands to interact with the vehicle. The interaction hopefully would also detect any sensor or module vulnerabilities with the messages being sent. The tool is designed to test four CAN channels at once. 

While the tools do have advanced capabilities and would suit many use cases, the 4CAN is able to complete these tests with a simplified bench set up. This assists the lab engineer to keep it simple and organized.

Resources
Arghire, I. (2019, August 23). New tool from cisco hunts flaws in automotive computers. Retrieved from https://www.securityweek.com/new-tool-cisco-hunts-flaws-automotive-computers 

CISOMAG. (2019, August 26). Cisco releases new security tool to identify vulnerabilities in connected cars. Retrieved from https://www.cisomag.com/cisco-releases-new-security-tool-to-identify-vulnerabilities-in-connected-cars/

DeTrano, A., Royes, J., & Valites, M. (2019, August 22). New 4CAN tool helps identify vulnerabilities in on-board car computers. Retrieved from https://blog.talosintelligence.com/2019/08/new-4can-tool-helps-identify.html

DeTrano, A. (2019, August 5).4CAN. Retrieved from https://github.com/alexdetrano/4CAN/tree/master/tools 

Haking. (n.d.). 4CAN-Open source security tool to find security vulnerabilities in modern cars. Retrieved from https://hakin9.org/4can-open-source-security-tool-to-find-security-vulnerabilities-in-modern-cars/ 

Meterpreter. (2020, April 16). Cisco releases 4CAN tool to find vulnerabilities in on-board car computers. Retrieved from https://meterpreter.org/cisco-releases-4can-tool-to-find-vulnerabilities-in-on-board-car-computers/ 

N, B. (2019, August 25). 4CAN-Cisco released new open source security tool to find security vulnerabilities in modern cars. Retrieved from https://gbhackers.com/4can/ 

Paganini, P. (2019, August 24). Cisco has released a hardware tool, called 4CAN, developed to help researchers to discover vulnerabilities in automotive systems. Retrieved from https://securityaffairs.co/wordpress/90317/hacking/4can-automotive-testing-tool.html

Friday, June 21, 2019

Securing Connected Cars


Securing Connected Cars
Charles Parker, II


Vehicles abound in society and culture. These vary in age, color, manufacturer, and the amount of tire and brake wear. One topic which has been in the news and talked about commonly has been securing these vehicles, especially the connected vehicles now and the future autonomous vehicles. Seemingly, there are new articles with these are the story focus. With these vehicles, due to the other assets the vehicle connects to (e.g. V2X, V2I, V2V, V2G, etc.), a successful attack has the potential to have a really bad day.

Vehicles are becoming increasingly connected. At some point in the near future, the vehicles we have grown with will become autonomous. With all of these iterations with vehicle advancing in technology, one aspect becomes increasingly pertinent. The vehicles have to incorporate security into the vehicle’s infrastructure. The functionality requires it. As these vehicles control a greater extent of the operations, previously managed manually, the risk increases. When the vehicles are autonomous, the risk is rather significant. For instance, when the sensors are connected, the risk is for a false positive. If there is a tire pressure monitoring system (TPMS), the risk is for the equipment to read more or less than the actual air pressure reading in the tire. An attacker could successfully force the system to register an exceptionally low-pressure reading forcing the driver to pull over to the side of the road.

With the advanced autonomous drive vehicle, the risk is magnified. This is due to the attacker having the opportunity to take full control of the vehicle. The auto could be re-routed to a totally different location or turn into traffic during rush hour. This series of use cases illustrate the necessity and requirement for a secure vehicle infrastructure. These attacks absolutely do not have to be by someone located in or within a few feet of the car, or physically connected to it with a patch cord. These attacks may be done from anywhere across the globe with a fair internet connection. This makes the connected and autonomous drive vehicle even more potentially devastating. These attacks occur unfortunately with the present fleets. These may initially take the form of a proof of concept (PoC) at this point. The jump to a fully mature attack from this point is not that great of a stretch for the adequately trained attacker. These hypothesized compromises have been demonstrated by cybersecurity researchers on the Tesla, BMW, Nissan, Mitsubishi, FCA, and other manufacturer vehicles.

To address this growing germane issue, Mitsubishi Electric developed a cyber-defense system to defend vehicles. The new system incorporates multiple cybersecurity layers into one defense in depth tool. This works by improving the head unit’s (HU’s) ability to defend the vehicle. The vehicle’s connected function has allowed for an in-depth attack vector and path to the vehicle’s crown jewels, or the attacker’s targets to exfiltrate.

As noted, there are multiple layers of defense. This acts much like an intrusion detection/protection system (IDS/IPS). This is intended to decrease the potential for a successful attack. The more difficult is would be for the attacker to succeed, the greater the chance the attacker will move onto the next target, looking for an easier target. The attackers would not spend weeks or months on a random target when they would be able to successfully compromise another vehicle in days or a week. This is simple economics and algorithm.

This works by identifying attempted attacks in the HU and modules controlling the vehicle. This detects attack methods for the vehicle. This was designed for a faster boot-up. This is estimated to take less than 10% of the time for a conventional boot-up process. For this cybersecurity system, the HU is the focus for the defensive operating system. This is an appropriate central point as the HU is attached to the internet, and the researchers analyzed the defense-in-depth used by critical infrastructure and applied the theory to the vehicle.

The new system verifies the software in the vehicle’s operations integrity during the boot-up process. The system completes the task while not being over-bearing on the processing time and power. The direct effect on the system is paramount. The vehicle’s cybersecurity has to be fully addressed prior to the more connected vehicles being placed on the road. The drivers across the freeways would rather not have a rogue vehicle careening through traffic during rush hour on a Tuesday morning.

This cybersecurity feature is a great first step. This tool addresses one vector for an attack. There are others which focus on the other aspects of the vehicle’s functions and communications to address in the future.

Resources
Green Cars Congress. (2019, January 22). Mitsubishi electric develops cyber defense technology for connected cars. Retrieved from https://www.greencarcongress.com/2019/01/20190122.html

Kovacs, E. (2019, January 22). Mitsubishi develops cybersecurity technology for cars. Retrieved from https://www.securyweek.com/mitsubishi-develops-cybersecurity-technology-cars

Market Watch. (2019, January 21). Mitsubishi electric develops cyber defense technology for connected cars. Retrieved from https://www.marketwatch.com/press-release/mitsubishi-electric-develops-cyber-defense-technology-for-connected-cars-2019-01-21

R., J. (2019, January 22). Mitsubishi electric develops auto cyber security. Retrieved from https://www.universitymitsubishi.com/mitsubishi-electric-develops-auto-cyber-security/

Rajan, P. (2019, January 23). Mitsubishi electric develops cybersecurity technology for connected cars. Retrieved from https://www.telematicswire.net/automotive-security/mitsubishi-electric-develops-cybersecurity-technology-for-connected-cars/