21
Automotive security New challenges

Владимир Махитко - Automotive security. New challenges

Embed Size (px)

Citation preview

Page 1: Владимир Махитко - Automotive security. New challenges

Automotive securityNew challenges

Page 2: Владимир Махитко - Automotive security. New challenges

I am Volodymyr MakhitkoSoftware Engineer GlobalLogic

Page 3: Владимир Махитко - Automotive security. New challenges

Automotive security is a ecosystem

Page 4: Владимир Махитко - Automotive security. New challenges

Automotive ecosystem

Page 5: Владимир Махитко - Automotive security. New challenges

Vehicle attack surface

Page 6: Владимир Махитко - Automotive security. New challenges

Common ways of hacking

◉ hardware hacking◉ wireless hacking◉ network hacking◉ browser hacking

◉ linux/qnx hacking◉ binary reverse engineering◉ protocol reverse engineering◉ custom tool development

Page 7: Владимир Махитко - Automotive security. New challenges

Video examples

Page 8: Владимир Махитко - Automotive security. New challenges

Vehicle attack surface

Page 9: Владимир Махитко - Automotive security. New challenges

CAN bus frame

Page 10: Владимир Махитко - Automotive security. New challenges

OBD pinout example

Page 11: Владимир Махитко - Automotive security. New challenges

CAN tools

● apt-get install can-utils● configure can interface● # candump -cae can0,0:0,#FFFFFFFF

Page 12: Владимир Махитко - Automotive security. New challenges

Keep car in diagnostic state

Page 13: Владимир Махитко - Automotive security. New challenges

Mazda CAN ID

Page 14: Владимир Махитко - Automotive security. New challenges

TPMS Attack

● track vehicle● trigger events● spoofing

Page 15: Владимир Махитко - Automotive security. New challenges

Vehicle attack surface

Page 16: Владимир Махитко - Automotive security. New challenges

Intrusion detection & Snort

Page 17: Владимир Махитко - Automotive security. New challenges

Attacks classification

● backdoor● bad-traffic● botnet-cnc● content-replace● ddos● exploit

● file-identify● ftp● icmp● multimedia● mysql● scan

● telnet● virus● voip● tftp● web-attacks

Page 18: Владимир Махитко - Automotive security. New challenges

IDS & enterprise network topology

Page 19: Владимир Махитко - Automotive security. New challenges

IDS & enterprise network topology

Page 20: Владимир Махитко - Automotive security. New challenges

Bad & Good Automotive Architecture

Page 21: Владимир Махитко - Automotive security. New challenges

THANKS!