Communication-Traffic-Assisted Mining and Exploitation of Buffer Overflow Vulnerabilities in ADASs

被引:2
|
作者
Li, Yufeng [1 ,2 ]
Liu, Mengxiao [1 ]
Cao, Chenhong [1 ,2 ]
Li, Jiangtao [1 ,2 ]
机构
[1] Shanghai Univ, Sch Comp Engn & Sci, Shanghai 200444, Peoples R China
[2] Purple Mt Labs, Nanjing 211100, Peoples R China
来源
FUTURE INTERNET | 2023年 / 15卷 / 05期
基金
美国国家科学基金会;
关键词
advanced driver assistance systems; buffer overflow vulnerability; communication traffic; intelligent vehicles; SECURITY;
D O I
10.3390/fi15050185
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Advanced Driver Assistance Systems (ADASs) are crucial components of intelligent vehicles, equipped with a vast code base. To enhance the security of ADASs, it is essential to mine their vulnerabilities and corresponding exploitation methods. However, mining buffer overflow (BOF) vulnerabilities in ADASs can be challenging since their code and data are not publicly available. In this study, we observed that ADAS devices commonly utilize unencrypted protocols for module communication, providing us with an opportunity to locate input stream and buffer data operations more efficiently. Based on the above observation, we proposed a communication-traffic-assisted ADAS BOF vulnerability mining and exploitation method. Our method includes firmware extraction, a firmware and system analysis, the locating of risk points with communication traffic, validation, and exploitation. To demonstrate the effectiveness of our proposed method, we applied our method to several commercial ADAS devices and successfully mined BOF vulnerabilities. By exploiting these vulnerabilities, we executed the corresponding commands and mapped the attack to the physical world, showing the severity of these vulnerabilities.
引用
收藏
页数:16
相关论文
共 1 条
  • [1] Predicting Buffer Overflow Vulnerabilities through Mining Light-Weight Static Code Attributes
    Padmanabhuni, Bindu Madhavi
    Tan, Hee Beng Kuan
    2014 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW), 2014, : 317 - 322