The Unified Diagnostic Services (UDS) protocol—often referred to as the "HTTP of automotive ECUs"—relies on Service 0x27, "Security Access," to safeguard safety-critical operations, such as firmware reflashing, VIN rewriting, or ADAS calibration. Prior research has predominantly focused on firmware reverse-engineering, fault injection, or brute-forcing the key. However, with the widespread adoption of encrypted JTAG, hardened hardware, and secure supply-chain governance, these avenues are increasingly obstructed, rendering successful attacks rare and prohibitively expensive. We therefore introduce an algorithmic brute-force paradigm that reconstructs the algorithmic structure embedded within the ECU. Through three real-world case studies, AlgoBuster's battlefield performance is demonstrated. The framework has been tested on 12 ECUs launched after 2018 (covering nine Tier-1 suppliers), two of which were successfully broken.
Jianwen Ren | ETAS Cybersecurity Consultant | Security MM Team Member, ETAS
Jianchi Jiang | Automotive Security Engineer |Security MM Team Member, SGS Brightsight
Su Shengfeng | Vehicle Security Engineer | Security MM Team Member, Ford Motor Company
Lin Zengda | Security Researcher,
Chen Guannan | OSR Security Researcher | Security MM Team Member,
https://ift.tt/BpWOTFx
source https://www.youtube.com/watch?v=1RFx_5p3DYY
Subscribe to:
Post Comments (Atom)
-
WeChat, with over 1.2 billion monthly active users, stands as the most popular messaging and social media platform in China and third global...
-
Unmasking State-Sponsored Mobile Surveillance Malware from Russia, China, and North Korea – Threat Actors, Tactics, and Defense Strategies S...
No comments:
Post a Comment