Skip to main content
Automotive

YekCar

Emulated control units with CAN, UDS and keyless entry, with an attacker dashboard and an IDS monitor in the same case.

Der Demonstrator YekCar mit Steuergeräten, CAN-Bus und OBD-II-Schnittstelle

A transportable case holding emulated control units on a real CAN bus, the UDS diagnostic protocol above it, a keyless entry system, and two detection components reporting to a vehicle security operations centre. Built in the FINESSE research project.

The problem

A car is a computing platform on wheels

A new vehicle today contains more than a hundred control units and several million lines of code, connected over CAN, automotive Ethernet, Bluetooth, Wi-Fi and mobile networks. What follows from that was shown in 2015 by the remote access to a moving SUV: through a weakness in the infotainment system onto the vehicle bus, and from there to safety-critical functions. The manufacturer recalled around 1.4 million vehicles.

None of that can be practised on a production vehicle. The buses are built in, the vehicle is type-approved, and the things you would have to do are not things you do to a roadworthy car. So we transferred the architecture into a setup that may be opened, wired up and attacked.

The setup

What is inside the case

Everything visible side by side: what the vehicle does, what the attacker does, and what the detection makes of it.

CAN, UDS and keyless entry

Emulated control units with authentic CAN communication, the UDS diagnostic protocol to ISO 14229 above it, an OBD-II interface for real workshop tools, and a keyless entry system for record and replay attacks.

Three views at once

A vehicle dashboard with speed, engine revolutions, temperature, fuel level and warning lights. An attacker dashboard for message injection, speed manipulation, horn and lights. And an IDS monitor that evaluates the bus traffic in real time and marks what stands out.

Driving situation and radio

A 3D driving simulation shows the effect of an intervention in a driving context, controlled with an off-the-shelf gamepad. Alongside it a keyless entry system for record and replay attacks. A power station makes the case self-sufficient for demonstrations.

Scenarios

Attack and detection in the same picture

Automotive-Demonstrator mit CAN, UDS und Keyless Emulierte Steuergeraete an einem CAN-Bus, Diagnosezugang ueber OBD-II und ein schluesselloses System. Zwei Erkennungskomponenten melden an ein Vehicle Security Operations Center. EMULATED ECUS CAN-BUS OBD-II · UDS KEYLESS · REPLAY CAN-IDS MESSAGES UDS-IDS SESSIONS VSOC MAPPED TO TACTICS YEKCAR · CAN, UDS, KEYLESS, IDS, VSOC

On the attack side: injecting manipulated messages onto the bus with direct effect on displays and functions. Structured abuse of the diagnostic protocol through service, memory and sub-function requests. Systematic fuzzing to find unexpected behaviour. And a replay attack against the keyless entry.

On the defence side, intrusion detection runs alongside, making deviations from normal message traffic visible, showing thresholds and logging everything for later forensics.

In a demonstration for clients from the automotive industry we showed exactly that simultaneity: a message injection manipulates the speedometer, and in the same moment the detection fires and presents the anomaly. What people learn from does not come from the attack but from the two things sitting side by side.

What follows

From a single vehicle to a fleet picture

Vehicle Security Operations Center Steuergeraete an zwei Bussen, eine Erkennungseinheit an Bord, der Uplink und die Auswertung im Betrieb. Was auffaellt, wird zur Regel und geht zurueck ins Fahrzeug. IN-VEHICLE ECUS ON THE BUS IDS UPLINK VEHICLE SOC USE CASES PER VEHICLE TYPE VEHICLE SOC · ON BOARD AND IN THE BACKEND

A single vehicle only detects what happens to it. It gets interesting when many vehicles report and a picture emerges from that. For exactly that we developed a security operations centre for vehicles in the same research project.

It differs from an IT SOC in what it has to evaluate: events from vehicle systems rather than from servers, with different timing and different options for response. Its structure includes central collection and correlation, analysis on SIEM principles, and response processes that take the particulars of vehicle operation into account.

Because the common tactics and techniques model from IT does not cover the vehicle domain, we extended it for that purpose.

Use

What we use the case for

For training security professionals with realistic attack scenarios. For raising awareness among decision-makers, to whom an abstract risk is hard to convey. For developing and testing protection concepts in a controlled environment. For red-blue exercises. And as a reference point for the evidence arising from the regulations on type approval and software update management.

The setup is extended continuously, because vehicle architecture keeps moving: vehicle-to-everything communication and software-defined vehicles bring attack surfaces that did not exist a few years ago.

Trusted by
Next step

See the demonstrator in action.

Wir zeigen die Anlage, die Angriffswege und was sich daran prüfen lässt.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139