Dr. David J. Pearce

Experimental Security Analysis of a Modern Automobile


Another good paper I found recently was the following:

“Experimental Security Analysis of a Modern Automobile”, Hoscher, Czeskis, et al. In Proceedings of IEEE Symposium on Security and Privacy, 2010. [PDF]

What I found particularly interesting was the discussion of the computing setup on a modern car.  Here’s some info:

I think we’re probably starting to get the picture now.  The essence of the paper is that author’s took a fairly standard car and attacked in a variety of ways to determine what was possible.  They managed to do things like upgrading the firmware of the Engine Control Module whilst the car was running — at which point the engine stops running immediately.  Other interesting things include the ability to pop the trunk whilst at speed, deactivating the brakes at speed, or instantly putting them on!  It’s pretty scary stuff when you think about it; particularly, as you might install a seemingly innocent new CD-player …. which then decides to randomly take over your car when you least expect it.

Anyway, worth a read …