Communication-Traffic-Assisted Mining and Exploitation of Buffer Overflow Vulnerabilities in ADASs
Yufeng Li,
Mengxiao Liu,
Chenhong Cao and
Jiangtao Li ()
Additional contact information
Yufeng Li: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Mengxiao Liu: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Chenhong Cao: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Jiangtao Li: School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China
Future Internet, 2023, vol. 15, issue 5, 1-16
Abstract:
Advanced Driver Assistance Systems (ADASs) are crucial components of intelligent vehicles, equipped with a vast code base. To enhance the security of ADASs, it is essential to mine their vulnerabilities and corresponding exploitation methods. However, mining buffer overflow (BOF) vulnerabilities in ADASs can be challenging since their code and data are not publicly available. In this study, we observed that ADAS devices commonly utilize unencrypted protocols for module communication, providing us with an opportunity to locate input stream and buffer data operations more efficiently. Based on the above observation, we proposed a communication-traffic-assisted ADAS BOF vulnerability mining and exploitation method. Our method includes firmware extraction, a firmware and system analysis, the locating of risk points with communication traffic, validation, and exploitation. To demonstrate the effectiveness of our proposed method, we applied our method to several commercial ADAS devices and successfully mined BOF vulnerabilities. By exploiting these vulnerabilities, we executed the corresponding commands and mapped the attack to the physical world, showing the severity of these vulnerabilities.
Keywords: advanced driver assistance systems; buffer overflow vulnerability; communication traffic; intelligent vehicles (search for similar items in EconPapers)
JEL-codes: O3 (search for similar items in EconPapers)
Date: 2023
References: View complete reference list from CitEc
Citations:
Downloads: (external link)
https://www.mdpi.com/1999-5903/15/5/185/pdf (application/pdf)
https://www.mdpi.com/1999-5903/15/5/185/ (text/html)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:gam:jftint:v:15:y:2023:i:5:p:185-:d:1150570
Access Statistics for this article
Future Internet is currently edited by Ms. Grace You
More articles in Future Internet from MDPI
Bibliographic data for series maintained by MDPI Indexing Manager ().