Defending AUTOSAR Safety Critical Systems Against Code Reuse Attacks

Ahmad Nasser, Di Ma · 2019

With the emergence of AUTOSAR as the dominant software platform for deeply embedded automotive systems, securing AUTOSAR against software based attacks becomes essential to securing most vehicles. However security countermeasures have to fit within the constraints of automotive systems, such as available system resources, legacy code reuse and sensitivity to cost. Since the primary goal of such systems is to control safety critical vehicle functions, any security countermeasures need to harmonize the safety and security response. In this paper, we investigate the susceptibility of safety critical automotive systems to code reuse attacks that aim to violate the vehicle safety. We perform a case study using the vehicle diagnostics protocol with the aim to bypass the security access checks and execute a safety critical Routine Control service. Then we propose an HSM based monitoring system to detect or prevent such attacks.

Read the paper · More papers on PaperTik