Sep 2026· International Conference on Signal Processing and Communication Security· Vol 14374, pp. 143740R - 143740R-6· 0 citations· 10 references
Engineering
TL;DR
A layered test architecture tailored for ECM applications is constructed, security risks of the XCP protocol under unauthenticated and weak-permission scenarios are identified, and engineering-oriented mitigation strategies are proposed.
Abstract
With the development of automotive intelligence and connectivity, the security vulnerabilities of the XCP protocol adopted by in-vehicle ECUs have become increasingly prominent. Conducting targeted penetration testing is crucial for safeguarding in-vehicle security. This paper takes the ECM engine controller as the research object, builds a test environment based on CAN FD-200U hardware and Kali Linux, and uses SocketCAN and CaringCaribou tools. It designs and conducts penetration tests covering three typical XCP attack scenarios: node scanning, information disclosure, and calibration data tampering. A layered test architecture tailored for ECM applications is constructed, security risks of the XCP protocol under unauthenticated and weak-permission scenarios are identified, and engineering-oriented mitigation strategies are proposed. The research results can provide references for security testing, vulnerability mining, and protection system construction of the XCP protocol for in-vehicle ECUs.
A survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends is presented and several security recommendations for software engineering teams are provided based on the findings.
Srijita Basu, Miroslaw Staron, M. Almgren et al.· Software quality journal· 0 citations
The impending formal adoption of SAE J1939-91C creates an urgent need for rigorous, repeatable validation methods that extend beyond functional conformance. This paper presents a structured validation and benchmarking framework, with a focus on performance characterization across dynamic vehicle configurations. Buildin...
Mark P. Zachos, Prakash Kulkarni· SAE technical paper series· 0 citations
A stateful security verification methodology that combines stateful fuzzing with specification-guided security verification of the NG Application Protocol between the radio access network and the 5G core is proposed.
Seungjoon Na, Hwankuk Kim· Italian National Conference...· 0 citations
This article presents the implementation of basic penetration testing which focuses on the scanning phase by using two virtual machines which are Kali Linux and Metasploitable 2 installed virtually in a local machine through VirtualBox as one of the virtualization software to simulate the environment.
An architectural analysis of automotive HSMs is presented and examines their role in establishing secure boot and hardware roots of trust and emerging challenges such as cryptographic agility and post-quantum readiness that are likely to shape the next generation of automotive HSM architectures are discussed.
Industrial Control Systems (ICS) form the backbone of critical infrastructure, enabling automation and control in sectors such as energy, water, and manufacturing. The convergence of Operational Technology (OT) and Information Technology (IT) has introduced significant cybersecurity challenges, particularly for legacy...
Lukumba Phiri, Mukubesa Kamutumwa· International Journal of App...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.