SlideShare a Scribd company logo
1 of 24
Download to read offline
Gentlemen,
Start your engines
   Mattias Jidhage
Omegapoint

                                               - Founded in 2001
                                               - 170 consultants
                                               - e-Business & Security
                         Falun	



New York	


                                    Stockholm	


        Göteborg	

                             Kalmar	

    Helsingborg	


              Malmö
Agenda
Telematics
                               “integrated use of telecommunications and informatics”




ECU	
  =	
  Electronic	
  C
BCM=Brake	
  
ECU=Engine	
   ontrol	
  
CCU=Convenience	
  ontrol	
  
ACU=Airbag	
  CC ontrol	
   odule	
  
CTM=Central	
   Ciming	
  Module	
  
GEM=General	
  Electronic	
   M
SCM=Suspension	
   ontrol	
  U odule	
  
TCM=Transmission	
   M Module	
  
BCM=Body	
  CCTontrol	
  ontrol	
  odule	
  
ECM=Engine	
  ontrol	
  CUodule	
  M
PCM=Powertrain	
  CC Mnit	
  MUnit	
  
CCM=Central	
  ontrol	
  ontrol	
  nit odule	
  
~100	
  Bosch,	
  Siemens,	
  Delphi..	
  
Telematics




Potentially less than great security?
Eh, What's up Doc?
•    The Car
•    Transport
•    Server
•    Client
The Car - Research
•  Experimental Security Analysis of a
   Modern Automobile
  –  OBD-II
•  Comprehensive Experimental Analyses of
   Automotive Attack Surfaces
  –  CD
  –  OBD-II (PassThru)
  –  Bluetooth
  –  GSM
The Car – Reality
•  War Texting: Identifying and Interacting
   with Devices on the Telephone Network
  –  Method for attacking telematics
     •  In general: GSM Baseband + uC Chip
     •  UART -> RE -> Firmware -> Vulnerability
  –  How2 find targets?
     •  FindMe
     •  WhoIs
The Car – Reality

•  Put it to the test
   –  Zoombak Tracking Device
      •  Zoombak Scanner
      •  Ask nicely via SMS
   –  Subaru Outback 1998
      •  after market telematics unit
      •  unlock and start engine
      •  http://youtu.be/bNDv00SGb6w
Transport - GSM
•  A5/1

•  SRLabs
  –  CCC 2009, BlackHat 2010
  –  Rainbow tables (100.000 years to 1 month)
  –  Decode voice
     •  100-300m upstream
     •  5-35km downstream
Transport – GPRS/EDGE
                    No encryption
•    GEA/0
•    GEA/1
•    GEA/2
•    GEA/3
•    GEA/4            No users



•  SRLabs
     –  CCC 2011, Crypto analysis (weak crypto)
     –  Decode GPRS -> Wireshark
Transport – cell




        USRP H
          W
Server
•  Car interface
  –  Proprietary protocol
     •  ASN.1 – Touring complete
     •  GPRS, EDGE, SMS and data over voice
  –  “We use a Private APN”
     •  Generic Routing Encapsulation
     •  Node to Node communication
•  Operator web application
•  Smartphone interface: REST/JSON
Client - browser
•  Web application
  –  no news
  –  move on
  –  there is nothing to see

  –  DriveBy Trojan Download & Install
     •  Starring Windows
     •  Guest appearance by Mac OSX
Client – smart phone
•  Few real vulnerability tests performed
•  iOS
  –  Continous Jailbreak
  –  iOS 5.0.1 - iPhone 4GS and iPad2
  –  iOS 5.1 – iPad3


•  Android
  –  Rouge apps
  –  Android Market - ‘Bouncer’
Conclusion
•    All components are possible targets
•    Very few has the complete picture
•    Activity in the security arena
•    This is going to get worse before it gets
     better
     –  2012 models CAN bus is unprotected
     –  New tools arriving every day
     –  Larger attack surface than ever
•  Use fast shoes
What’s to come?
•  “Internet of Things”
The Future
The Future
•  Telematics – M2M
  –  “integrated use of telecommunications and
     informatics”




   Insulin pump                Prescription
                               medication
The Future




 ABB IRB 6640
Industrial robot
The Future
          Three Gorges
Infrastructure - SCADA – Stuxnet
The Future
Home Metering Unit - SmartGrid
  270 000 HMU using ZigBee
“Everything is a computer”




@mjidhage
mattias.jidhage@omegapoint.se

Thank You!
References
•  http://www.autosec.org/publications.html
•  http://www.isecpartners.com/storage/docs/presentations/
   isec_bh2011_war_texting.pdf
•  http://events.ccc.de/congress/2009/Fahrplan/
   attachments/1519_26C3.Karsten.Nohl.GSM.pdf
•  https://srlabs.de/blog/wp-content/uploads/
   2010/07/100729.Breaking.GSM_.Privacy.BlackHat1.pdf
•  http://events.ccc.de/camp/2011/Fahrplan/attachments/
   1868_110810.SRLabs-Camp-GRPS_Intercept.pdf

More Related Content

What's hot

Transit-Protect presentation 2014
Transit-Protect presentation 2014Transit-Protect presentation 2014
Transit-Protect presentation 2014
Transit-Protect
 
T062500000 p003050ppte
T062500000 p003050ppteT062500000 p003050ppte
T062500000 p003050ppte
Phani Kumar
 
GSM Based Anti theft system
GSM Based Anti theft systemGSM Based Anti theft system
GSM Based Anti theft system
Kshitij Rokde
 

What's hot (15)

Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris ValasekSuns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
 
Connected car solution and E-call system for OEM by Smartdriving
Connected car solution and E-call system for OEM by SmartdrivingConnected car solution and E-call system for OEM by Smartdriving
Connected car solution and E-call system for OEM by Smartdriving
 
Self driving and connected cars fooling sensors and tracking drivers
Self driving and connected cars fooling sensors and tracking driversSelf driving and connected cars fooling sensors and tracking drivers
Self driving and connected cars fooling sensors and tracking drivers
 
Need and value for various levels of autonomous driving
Need and value for various levels of autonomous drivingNeed and value for various levels of autonomous driving
Need and value for various levels of autonomous driving
 
I.c ingine ppt
I.c ingine pptI.c ingine ppt
I.c ingine ppt
 
20140311 cisec-automotive systems
20140311 cisec-automotive systems20140311 cisec-automotive systems
20140311 cisec-automotive systems
 
E call ppt
E call pptE call ppt
E call ppt
 
Transit-Protect presentation 2014
Transit-Protect presentation 2014Transit-Protect presentation 2014
Transit-Protect presentation 2014
 
Vehicle Tracking System
Vehicle Tracking SystemVehicle Tracking System
Vehicle Tracking System
 
T062500000 p003050ppte
T062500000 p003050ppteT062500000 p003050ppte
T062500000 p003050ppte
 
MIPI IP Modules for SoC Prototyping
MIPI IP Modules for SoC PrototypingMIPI IP Modules for SoC Prototyping
MIPI IP Modules for SoC Prototyping
 
Automation on Traffic Signals
Automation on Traffic SignalsAutomation on Traffic Signals
Automation on Traffic Signals
 
Automated Driving: Innovative Product Development & Safety
Automated Driving: Innovative Product Development & SafetyAutomated Driving: Innovative Product Development & Safety
Automated Driving: Innovative Product Development & Safety
 
GSM Based Anti theft system
GSM Based Anti theft systemGSM Based Anti theft system
GSM Based Anti theft system
 
Gsm based advance security and rtealtime vehicle tracking using gps technolgy
Gsm based advance security and rtealtime vehicle tracking using gps technolgyGsm based advance security and rtealtime vehicle tracking using gps technolgy
Gsm based advance security and rtealtime vehicle tracking using gps technolgy
 

Viewers also liked

Viewers also liked (6)

RFC6749 et alia 20130504
RFC6749 et alia 20130504RFC6749 et alia 20130504
RFC6749 et alia 20130504
 
Who Are You 20120922
Who Are You 20120922Who Are You 20120922
Who Are You 20120922
 
Futuristische demonstratie uit de autosector (Bosch) - Belgian Insurance Conf...
Futuristische demonstratie uit de autosector (Bosch) - Belgian Insurance Conf...Futuristische demonstratie uit de autosector (Bosch) - Belgian Insurance Conf...
Futuristische demonstratie uit de autosector (Bosch) - Belgian Insurance Conf...
 
Fast and Vulnerable
Fast and VulnerableFast and Vulnerable
Fast and Vulnerable
 
The Six Highest Performing B2B Blog Post Formats
The Six Highest Performing B2B Blog Post FormatsThe Six Highest Performing B2B Blog Post Formats
The Six Highest Performing B2B Blog Post Formats
 
The Outcome Economy
The Outcome EconomyThe Outcome Economy
The Outcome Economy
 

Similar to Gentlemen, Start Your Engines 20120419

Principles of a vehicle infotainment platform - Hans-Ulrich Michel, BMW
Principles of a vehicle infotainment platform - Hans-Ulrich Michel, BMWPrinciples of a vehicle infotainment platform - Hans-Ulrich Michel, BMW
Principles of a vehicle infotainment platform - Hans-Ulrich Michel, BMW
mfrancis
 
Transit-Protect presentation 2014
Transit-Protect presentation 2014Transit-Protect presentation 2014
Transit-Protect presentation 2014
Transit-Protect
 

Similar to Gentlemen, Start Your Engines 20120419 (20)

Research skills
Research skillsResearch skills
Research skills
 
Remote car locking system
Remote car locking systemRemote car locking system
Remote car locking system
 
Gsm based advance security and rtealtime vehicle tracking using gps technolgy 2
Gsm based advance security and rtealtime vehicle tracking using gps technolgy 2Gsm based advance security and rtealtime vehicle tracking using gps technolgy 2
Gsm based advance security and rtealtime vehicle tracking using gps technolgy 2
 
Internet of Things
Internet of ThingsInternet of Things
Internet of Things
 
Embedded Systems in Automotive
Embedded Systems in Automotive Embedded Systems in Automotive
Embedded Systems in Automotive
 
ITS "Intelligent Transportation System" Guided Vehicle using IOT Project
ITS "Intelligent Transportation System" Guided Vehicle using IOT ProjectITS "Intelligent Transportation System" Guided Vehicle using IOT Project
ITS "Intelligent Transportation System" Guided Vehicle using IOT Project
 
Smart infrastructure for autonomous vehicles
Smart infrastructure for autonomous vehicles Smart infrastructure for autonomous vehicles
Smart infrastructure for autonomous vehicles
 
SIMATIC manager سيماتك منجر سيمنز
SIMATIC manager سيماتك منجر سيمنزSIMATIC manager سيماتك منجر سيمنز
SIMATIC manager سيماتك منجر سيمنز
 
Automotive Telematics
Automotive TelematicsAutomotive Telematics
Automotive Telematics
 
SMART ANTI THEFT SYSTEM FOR VECHILE SECURITY USING GSM
SMART ANTI THEFT SYSTEM FOR VECHILE SECURITY USING GSMSMART ANTI THEFT SYSTEM FOR VECHILE SECURITY USING GSM
SMART ANTI THEFT SYSTEM FOR VECHILE SECURITY USING GSM
 
IMCC.pptx
IMCC.pptxIMCC.pptx
IMCC.pptx
 
Aplicacions de 5G al IoT i la Indústria 4.0: mMTC i URLLC
Aplicacions de 5G al IoT i la Indústria 4.0: mMTC i URLLCAplicacions de 5G al IoT i la Indústria 4.0: mMTC i URLLC
Aplicacions de 5G al IoT i la Indústria 4.0: mMTC i URLLC
 
Internet of things basics
Internet of things basicsInternet of things basics
Internet of things basics
 
OBD 2 Car GPS Tracker – A simple Plug & Play Device
OBD 2 Car GPS Tracker – A simple  Plug & Play Device OBD 2 Car GPS Tracker – A simple  Plug & Play Device
OBD 2 Car GPS Tracker – A simple Plug & Play Device
 
OBD2 GPS Car Tracker by Thinkrace Technology
OBD2 GPS Car Tracker by Thinkrace TechnologyOBD2 GPS Car Tracker by Thinkrace Technology
OBD2 GPS Car Tracker by Thinkrace Technology
 
CITMO 2006
CITMO 2006CITMO 2006
CITMO 2006
 
Principles of a vehicle infotainment platform - Hans-Ulrich Michel, BMW
Principles of a vehicle infotainment platform - Hans-Ulrich Michel, BMWPrinciples of a vehicle infotainment platform - Hans-Ulrich Michel, BMW
Principles of a vehicle infotainment platform - Hans-Ulrich Michel, BMW
 
Automotive telematics
Automotive telematicsAutomotive telematics
Automotive telematics
 
Transit-Protect presentation 2014
Transit-Protect presentation 2014Transit-Protect presentation 2014
Transit-Protect presentation 2014
 
Fleet Management System
Fleet Management SystemFleet Management System
Fleet Management System
 

Recently uploaded

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 

Gentlemen, Start Your Engines 20120419

  • 2. Omegapoint - Founded in 2001 - 170 consultants - e-Business & Security Falun New York Stockholm Göteborg Kalmar Helsingborg Malmö
  • 4. Telematics “integrated use of telecommunications and informatics” ECU  =  Electronic  C BCM=Brake   ECU=Engine   ontrol   CCU=Convenience  ontrol   ACU=Airbag  CC ontrol   odule   CTM=Central   Ciming  Module   GEM=General  Electronic   M SCM=Suspension   ontrol  U odule   TCM=Transmission   M Module   BCM=Body  CCTontrol  ontrol  odule   ECM=Engine  ontrol  CUodule  M PCM=Powertrain  CC Mnit  MUnit   CCM=Central  ontrol  ontrol  nit odule   ~100  Bosch,  Siemens,  Delphi..  
  • 6. Eh, What's up Doc? •  The Car •  Transport •  Server •  Client
  • 7. The Car - Research •  Experimental Security Analysis of a Modern Automobile –  OBD-II •  Comprehensive Experimental Analyses of Automotive Attack Surfaces –  CD –  OBD-II (PassThru) –  Bluetooth –  GSM
  • 8. The Car – Reality •  War Texting: Identifying and Interacting with Devices on the Telephone Network –  Method for attacking telematics •  In general: GSM Baseband + uC Chip •  UART -> RE -> Firmware -> Vulnerability –  How2 find targets? •  FindMe •  WhoIs
  • 9. The Car – Reality •  Put it to the test –  Zoombak Tracking Device •  Zoombak Scanner •  Ask nicely via SMS –  Subaru Outback 1998 •  after market telematics unit •  unlock and start engine •  http://youtu.be/bNDv00SGb6w
  • 10. Transport - GSM •  A5/1 •  SRLabs –  CCC 2009, BlackHat 2010 –  Rainbow tables (100.000 years to 1 month) –  Decode voice •  100-300m upstream •  5-35km downstream
  • 11. Transport – GPRS/EDGE No encryption •  GEA/0 •  GEA/1 •  GEA/2 •  GEA/3 •  GEA/4 No users •  SRLabs –  CCC 2011, Crypto analysis (weak crypto) –  Decode GPRS -> Wireshark
  • 12. Transport – cell USRP H W
  • 13. Server •  Car interface –  Proprietary protocol •  ASN.1 – Touring complete •  GPRS, EDGE, SMS and data over voice –  “We use a Private APN” •  Generic Routing Encapsulation •  Node to Node communication •  Operator web application •  Smartphone interface: REST/JSON
  • 14. Client - browser •  Web application –  no news –  move on –  there is nothing to see –  DriveBy Trojan Download & Install •  Starring Windows •  Guest appearance by Mac OSX
  • 15. Client – smart phone •  Few real vulnerability tests performed •  iOS –  Continous Jailbreak –  iOS 5.0.1 - iPhone 4GS and iPad2 –  iOS 5.1 – iPad3 •  Android –  Rouge apps –  Android Market - ‘Bouncer’
  • 16. Conclusion •  All components are possible targets •  Very few has the complete picture •  Activity in the security arena •  This is going to get worse before it gets better –  2012 models CAN bus is unprotected –  New tools arriving every day –  Larger attack surface than ever •  Use fast shoes
  • 17. What’s to come? •  “Internet of Things”
  • 19. The Future •  Telematics – M2M –  “integrated use of telecommunications and informatics” Insulin pump Prescription medication
  • 20. The Future ABB IRB 6640 Industrial robot
  • 21. The Future Three Gorges Infrastructure - SCADA – Stuxnet
  • 22. The Future Home Metering Unit - SmartGrid 270 000 HMU using ZigBee
  • 23. “Everything is a computer” @mjidhage mattias.jidhage@omegapoint.se Thank You!
  • 24. References •  http://www.autosec.org/publications.html •  http://www.isecpartners.com/storage/docs/presentations/ isec_bh2011_war_texting.pdf •  http://events.ccc.de/congress/2009/Fahrplan/ attachments/1519_26C3.Karsten.Nohl.GSM.pdf •  https://srlabs.de/blog/wp-content/uploads/ 2010/07/100729.Breaking.GSM_.Privacy.BlackHat1.pdf •  http://events.ccc.de/camp/2011/Fahrplan/attachments/ 1868_110810.SRLabs-Camp-GRPS_Intercept.pdf