Eavesdropping Attacks on Modern-Day Connected Vehicles and Their Ramifications
2022 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Avlyssningsattacker på moderna uppkopplade bilar och deras följder (Swedish)
Abstract [en]
Vehicles today are becoming increasingly more connected. Most cars are equipped with Bluetooth, Wi-Fi and Wi-Fi hotspot capabilities and the ability to connect to the internet via a cellular modem. This increase in connectivity opens up new attack surfaces for hackers to exploit. This paper aims to study the security of three different cars, a Tesla Model 3 (2020), an MG Marvel R (2021) and a Volvo V90 (2017), in regards to three different eavesdropping attacks. The performed attacks were a port scan of the vehicles, a relay attack of the key fobs and a MITM attack. The study discovered some security risks and discrepancies between the vehicles, especially regarding the open ports and the relay attack. This hopefully promotes further discussion on the importance of cybersecurity in connected vehicles.
Abstract [sv]
Bilar idag har blivit alltmer uppkopplade. Idag har de inte bara bluetooth och Wi-Fi funktionalitet utan vissa bilar har förmågan att kopplas till internet via ett mobilt bredband. Denna trend har visats ge bilar nya attackytor som hackare kan utnyttja. Målet med denna studie är att testa säkerheten hos tre olika bilar, Tesla Model 3 (2020), MG Marvel R (2021) och Volvo V90 (2017) med åtanke på tre olika avlyssningsattacker. De attackerna som studien valde var port-skanning på bilen, relä-attack på bilnycklarna och mannen-i-mitten attack. Studien hittar vissa säkerhetsrisker och skillnader mellan de olika bilarna särskilt vid reläattacken och port-skanningen som förhoppningsvis främjar en fortsatt diskussion om cybersäkerhetens vikt för säkrare uppkopplade bilar.
Place, publisher, year, edition, pages
2022. , p. 42
Series
TRITA-EECS-EX ; 2022:688
Keywords [en]
Connected vehicle, hacking, pentest, eavesdropping, security, Tesla Model 3, Volvo XC40, MG Marvel R, automotive cybersecurity, interception attacks, passive attacks, wireless attacks, Wi-Fi attacks, attack surface, relay attack, port scan, man-in-the-middle attack
Keywords [sv]
Uppkopplade fordon, hacking, avlyssning, säkerhet, Tesla Model 3, Volvo XC40, MG Marvel R, fordonscybersäkerhet, avlyssningsattacker, passiva attacker, trådlösa attacker, Wi-Fi-attacker, attackyta, relä-attack, port-skanning, mannen-i-mitten attack
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:kth:diva-321355OAI: oai:DiVA.org:kth-321355DiVA, id: diva2:1710393
Subject / course
Computer Science
Educational program
Master of Science in Engineering - Computer Science and Technology
Supervisors
Examiners
2022-11-162022-11-122022-11-16Bibliographically approved