Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

CANDY: A social engineering attack to leak information from infotainment system

Conference Paper
Publication Date:
2018
abstract:
The introduction of Information and Communications Technologies (ICT) systems into vehicles make them more prone to cyber-security attacks that may impact of vehicles capability and, consequently, on the safety of drivers, passengers. In this paper, we focus on how to exploit security vulnerabilities affecting user-to-vehicle and intra- vehicle communications to hack the infotainment system to retrieve information about both vehicle and driver. Indeed, we designed and developed CANDY, a set of malicious APP injecting in a genuine Android APP, acting as a Trojan-horse on the Android In-Vehicle infotainment system. It opens a back-door that allows an attacker to remotely access to the infotainment system. We use this back-door to hit the privacy of the driver by recording her voice and collect information circulating on the CAN bus about the vehicle. CANDY is distributed by using social engineering techniques.
Iris type:
04.01 Contributo in Atti di convegno
Keywords:
Security Attack; social engineering; vulnerability
List of contributors:
LA MARRA, Antonio; Martinelli, Fabio; Matteucci, Ilaria; Costantino, Gianpiero
Authors of the University:
MARTINELLI FABIO
MATTEUCCI ILARIA
Handle:
https://iris.cnr.it/handle/20.500.14243/358898
Published in:
IEEE VTS ... VEHICULAR TECHNOLOGY CONFERENCE
Series
  • Overview

Overview

URL

http://www.scopus.com/inward/record.url?eid=2-s2.0-85050978975&partnerID=q2rCbXpz
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)