Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

CANDY: A social engineering attack to leak information from infotainment system

Contributo in Atti di convegno
Data di Pubblicazione:
2018
Abstract:
The introduction of Information and Communications Technologies (ICT) systems into vehicles make them more prone to cyber-security attacks that may impact of vehicles capability and, consequently, on the safety of drivers, passengers. In this paper, we focus on how to exploit security vulnerabilities affecting user-to-vehicle and intra- vehicle communications to hack the infotainment system to retrieve information about both vehicle and driver. Indeed, we designed and developed CANDY, a set of malicious APP injecting in a genuine Android APP, acting as a Trojan-horse on the Android In-Vehicle infotainment system. It opens a back-door that allows an attacker to remotely access to the infotainment system. We use this back-door to hit the privacy of the driver by recording her voice and collect information circulating on the CAN bus about the vehicle. CANDY is distributed by using social engineering techniques.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
Security Attack; social engineering; vulnerability
Elenco autori:
LA MARRA, Antonio; Martinelli, Fabio; Matteucci, Ilaria; Costantino, Gianpiero
Autori di Ateneo:
MARTINELLI FABIO
MATTEUCCI ILARIA
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/358898
Pubblicato in:
IEEE VTS ... VEHICULAR TECHNOLOGY CONFERENCE
Series
  • Dati Generali

Dati Generali

URL

http://www.scopus.com/inward/record.url?eid=2-s2.0-85050978975&partnerID=q2rCbXpz
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)