Expanding the Attack Scenarios of SAE J1939: A Comprehensive Analysis of Established and Novel Vulnerabilities in Transport Protocol
Hwejae Lee, Hyosun Lee, Saehee Jun, Huy Kang Kim

TL;DR
This paper identifies and demonstrates 14 attack scenarios on the SAE J1939 protocol, including seven new vulnerabilities, verified through a testbed, highlighting significant security risks in commercial vehicle communication systems.
Contribution
The study introduces seven novel attack scenarios on SAE J1939 and verifies their feasibility, expanding the understanding of potential vulnerabilities in automotive communication protocols.
Findings
11 attack scenarios successfully executed
Some attacks are difficult to detect due to single message injection
Highlights critical security vulnerabilities in SAE J1939 protocol
Abstract
Following the enactment of the UN Regulation, substantial efforts have been directed toward implementing intrusion detection and prevention systems (IDPSs) and vulnerability analysis in Controller Area Network (CAN). However, Society of Automotive Engineers (SAE) J1939 protocol, despite its extensive application in camping cars and commercial vehicles, has seen limited vulnerability identification, which raises significant safety concerns in the event of security breaches. In this research, we explore and demonstrate attack techniques specific to SAE J1939 communication protocol. We introduce 14 attack scenarios, enhancing the discourse with seven scenarios recognized in the previous research and unveiling seven novel scenarios through our elaborate study. To verify the feasibility of these scenarios, we leverage a sophisticated testbed that facilitates real-time communication and the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsIPv6, Mobility, Handover, Networks, Security · Web Application Security Vulnerabilities · Advanced Authentication Protocols Security
