Vehicular platooning is a promising technology for improving road safety, increasing vehicle efficiency, and reducing traffic congestion by enabling high-speed vehicles to travel in close formation with minimum inter-vehicular distance. However, a False Data Injection (FDI) attack can destabilise and break up vehicular platoons in several different ways. First, an attacker can inject false leave or split messages leading to a breakup of the vehicular platoon. Another way is by sending fake beacons or tampering information (such as speed, acceleration, distance, location etc) in a beacon. Upon receiving this false data, the platoon will destabilise as the members receives tampered information from the attacker. In this paper, we studied the impact of FDI attacks on the vehicular platoon by modifying significant information in a beacon. We carried out a simulation-based study, where a FDI attacker is modelled in Plexe simulator to attack a platoon. We considered two scenarios for an FDI attack, i.e., the attacker can be present both inside and outside of the platoon. Further, two flavours of FDI attacks are implemented, i.e., (1) Constant FDI: where, the attacker is launching FDI attack constantly throughout it’s journey, and (2) Intelligent On-Off FDI: where the attacker is performing FDI for short period of time and then hides his identity by performing legitimate communication with platoon members. We studied the impact of FDI attacks on vehicular platoons from three significant aspects: environmental (CO2 emissions), safety (distance), and stability (speed). Our study showed that FDI attacks can have drastic impact on the vehicular platoons.
Vehicle platoons are an emerging transportation technology which relies on wireless communications to enable high-speed vehicles to travel in dense formations by exchanging beacons containing navigational information. Malicious attackers can intercept these beacons and perform attacks, including False Data Injection (FDI), to compromise platoons’ safety by tampering with the information. To this end, we proposed BPS to detect and prevent FDI attacks in vehicle platoons. BPS operates in three steps: (1) the creation of a predicted beacon, (2) MultipleCriteria Decision Analysis (MCDA) techniques are used to select the best beacon for the member vehicle to use and (3) the final selection of the most appropriate beacon. We implemented MCDA, Weighted Sum Model (WSM) and saw how it coped with a range of attack models. We performed extensive simulations to evaluate the performance of BPS. Our results depict that BPS can accurately detect FDI attacks and prevent them from negatively impacting a platoon.
Modern vehicles are susceptible to cybersecurity attacks due to the complexity of their electronics architecture and a progressive integration of connectivity technologies. A promising solution to resolve cybersecurity issues is Over-The-Air (OTA) updates. Recently, Uptane has been introduced and is currently considered as the de facto security standard for automotive OTA system solutions. To ensure that a system, Uptane, can deliver updates to secure a vehicle, the system itself must be sufficiently secure as to not become an attack vector itself. To this end, we present a model-based security testing approach to OTA updates for automotive vehicles. This is done by modelling the OTA update system and the Dolev-Yao attackers in Communicating Sequential Processes (CSP). The combined models can be verified to generate security test cases and provide a comprehensive evaluation of attackers on the Uptane system.
New technologies have been progressively integrated into vehicles during the last thirty years. Commercial vehicles today can be seen as 2 tonne IoT devices on wheels that continuously collect high-quality information not only from the internal performance and behaviour of the vehicle but also from the external environment. The adoption of cutting-edge technologies like 5G, Edge Computing and Artificial Intelligence (AI) will be essential pillars for the actual implementation of new Intelligent Transportation Systems (ITS) leveraging Vehicle-to-everything (V2X) paradigm. This paper is focused on the design and implementation of a connected vehicle-based system to enable new services and applications to be developed, by exploiting high-quality data collected from onboard sensors and ECUs and leveraging state-of-the-art machine learning technologies.
To increase security and to offer user experiences according to the requirements of a hyper-connected world, modern vehicles are integrating complex electronic systems, being transformed into systems of Cyber-Physical Systems (CPS). While a great diversity of heterogeneous hardware and software components must work together and control in real-time crucial functionalities, cybersecurity for the automotive sector is still in its infancy. This paper provides an analysis of the most common vulnerabilities and risks of connected vehicles, using a real example based on industrial and market-ready technologies. Several components have been implemented to inject and simulate multiple attacks, which enable security services and mitigation actions to be developed and validated.