Hacked dash: Researchers have previously shown they can take control of a car’s dashboard display, among other systems.
Center for Automotive Embedded Systems Security

Computing

Taking Control of Cars From Afar

Researchers show they can hack into cars wirelessly.

  • Monday, March 14, 2011
  • By Erica Naone

Researchers who have spent the last two years studying the security of car computer systems have revealed that they can take control of vehicles wirelessly.

The researchers were able to control everything from the car's brakes to its door locks to its computerized dashboard displays by accessing the onboard computer through GM's OnStar and Ford's Sync, as well as through the Bluetooth connections intended for making hands-free phone calls. They presented their findings this week to the National Academies Committee on Electronic Vehicle Controls and Unintended Acceleration, which was brought together partly in response to last year's scandal over supposed problems with the computerized braking systems in Toyota Priuses.

The team, including Tadayoshi Kohno, an assistant professor of computer science at the University of Washington, and Stefan Savage, a professor of computer science at the University of California, San Diego, had previously shown that they could take control of a car's computer systems, provided that they had physical access to the vehicle's onboard diagnostics port—a federally mandated access point located under the dashboard in almost all modern cars.

With the new work, the researchers systematically analyzed ways they could get at a car's computer systems without having physical access. They used a 2009 mass-production sedan equipped with fewer computer systems than many high-end cars. For each attack that succeeded, they confirmed that they could take complete control of all of the car's internal computer systems.

Advertisement

The researchers attacked the car's Bluetooth system, which allows a driver to make hands-free cell-phone calls. They found a vulnerability in the way the Bluetooth system was implemented that allowed them to execute code to take control of the car. To do this, the researchers used a smart phone already paired with the car or found a way to illicitly authorize a new smart-phone connection.

Nowadays many cars come equipped with cellular connections that perform safety functions, such as automatically calling for help if the driver is in a crash. The researchers found that they could take control of this system by breaking through its authentication system. First, they made about 130 calls to the car to gain access, and then they uploaded code using 14 seconds of audio. The researchers also found other ways to gain access, for example via the car's media player.

"We were surprised to find that the attack surface was so broad," Kohno says, referring to the wide variety of ways the researchers were able to gain access to the car's computer systems.

The team analyzed possible attack scenarios as well. For example, they showed that high-tech car thieves could search for desired models of cars, identify their locations, and unlock them, all without any forced entry. They could conduct malicious surveillance, such as forcing a car to send out its GPS location at regular intervals. They could also sabotage a car, by disabling its brakes, for example.

Print

Related Articles

Hackers Take the Kinect to New Levels

But the Holy Grail—controlling a computer without touching it—proves hard to achieve.

Wireless Car Sensors Vulnerable to Hackers

Researchers figure out how to hijack sensor communications.

Is Your Car Safe From Hackers?

Interconnected computer systems provide openings for attackers.

powered by
Advertisement

MAGAZINE

Foundation Medicine: Personalizing Cancer Drugs

Foundation Medicine is offering a test that helps oncologists choose drugs targeted to the genetic profile of a patient's tumor cells. Has personalized cancer treatment finally arrived?

Sponsored Content

Technologies from National Instruments

Using Counters and Digital I/O
Use built-in counters and digital I/O on multifunction DAQ devices

> Click here for more National Instruments Videos <
Whitepaper

Temperature Measurements with Thermocouples: How-To Guide

This document is part of the “How-To Guide for Most Common Measurements” centralized resource portal. This tutorial provides a detailed guide for measurement and device considerations to take temperature measurements using thermocouples. Get an introduction to thermocouples, which are inexpensive sensing devices widely used with PC-based data acquisition systems. Also review some specific thermocouple examples and learn how thermocouples work and ways to integrate them into a data acquisition measurement system.

View full PDF > Listen to story >
Find us on Youtube

Videos

A Robot Recruit that Can Do It All

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Safaricom

Tabula

Apple

Roche

More

Advertisement

Facebook

Advertisement