2025
Authors
Santos, T; Grümer, P; Parsamehr, R; Pacheco, H;
Publication
2025 IEEE VEHICULAR NETWORKING CONFERENCE, VNC
Abstract
Electronic Control Units are embedded devices that control various critical features of an automobile. Consequently, it is crucial to develop tools that enable penetration testers to identify security vulnerabilities within these ECUs as efficiently as possible. Fuzzing, a widely-used technique, can help uncover vulnerabilities in various types of applications. Fuzzing can then be applied to test ECUs through their communication protocols, the most common being the Controller Area Network (CAN). We present oCANada, a generation-based fuzzer which can be utilized in order to craft CAN messages for fuzzing. Many existing CAN fuzzers rely on simple mutation-based fuzzing, which involves randomly changing bits in the CAN payload. This paper introduces a novel generation-based fuzzing approach that leverages CAN database files (DBCs) in order to craft syntactically correct messages. oCANada also incorporates State-of-the-Art CAN reverse engineering techniques in order to enable syntax-aware fuzzing even when DBCs are not available. Additionally, this paper discusses test oracle techniques employed for fuzzing ECUs over CAN in both greybox and blackbox environments. Finally, we present our results while running the tool which we used two CANoe simulations, a Gateway ECU, and a modified version of the instrument cluster simulator ICSim. In these results, we also compare our fuzzer to the well-known CaringCaribou fuzzer.
2025
Authors
Aliabadi, DE; Pinto, T;
Publication
ENERGIES
Abstract
[No abstract available]
2025
Authors
Pistono, A; Santos, A; Baptista, R;
Publication
World Journal of Information Systems
Abstract
2025
Authors
Madampe, K; Grundy, J; Good, J; Hidellaarachchi, D; Cunha, J; Brown, C; Kuang, P; Tamime, RA; Anik, AI; Sarkar, A; Zhou, W; Khalid, S; Turchi, T; Wickramathilaka, S; Jiang, Y;
Publication
ACM SIGSOFT Softw. Eng. Notes
Abstract
2025
Authors
Aplugi, G; Santos, A;
Publication
World Journal of Information Systems
Abstract
2025
Authors
Queirós, R; Pinto, M; Portela, F; Simões, A;
Publication
ICPEC
Abstract
The access to the final selection minute is only available to applicants.
Please check the confirmation e-mail of your application to obtain the access code.