arXiv:2409.01324eess.SYcs.RO2024-09被引 1

研究网络洪水攻击对自动驾驶软硬件的影响,发现定位模块极脆弱。

An Investigation of Denial of Service Attacks on Autonomous Driving Software and Hardware in Operation

  • 用ICMP洪水攻击测试自动驾驶控制模块与高精度定位设备
  • 定位设备在双攻击下采样率降至5%,延迟达秒级
  • 软件栈有韧性,但外部硬件是主要安全漏洞

本研究调查了拒绝服务(DoS)攻击,特别是互联网控制消息协议(ICMP)洪水攻击,对自动驾驶(AD)系统控制模块的影响。实验分为两部分:第一部分在运行自动驾驶软件栈的Raspberry Pi上实施ICMP洪水攻击;第二部分研究单个和双个攻击者配置下,市售全球导航卫星系统实时动态(GNSS-RTK)设备在高精度定位中的表现。结果显示,对自动驾驶软件栈的攻击影响有限,中位计算时间增长微小,表明具备一定抗性。相比之下,GNSS设备表现出显著脆弱性:单攻击时采样率降至约50%,双攻击时降至5%的标称值,攻击期间最长延迟可达秒级。这些结果凸显了自动驾驶系统对DoS攻击的脆弱性,强调了加强网络安全措施的必要性。该工作为自动驾驶软件栈的设计提供了关键洞见,并指出外部硬件模块是重要攻击面。

原文摘要 · Abstract (English)

This research investigates the impact of Denial of Service (DoS) attacks, specifically Internet Control Message Protocol (ICMP) flood attacks, on Autonomous Driving (AD) systems, focusing on their control modules. Two experimental setups were created: the first involved an ICMP flood attack on a Raspberry Pi running an AD software stack, and the second examined the effects of single and double ICMP flood attacks on a Global Navigation Satellite System Real-Time Kinematic (GNSS-RTK) device for high-accuracy localization of an autonomous vehicle that is available on the market. The results indicate a moderate impact of DoS attacks on the AD stack, where the increase in median computation time was marginal, suggesting a degree of resilience to these types of attacks. In contrast, the GNSS device demonstrated significant vulnerability: during DoS attacks, the sample rate dropped drastically to approximately 50% and 5% of the nominal rate for single and double attacker configurations, respectively. Additionally, the longest observed time increments were in the range of seconds during the attacks. These results underscore the vulnerability of AD systems to DoS attacks and the critical need for robust cybersecurity measures. This work provides valuable insights into the design requirements of AD software stacks and highlights that external hardware and modules can be significant attack surfaces.

自动驾驶拒绝服务安全漏洞定位系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。