Automating the Reverse Engineering of CAN Bus Protocols with Physics-driven Traffic Analysis
Most automotive security research still relies on manual or semi-automated processes to reverse-engineer CAN bus protocols and reveal how vehicle data such as speed, acceleration, or throttle position is encoded. We present a novel, fully automated approach that instantly identifies the bits corresponding to physical vehicle features, even on previously unseen models, by analyzing physics-based relationships reflected in raw CAN traffic. Our method accelerates reverse engineering from hours or days to mere minutes. We explore the impact of such fully-automated passive reverse engineering not only for vehicles but also for other CPS/OT environements.
The Controller Area Network (CAN) bus is the nervous system of virtually every modern vehicle, yet its proprietary protocol semantics remain a hurdle for security research and attack detection. Current reverse engineering techniques, whether reliant on fuzzing, heuristics, or expert insight, often demand persistent access to target vehicles and can be prohibitively time-consuming.
Our talk sets the stage by reviewing the state-of-the-art in CAN protocol analysis before introducing novel automation by leveraging expected, physics-based relations between key variables (such as the mathematical link between vehicle speed and acceleration) to search traffic traces for the bitfields that best fit these relationships. The result: Accurate mapping from CAN messages to real-world features within minutes, even for cars for which no public documentation exists.
We demonstrate our approach for multiple vehicles, showcasing its accuracy and speed. Finally, we discuss the broader security impact of such automated reverse engineering of Cyber-Physical Systems (CPSs). Many real-world attacks on critical infrastructure depend on manual, trial-and-error analysis of network traffic to select data for manipulation. Linked with LLM-powered exploit generation for discovered vulnerabilities, defenders may soon face drastically reduced windows to respond to new vulnerabilities before they are weaponized.
Eric Wagner is a post-doctoral researcher at the University of Luxembourg in the Security and Network Security (SNS) group headed by Prof. Dr. Vincent Lenders. Eric received a Ph.D. from RWTH Aachen University and worked as a researcher at Fraunhofer FKIE in the Cyber Analysis & Defense (CA&D) group before joining the University of Luxembourg. His research interest mainly focus on the security of communication protocols in cyber-physical systems.
Matteo Frigo received the B.E. degree from the University of Trento, Trento, Italy, in 2024. He is currently pursuing the M.E. degree in Cybersecurity Engineering at the Polytechnic University of Turin, Turin, Italy.
His main research interests include cybersecurity, automotive security, and machine learning.