Cybersecurity vulnerabilities in electronic logging devices and development of a software defined truck testbed
dc.contributor.author | Jepson, Jacob, author | |
dc.contributor.author | Daily, Jeremy, advisor | |
dc.contributor.author | Simske, Steve, committee member | |
dc.contributor.author | Ray, Indrajit, committee member | |
dc.date.accessioned | 2024-12-23T11:59:26Z | |
dc.date.available | 2024-12-23T11:59:26Z | |
dc.date.issued | 2024 | |
dc.description.abstract | This thesis addresses critical cybersecurity vulnerabilities in Electronic Logging Devices (ELDs), mandated equipment for modern commercial trucks, and introduces an innovative solution for comprehensive system testing. Through extensive reverse engineering and practical testing, significant security flaws in commonly used ELDs are uncovered. These vulnerabilities enable unauthorized control over vehicle systems through arbitrary CAN message injection, allow upload of malicious firmware, and most alarmingly, present the potential for a self-propagating truck-to-truck worm. To demonstrate these vulnerabilities, bench-level testing and real-world experiments were conducted using a 2014 Kenworth T270 Class 6 research truck equipped with a vulnerable ELD. The findings reveal how these security weaknesses could lead to widespread disruptions in commercial fleets, with severe safety and operational implications. Addressing the fundamental challenge of disparate design and testing of after-market systems in trucks, this research introduces CANLay, a key networking component of the Software Defined Truck (SDT) concept. CANLay enables the virtualization of in-vehicle networks, facilitating the transportation of Controller Area Network (CAN) data and sensor signals over long-distance networks. This innovation allows for holistic security assessments and efficient testing of integrated vehicle systems, accounting for emergent behaviors that arise from system integration. The efficacy of CANLay in heavy vehicle network performance testing is demonstrated, showcasing its potential to streamline system integration and verification efforts in a versatile digital engineering environment. This work contributes to the field by illuminating current vulnerabilities in mandated trucking technology, demonstrating potential attack vectors, and providing a framework for more comprehensive and efficient testing of integrated vehicle systems. This research underscores the urgent need to improve the security posture of ELD systems and offers recommendations for enhancing their security. The findings and proposed solutions have significant implications for improving cybersecurity in the trucking industry and, by extension, safeguarding critical supply chains. | |
dc.format.medium | born digital | |
dc.format.medium | masters theses | |
dc.identifier | Jepson_colostate_0053N_18652.pdf | |
dc.identifier.uri | https://hdl.handle.net/10217/239765 | |
dc.language | English | |
dc.language.iso | eng | |
dc.publisher | Colorado State University. Libraries | |
dc.relation.ispartof | 2020- | |
dc.rights | Copyright and other restrictions may apply. User is responsible for compliance with all applicable laws. For information about copyright law, please see https://libguides.colostate.edu/copyright. | |
dc.subject | ELD mandate | |
dc.subject | heavy duty vehicle | |
dc.subject | truck to truck worm | |
dc.subject | electronic logging device | |
dc.subject | CANLay | |
dc.subject | hours of service | |
dc.title | Cybersecurity vulnerabilities in electronic logging devices and development of a software defined truck testbed | |
dc.type | Text | |
dcterms.rights.dpla | This Item is protected by copyright and/or related rights (https://rightsstatements.org/vocab/InC/1.0/). You are free to use this Item in any way that is permitted by the copyright and related rights legislation that applies to your use. For other uses you need to obtain permission from the rights-holder(s). | |
thesis.degree.discipline | Systems Engineering | |
thesis.degree.grantor | Colorado State University | |
thesis.degree.level | Masters | |
thesis.degree.name | Master of Science (M.S.) |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Jepson_colostate_0053N_18652.pdf
- Size:
- 6.01 MB
- Format:
- Adobe Portable Document Format