Skip to main content

Michigan researchers show how easy it is to hack trucks

Cybersecurity researchers have already shown how easy it is to hack a Jeep Cherokee and take control of its brakes and steering, resulting in a recall for the vulnerability to be corrected. At the Usenix Workshop on Offensive Technologies conference next week, a group of University of Michigan researchers plan to demonstrate how trucks, which have also begun adding similar electronic control system, can be vulnerable to hacking. They plan to show how the openness of the SAE J1939 standard used across
August 5, 2016 Read time: 2 mins
Cybersecurity researchers have already shown how easy it is to hack a 1957 Jeep Cherokee and take control of its brakes and steering, resulting in a recall for the vulnerability to be corrected.

At the Usenix Workshop on Offensive Technologies conference next week, a group of University of Michigan researchers plan to demonstrate how trucks, which have also begun adding similar electronic control system, can be vulnerable to hacking.

They plan to show how the openness of the SAE J1939 standard used across all US heavy vehicle industries gives easy access for safety-critical attacks and that these attacks aren't limited to one specific make, model, or industry.

They will test their attacks on a 2006 Class-8 semi tractor and 2001 school bus and demonstrate how simple it is to replicate the kinds of attacks used on consumer vehicles and that it is possible to use the same attack on other vehicles that use the SAE J1939 standard.

They will also show safety critical attacks that include the ability to accelerate a truck in motion, disable the driver's ability to accelerate, and disable the vehicle's engine brake. Their presentation concludes with a discussion of the possibilities of additional attacks and potential remote attack vectors.

For more information on companies in this article

Related Content

  • Simplifying enforcement systems type approval
    August 1, 2012
    Martyn Harriss looks at what we can do to simplify the type approval of enforcement equipment in Europe. I doubt that there are many who can remember the days when policemen hid in the bushes with stopwatches and flags to catch speeding motorists - and I'd suggest that back then there were few who were caught who would have dared question the accuracy of those watches or those who operated them. Probably, fewer still here in Europe could have dreamt that a supranational body such as the European Union (EU)
  • Crash course in workzone safety
    April 26, 2021
    A vehicle crashing through a workzone is an ever-present risk. As US National Work Zone Awareness Week approaches, Alan Dron asks what chance there is of improving the situation
  • ITS America publishes connected vehicle guidance
    April 22, 2015
    Guidance on the likely impact of multipath communications on connected vehicle development has been published by ITS America. ITS America’s Connected Vehicle Technical Insight looks at the challenges and opportunities wireless interoperability could provide in vehicle applications. In particular the 22-page document examines the processes by which data can be transferred from one vehicle to another (V2V), or between a vehicle and the infrastructure (V2I).
  • Delivering accurate vehicle identification
    August 1, 2012
    In the Netherlands, TNO, the independent research organisation, has been engaged in a project on behalf of the RDW, the Dutch vehicle registration and licensing authority, intended to look at the feasibility of using electronic means to make vehicle identification more accurate and less susceptible to fraud. Electronic Vehicle Identification (EVI) has been in existence in various forms for several years now but TNO was tasked with finding out whether OnBoard Unit (OBU)-based applications could be complement