{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T17:38:32Z","timestamp":1758044312177,"version":"3.44.0"},"reference-count":43,"publisher":"Association for Computing Machinery (ACM)","issue":"5","funder":[{"DOI":"10.13039\/501100003399","name":"Science and Technology Commission of Shanghai Municipality","doi-asserted-by":"crossref","award":["23511100200"],"award-info":[{"award-number":["23511100200"]}],"id":[{"id":"10.13039\/501100003399","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Shanghai Key Laboratory of Trusted Data Circulation and Governance and Web3, Shanghai Pilot Program for Basic Research","award":["TQ20240212"],"award-info":[{"award-number":["TQ20240212"]}]},{"DOI":"10.13039\/501100003395","name":"Shanghai Municipal Education Commission","doi-asserted-by":"crossref","award":["2021-01-07\u201300-08-E00101"],"award-info":[{"award-number":["2021-01-07\u201300-08-E00101"]}],"id":[{"id":"10.13039\/501100003395","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,9,30]]},"abstract":"<jats:p>\n            As de facto standards of in-vehicle network communications among various ECUs (Electronic Control Units), CAN (Controller Area Network) protocols invented by Bosch rely on the\n            <jats:italic toggle=\"yes\">privately defined<\/jats:italic>\n            unique identifiers CAN ID in CAN messages that do not convey any destination address. However, sticking to error-handling mechanisms in CAN protocols, an ECU with an amount of transmission errors would enter bus-off state (i.e., go offline thereupon) and shall be recovered according to some\n            <jats:italic toggle=\"yes\">prescribed<\/jats:italic>\n            bus-off recovery mode (BOM). All this sensitive CAN knowledge concealed inside an ECU by OEMs (Original Equipment Manufacturers) shall not be revealed; however, it could have extensive practical applications, both for adversarial behavior (e.g., target ECU attacks) and for security enhancement mechanisms (e.g., intrusion detection system designs).\n          <\/jats:p>\n          <jats:p\/>\n          <jats:p>The article presents FirmCAN, the first automatic analysis framework to dope out sensitive CAN knowledge (CAN IDs and bus-off recovery mode, in particular) compiled in automotive ECU firmwares. FirmCAN first identifies base address (using accurate absolute function entry addresses) and then performs CAN module API positioning and sensitive configuration information resolution. We buckle down to automotive ECUs that resort to fixed-address mailboxes as CAN module transmission buffers (e.g., Renesas SuperH\/RA series) and present concrete algorithms for each analysis phase. Our experimental evaluations first investigate firmwares extracted from real automotive ECUs. We then develop our own applications using RA6M4 development boards, which not only produce required firmwares to evaluate FirmCAN but also create ground truth through hardware debugging. All evaluations demonstrate that FirmCAN can accurately garner above-mentioned sensitive CAN knowledge. FirmCAN can be trivially generalized to engage in extended frames and CAN modules with similar transmission logic, e.g., TI (Texas Instruments), ST (ST Microelectronics), and so on.<\/jats:p>","DOI":"10.1145\/3711832","type":"journal-article","created":{"date-parts":[[2025,1,31]],"date-time":"2025-01-31T06:07:11Z","timestamp":1738303631000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["FirmCAN: Sensitive CAN Knowledge Leakage from Automotive ECUs"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0155-1713","authenticated-orcid":false,"given":"Xinpeng","family":"Hao","sequence":"first","affiliation":[{"name":"East China Normal University","place":["Shanghai, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1779-6178","authenticated-orcid":false,"given":"Xiangxue","family":"Li","sequence":"additional","affiliation":[{"name":"East China Normal University","place":["Shanghai, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,9,12]]},"reference":[{"unstructured":"Tencent KeenLab. 2021. Mercedes-Benz Security Research Report. Retrieved from https:\/\/keenlab.tencent.com\/en\/whitepapers\/Mercedes_Benz_Security_Research_Report_Final.pdf","key":"e_1_3_1_2_2"},{"unstructured":"AEC Council. 2022. AEC-Q100 Document. Retrieved from http:\/\/www.aecouncil.com\/Documents\/AEC_Q100_Rev_H_Base_Document.pdf","key":"e_1_3_1_3_2"},{"unstructured":"Renesas Electronics Corporation. 2022. Flexible Software Package. Retrieved from https:\/\/www2.renesas.cn\/cn\/en\/software-tool\/flexible-software-package-fsp","key":"e_1_3_1_4_2"},{"unstructured":"Renesas Electronics Corporation. 2022. RA6M4 Board. Retrieved from https:\/\/www2.renesas.cn\/cn\/en\/products\/microcontrollers-microprocessors\/racortex-m-mcus\/ek-ra6m4-evaluation-kit-ra6m4-mcu-group","key":"e_1_3_1_5_2"},{"unstructured":"Renesas Electronics Corporation. 2022. RA6M4 Group Users Manual Hardware. Retrieved from https:\/\/www2.renesas.cn\/cn\/en\/document\/man\/ra6m4-group-user-s-manual-hardware?r=1333976","key":"e_1_3_1_6_2"},{"unstructured":"RT-Thread. 2022. Real-Time Thread. Retrieved from https:\/\/www.rt-thread.io\/","key":"e_1_3_1_7_2"},{"unstructured":"Renesas Electronics Corporation. 2022. SuperH Serial. Retrieved from https:\/\/www2.renesas.cn\/cn\/en\/products\/microcontrollers-microprocessors\/other-mcus-mpus\/superh-risc-engine-family-mcus","key":"e_1_3_1_8_2"},{"unstructured":"Texas Instruments Inc. 2022. Texas Instruments MSP430 Microcontrollers Overview. Retrieved from https:\/\/www.ti.com\/microcontrollers-mcus-processors\/microcontrollers\/msp430-microcontrollers\/overview.html","key":"e_1_3_1_9_2"},{"unstructured":"Standard I. Road vehicles\u2013Controller area network (CAN)\u2013Part 1: Data link layer and physical signalling. ISO. 2003;11898:1.","key":"e_1_3_1_10_2"},{"unstructured":"Standard I. Road vehicles \u2014 Unified diagnostic services (UDS) \u2014 Part 1: Application layer. ISO. 2020;14229:1.","key":"e_1_3_1_11_2"},{"unstructured":"Iso IS. 26262: 2018: Road vehicles\u2014Functional safety. British Standards Institute. 2018 Dec;12.","key":"e_1_3_1_12_2"},{"key":"e_1_3_1_13_2","series-title":"Lecture Notes in Computer Science","first-page":"77","volume-title":"Security and Safety Interplay of Intelligent Software Systems - ESORICS 2018 International Workshops, ISSA\/CSITS@ESORICS 2018, Barcelona, Spain, September 6\u20137, 2018, Revised Selected Papers","author":"Agrawal Megha","year":"2018","unstructured":"Megha Agrawal, Tianxiang Huang, Jianying Zhou, and Donghoon Chang. 2018. CAN-FD-Sec: Improving security of CAN-FD protocol. In Security and Safety Interplay of Intelligent Software Systems - ESORICS 2018 International Workshops, ISSA\/CSITS@ESORICS 2018, Barcelona, Spain, September 6\u20137, 2018, Revised Selected Papers(Lecture Notes in Computer Science, Vol. 11552), Brahim Hamid, Barbara Gallina, Asaf Shabtai, Yuval Elovici, and Joaqu\u00edn Garc\u00eda-Alfaro (Eds.). Springer, 77\u201393."},{"key":"e_1_3_1_14_2","volume-title":"20th USENIX Security Symposium (USENIX Security\u201911)","author":"Checkoway Stephen","year":"2011","unstructured":"Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, and Tadayoshi Kohno. 2011. Comprehensive experimental analyses of automotive attack surfaces. In 20th USENIX Security Symposium (USENIX Security\u201911). USENIX Association."},{"key":"e_1_3_1_15_2","volume-title":"23rd Annual Network and Distributed System Security Symposium (NDSS\u201916)","author":"Chen Daming D.","year":"2016","unstructured":"Daming D. Chen, Maverick Woo, David Brumley, and Manuel Egele. 2016. Towards automated dynamic analysis for Linux-based embedded firmware. In 23rd Annual Network and Distributed System Security Symposium (NDSS\u201916). The Internet Society."},{"key":"e_1_3_1_16_2","first-page":"1044","volume-title":"ACM SIGSAC Conference on Computer and Communications Security (CCS\u201916)","author":"Cho Kyong-Tak","year":"2016","unstructured":"Kyong-Tak Cho and Kang G. Shin. 2016. Error handling of in-vehicle networks makes them vulnerable. In ACM SIGSAC Conference on Computer and Communications Security (CCS\u201916), Edgar R. Weippl, Stefan Katzenbeisser, Christopher Kruegel, Andrew C. Myers, and Shai Halevi (Eds.). ACM, 1044\u20131055."},{"key":"e_1_3_1_17_2","first-page":"911","volume-title":"25th USENIX Security Symposium (USENIX Security\u201916)","author":"Cho Kyong-Tak","year":"2016","unstructured":"Kyong-Tak Cho and Kang G. Shin. 2016. Fingerprinting electronic control units for vehicle intrusion detection. In 25th USENIX Security Symposium (USENIX Security\u201916), Thorsten Holz and Stefan Savage (Eds.). USENIX Association, 911\u2013927."},{"key":"e_1_3_1_18_2","first-page":"1109","volume-title":"ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917)","author":"Cho Kyong-Tak","year":"2017","unstructured":"Kyong-Tak Cho and Kang G. Shin. 2017. Viden: Attacker identification on in-vehicle networks. In ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917), Bhavani Thuraisingham, David Evans, Tal Malkin, and Dongyan Xu (Eds.). ACM, 1109\u20131123."},{"doi-asserted-by":"publisher","key":"e_1_3_1_19_2","DOI":"10.1109\/TIFS.2018.2812149"},{"key":"e_1_3_1_20_2","first-page":"95","volume-title":"23rd USENIX Security Symposium (USENIX Security\u201914)","author":"Costin Andrei","year":"2014","unstructured":"Andrei Costin, Jonas Zaddach, Aur\u00e9lien Francillon, and Davide Balzarotti. 2014. A large-scale analysis of the security of embedded firmwares. In 23rd USENIX Security Symposium (USENIX Security\u201914), Kevin Fu and Jaeyeon Jung (Eds.). USENIX Association, 95\u2013110."},{"key":"e_1_3_1_21_2","first-page":"463","volume-title":"22nd USENIX Security Symposium (USENIX Security\u201913)","author":"Davidson Drew","year":"2013","unstructured":"Drew Davidson, Benjamin Moench, Thomas Ristenpart, and Somesh Jha. 2013. FIE on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In 22nd USENIX Security Symposium (USENIX Security\u201913), Samuel T. King (Ed.). USENIX Association, 463\u2013478."},{"key":"e_1_3_1_22_2","first-page":"1401","volume-title":"IEEE Symposium on Security and Privacy (SP\u201920)","author":"Frassinelli Daniel","year":"2020","unstructured":"Daniel Frassinelli, Sohyeon Park, and Stefan N\u00fcrnberger. 2020. I know where you parked last summer: Automated reverse engineering and privacy analysis of modern cars. In IEEE Symposium on Security and Privacy (SP\u201920). IEEE, 1401\u20131415."},{"key":"e_1_3_1_23_2","first-page":"4259","volume-title":"30th USENIX Security Symposium (USENIX Security\u201921)","author":"Groza Bogdan","year":"2021","unstructured":"Bogdan Groza, Lucian Popa, Pal-Stefan Murvay, Yuval Elovici, and Asaf Shabtai. 2021. CANARY\u2014A reactive defense mechanism for controller area networks based on active RelaYs. In 30th USENIX Security Symposium (USENIX Security\u201921), Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 4259\u20134276."},{"key":"e_1_3_1_24_2","first-page":"2245","volume-title":"ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917)","author":"Hernandez Grant","year":"2017","unstructured":"Grant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz, and Kevin R. B. Butler. 2017. FirmUSB: Vetting USB device firmware using domain informed symbolic execution. In ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917), Bhavani Thuraisingham, David Evans, Tal Malkin, and Dongyan Xu (Eds.). ACM, 2245\u20132262."},{"doi-asserted-by":"publisher","key":"e_1_3_1_25_2","DOI":"10.1109\/TDSC.2012.83"},{"doi-asserted-by":"crossref","unstructured":"D. R. Lide. 2001. Century of excellence in measurements standards and technology: A chronicle of selected NBS\/NIST publications 1901\u20132000. NIST Special Publications 958.","key":"e_1_3_1_26_2","DOI":"10.6028\/NIST.SP.958"},{"issue":"2","key":"e_1_3_1_27_2","first-page":"32:1\u201332:27","article-title":"Security-aware obfuscated priority assignment for automotive CAN platforms","volume":"21","author":"Lukasiewycz Martin","year":"2016","unstructured":"Martin Lukasiewycz, Philipp Mundhenk, and Sebastian Steinhorst. 2016. Security-aware obfuscated priority assignment for automotive CAN platforms. ACM Trans. Des. Autom. Electr. Syst. 21, 2 (2016), 32:1\u201332:27.","journal-title":"ACM Trans. Des. Autom. Electr. Syst."},{"key":"e_1_3_1_28_2","first-page":"1","volume-title":"75th IEEE Vehicular Technology Conference (VTC Spring\u201912)","author":"Matsumoto Tsutomu","year":"2012","unstructured":"Tsutomu Matsumoto, Masato Hata, Masato Tanabe, Katsunari Yoshioka, and Kazuomi Oishi. 2012. A method of preventing unauthorized data transmission in controller area network. In 75th IEEE Vehicular Technology Conference (VTC Spring\u201912). IEEE, 1\u20135."},{"key":"e_1_3_1_29_2","volume-title":"10th USENIX Workshop on Offensive Technologies (WOOT\u201916)","author":"Mazloom Sahar","year":"2016","unstructured":"Sahar Mazloom, Mohammad Rezaeirad, Aaron Hunter, and Damon McCoy. 2016. A security analysis of an in-vehicle infotainment and app platform. In 10th USENIX Workshop on Offensive Technologies (WOOT\u201916), Natalie Silvanovich and Patrick Traynor (Eds.). USENIX Association."},{"unstructured":"Charlie Miller. 2015. Remote exploitation of an unaltered passenger vehicle. Black Hat USA (2015).","key":"e_1_3_1_30_2"},{"key":"e_1_3_1_31_2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"185","DOI":"10.1007\/978-3-319-60876-1_9","volume-title":"14th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201917)","volume":"10327","author":"Palanca Andrea","year":"2017","unstructured":"Andrea Palanca, Eric Evenchick, Federico Maggi, and Stefano Zanero. 2017. A stealth, selective, link-layer denial-of-service attack against automotive networks. In 14th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA\u201917)(Lecture Notes in Computer Science, Vol. 10327), Michalis Polychronakis and Michael Meier (Eds.). Springer, 185\u2013206."},{"issue":"800","key":"e_1_3_1_32_2","article-title":"Guide to intrusion detection and prevention systems (IDPS) recommendations","author":"Scarfone Karen","year":"2007","unstructured":"Karen Scarfone and Peter Mell. 2007. Guide to intrusion detection and prevention systems (IDPS) recommendations. Recomm. Nat\u2019l Instit. Stand. Technol.800, 94 (2007), 1\u2013127.","journal-title":"Recomm. Nat\u2019l Instit. Stand. Technol."},{"key":"e_1_3_1_33_2","first-page":"4241","volume-title":"30th USENIX Security Symposium (USENIX Security\u201921)","author":"Serag Khaled","year":"2021","unstructured":"Khaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik, and Dongyan Xu. 2021. Exposing new vulnerabilities of error handling mechanism in CAN. In 30th USENIX Security Symposium (USENIX Security\u201921), Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 4241\u20134258."},{"key":"e_1_3_1_34_2","volume-title":"22nd Annual Network and Distributed System Security Symposium (NDSS\u201915)","author":"Shoshitaishvili Yan","year":"2015","unstructured":"Yan Shoshitaishvili, Ruoyu Wang, Christophe Hauser, Christopher Kruegel, and Giovanni Vigna. 2015. Firmalice\u2014Automatic detection of authentication bypass vulnerabilities in binary firmware. In 22nd Annual Network and Distributed System Security Symposium (NDSS\u201915). The Internet Society."},{"key":"e_1_3_1_35_2","first-page":"1","volume-title":"Smart Card Research and Advanced Applications","author":"Shwartz Omer","year":"2018","unstructured":"Omer Shwartz, Yael Mathov, Michael Bohadana, Yuval Elovici, and Yossi Oren. 2018. Opening Pandora\u2019s box: Effective techniques for reverse engineering IoT devices. In Smart Card Research and Advanced Applications, Thomas Eisenbarth and Yannick Teglia (Eds.). Springer International Publishing, Cham, 1\u201321."},{"issue":"921603","key":"e_1_3_1_36_2","doi-asserted-by":"crossref","DOI":"10.4271\/921603","article-title":"CAN specification 2.0: Protocol and implementations","author":"Szydlowski C.","year":"1992","unstructured":"C. Szydlowski. 1992. CAN specification 2.0: Protocol and implementations. SAE Tech. Pap.921603 (1992).","journal-title":"SAE Tech. Pap."},{"key":"e_1_3_1_37_2","doi-asserted-by":"crossref","first-page":"305","DOI":"10.1007\/978-3-319-99073-6_15","volume-title":"Computer Security","author":"Herrewegen Jan Van den","year":"2018","unstructured":"Jan Van den Herrewegen and Flavio D. Garcia. 2018. Beneath the bonnet: A breakdown of diagnostic security. In Computer Security, Javier Lopez, Jianying Zhou, and Miguel Soriano (Eds.). Springer International Publishing, Cham, 305\u2013324."},{"key":"e_1_3_1_38_2","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1007\/978-3-030-15462-2_12","volume-title":"Smart Card Research and Advanced Applications","author":"Vasile Sebastian","year":"2019","unstructured":"Sebastian Vasile, David Oswald, and Tom Chothia. 2019. Breaking all the things\u2014A systematic survey of firmware extraction techniques for IoT devices. In Smart Card Research and Advanced Applications, Beg\u00fcl Bilgin and Jean-Bernard Fischer (Eds.). Springer International Publishing, Cham, 171\u2013185."},{"key":"e_1_3_1_39_2","first-page":"167","volume-title":"ACM SIGSAC Conference on Computer and Communications Security (CCS\u201920)","author":"Wen Haohuang","year":"2020","unstructured":"Haohuang Wen, Zhiqiang Lin, and Yinqian Zhang. 2020. FirmXRay: Detecting Bluetooth link layer vulnerabilities from bare-metal firmware. In ACM SIGSAC Conference on Computer and Communications Security (CCS\u201920), Jay Ligatti, Xinming Ou, Jonathan Katz, and Giovanni Vigna (Eds.). ACM, 167\u2013180."},{"unstructured":"IEEE P1722 working group. 2016. IEEE Standard for a Transport Protocol for Timesensitive Applications in Bridged Local Area Networks IEEESTD.2016.7782716.","key":"e_1_3_1_40_2"},{"key":"e_1_3_1_41_2","first-page":"1099","volume-title":"28th USENIX Security Symposium (USENIX Security\u201919)","author":"Zheng Yaowen","year":"2019","unstructured":"Yaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song, Hongsong Zhu, and Limin Sun. 2019. FIRM-AFL: High-throughput greybox fuzzing of IoT firmware via augmented process emulation. In 28th USENIX Security Symposium (USENIX Security\u201919), Nadia Heninger and Patrick Traynor (Eds.). USENIX Association, 1099\u20131114."},{"key":"e_1_3_1_42_2","first-page":"1133","volume-title":"28th USENIX Security Symposium (USENIX Security\u201919)","author":"Zhou Wei","year":"2019","unstructured":"Wei Zhou, Yan Jia, Yao Yao, Lipeng Zhu, Le Guan, Yuhang Mao, Peng Liu, and Yuqing Zhang. 2019. Discovering and understanding the security hazards in the interactions between IoT devices, mobile apps, and clouds on smart home platforms. In 28th USENIX Security Symposium (USENIX Security\u201919). 1133\u20131150."},{"key":"e_1_3_1_43_2","first-page":"8899193:1\u201388991","article-title":"Determining the image base of smart device firmware for security analysis","volume":"2020","author":"Zhu Ruijin","year":"2020","unstructured":"Ruijin Zhu, Baofeng Zhang, Yu-an Tan, Jinmiao Wang, and Yueliang Wan. 2020. Determining the image base of smart device firmware for security analysis. Wirel. Commun. Mob. Comput. 2020 (2020), 8899193:1\u20138899193:12.","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"e_1_3_1_44_2","article-title":"Determining the base address of MIPS firmware based on absolute address statistics and string reference matching","volume":"88","author":"Zhu Xiaodong","year":"2020","unstructured":"Xiaodong Zhu, Yi Zhang, Liehui Jiang, and Rui Chang. 2020. Determining the base address of MIPS firmware based on absolute address statistics and string reference matching. Comput. Secur. 88 (2020).","journal-title":"Comput. Secur."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3711832","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,12]],"date-time":"2025-09-12T11:44:23Z","timestamp":1757677463000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711832"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,12]]},"references-count":43,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9,30]]}},"alternative-id":["10.1145\/3711832"],"URL":"https:\/\/doi.org\/10.1145\/3711832","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"type":"print","value":"1539-9087"},{"type":"electronic","value":"1558-3465"}],"subject":[],"published":{"date-parts":[[2025,9,12]]},"assertion":[{"value":"2023-12-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-16","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}