{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T05:26:09Z","timestamp":1773984369090,"version":"3.50.1"},"reference-count":19,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2023,5,18]],"date-time":"2023-05-18T00:00:00Z","timestamp":1684368000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Henan Science and Technology Major Project","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"Henan Science and Technology Major Project","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"Henan Science and Technology Major Project","award":["21511102500"],"award-info":[{"award-number":["21511102500"]}]},{"name":"Henan Science and Technology Major Project","award":["62002213"],"award-info":[{"award-number":["62002213"]}]},{"name":"Henan Science and Technology Major Project","award":["21YF1413800"],"award-info":[{"award-number":["21YF1413800"]}]},{"name":"Henan Science and Technology Major Project","award":["20YF1413700"],"award-info":[{"award-number":["20YF1413700"]}]},{"name":"Shanghai Automotive Industry Science and Technology Development Foundation, SongShan Labtory Pre-Research Project","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"Shanghai Automotive Industry Science and Technology Development Foundation, SongShan Labtory Pre-Research Project","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"Shanghai Automotive Industry Science and Technology Development Foundation, SongShan Labtory Pre-Research Project","award":["21511102500"],"award-info":[{"award-number":["21511102500"]}]},{"name":"Shanghai Automotive Industry Science and Technology Development Foundation, SongShan Labtory Pre-Research Project","award":["62002213"],"award-info":[{"award-number":["62002213"]}]},{"name":"Shanghai Automotive Industry Science and Technology Development Foundation, SongShan Labtory Pre-Research Project","award":["21YF1413800"],"award-info":[{"award-number":["21YF1413800"]}]},{"name":"Shanghai Automotive Industry Science and Technology Development Foundation, SongShan Labtory Pre-Research Project","award":["20YF1413700"],"award-info":[{"award-number":["20YF1413700"]}]},{"name":"Shanghai Science and Technology Innovation Action Plan","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"Shanghai Science and Technology Innovation Action Plan","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"Shanghai Science and Technology Innovation Action Plan","award":["21511102500"],"award-info":[{"award-number":["21511102500"]}]},{"name":"Shanghai Science and Technology Innovation Action Plan","award":["62002213"],"award-info":[{"award-number":["62002213"]}]},{"name":"Shanghai Science and Technology Innovation Action Plan","award":["21YF1413800"],"award-info":[{"award-number":["21YF1413800"]}]},{"name":"Shanghai Science and Technology Innovation Action Plan","award":["20YF1413700"],"award-info":[{"award-number":["20YF1413700"]}]},{"name":"National Science Foundation of China","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"National Science Foundation of China","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"National Science Foundation of China","award":["21511102500"],"award-info":[{"award-number":["21511102500"]}]},{"name":"National Science Foundation of China","award":["62002213"],"award-info":[{"award-number":["62002213"]}]},{"name":"National Science Foundation of China","award":["21YF1413800"],"award-info":[{"award-number":["21YF1413800"]}]},{"name":"National Science Foundation of China","award":["20YF1413700"],"award-info":[{"award-number":["20YF1413700"]}]},{"name":"Shanghai Sailing Program","award":["221100240100"],"award-info":[{"award-number":["221100240100"]}]},{"name":"Shanghai Sailing Program","award":["YYJC042022016"],"award-info":[{"award-number":["YYJC042022016"]}]},{"name":"Shanghai Sailing Program","award":["21511102500"],"award-info":[{"award-number":["21511102500"]}]},{"name":"Shanghai Sailing Program","award":["62002213"],"award-info":[{"award-number":["62002213"]}]},{"name":"Shanghai Sailing Program","award":["21YF1413800"],"award-info":[{"award-number":["21YF1413800"]}]},{"name":"Shanghai Sailing Program","award":["20YF1413700"],"award-info":[{"award-number":["20YF1413700"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Advanced Driver Assistance Systems (ADASs) are crucial components of intelligent vehicles, equipped with a vast code base. To enhance the security of ADASs, it is essential to mine their vulnerabilities and corresponding exploitation methods. However, mining buffer overflow (BOF) vulnerabilities in ADASs can be challenging since their code and data are not publicly available. In this study, we observed that ADAS devices commonly utilize unencrypted protocols for module communication, providing us with an opportunity to locate input stream and buffer data operations more efficiently. Based on the above observation, we proposed a communication-traffic-assisted ADAS BOF vulnerability mining and exploitation method. Our method includes firmware extraction, a firmware and system analysis, the locating of risk points with communication traffic, validation, and exploitation. To demonstrate the effectiveness of our proposed method, we applied our method to several commercial ADAS devices and successfully mined BOF vulnerabilities. By exploiting these vulnerabilities, we executed the corresponding commands and mapped the attack to the physical world, showing the severity of these vulnerabilities.<\/jats:p>","DOI":"10.3390\/fi15050185","type":"journal-article","created":{"date-parts":[[2023,5,19]],"date-time":"2023-05-19T00:55:29Z","timestamp":1684457729000},"page":"185","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Communication-Traffic-Assisted Mining and Exploitation of Buffer Overflow Vulnerabilities in ADASs"],"prefix":"10.3390","volume":"15","author":[{"given":"Yufeng","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"},{"name":"Purple Mountain Laboratories, Nanjing 211100, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mengxiao","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chenhong","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"},{"name":"Purple Mountain Laboratories, Nanjing 211100, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9754-0008","authenticated-orcid":false,"given":"Jiangtao","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Engineering and Science, Shanghai University, Shanghai 200444, China"},{"name":"Purple Mountain Laboratories, Nanjing 211100, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,5,18]]},"reference":[{"key":"ref_1","unstructured":"Ben, N., Yisroel, M., Dudi, N., Raz, B.-N., Oleg, D., and Yuval, E. (2020, January 9\u201313). Phantom of the adas: Securing advanced driver-assistance systems from split-second phantom attacks. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Online."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Cao, C.Y., Xiao, X.C., and Cyr, C.B. (2019, January 11\u201315). Adversarial sensor attack on lidar-based perception in autonomous driving. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3339815"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Wan, Z., Shen, J., Chuang, J., Xia, X., Garcia, J., Ma, J., and Chen, Q.A. (2022). Too afraid to drive: Systematic discovery of semantic DoS vulnerability in autonomous driving planning under physical-world attacks. arXiv.","DOI":"10.14722\/autosec.2022.23046"},{"key":"ref_4","unstructured":"(2023, March 31). Tencent Keen Lab: Mercedes-Benz Automotive Information Security Research Overview Report. Available online: https:\/\/keenlab.tencent.com\/zh\/2021\/05\/12\/Tencent-Security-Keen-Lab-Experimental-Security-Assessment-on-Mercedes-Benz-Cars\/."},{"key":"ref_5","unstructured":"Weinmann, R.-P., and Schmotzle, B. (2023, March 31). TBONE\u2013A Zero-Click Exploit for Tesla MCUs. White Paper, ComSecuris. Available online: https:\/\/www.google.com.hk\/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwipr_OJoID_AhXPgVYBHYnEDzcQFnoECBUQAQ&url=https%3A%2F%2Fkunnamon.io%2Ftbone%2Ftbone-v1.0-redacted.pdf&usg=AOvVaw3D8rptrw4h1YJ0z7xKOtxI."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1049\/iet-sen.2014.0185","article-title":"Auditing buffer overflow vulnerabilities using hybrid static\u2013dynamic analysis","volume":"10","author":"Padmanabhuni","year":"2016","journal-title":"IET Softw."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1155\/2019\/8391425","article-title":"A Buffer Overflow Prediction Approach Based on Software Metrics and Machine Learning","volume":"2019","author":"Ren","year":"2019","journal-title":"Secur. Commun. Netw."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"443","DOI":"10.1109\/TC.2006.59","article-title":"Security protection and checking for embedded system integration against buffer overflow attacks via hardware\/software","volume":"55","author":"Shao","year":"2006","journal-title":"IEEE Trans. Comput."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Mullen, G., and Meany, L. (2019). Assessment of buffer overflow based attacks on an IoT operating system. IEEE Glob. Iot Summit, 1\u20136.","DOI":"10.1109\/GIOTS.2019.8766434"},{"key":"ref_10","unstructured":"(2023, April 01). CVE-2018-18708: Analysis of the Tenda Router Buffer Overflow Vulnerability. Available online: https:\/\/www.anquanke.com\/post\/id\/204403."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1109\/MITP.2016.117","article-title":"Defeating buffer overflow: A trivial but dangerous bug","volume":"18","author":"Black","year":"2016","journal-title":"IT Prof."},{"key":"ref_12","unstructured":"(2023, March 31). Driving Down the Rabbit Hole. Available online: https:\/\/defcon.org\/html\/defcon-25\/dc-25-speakers.html#Shkatov."},{"key":"ref_13","first-page":"812","article-title":"Buffer overflow vulnerability analysis and prevention strategies","volume":"5","author":"Chi","year":"2019","journal-title":"Inf. Secur. Res."},{"key":"ref_14","first-page":"3758","article-title":"A buffer stack overflow algorithm against address flooding","volume":"34","author":"Tang","year":"2017","journal-title":"Comput. Appl. Res."},{"key":"ref_15","first-page":"63","article-title":"Stackguard: Automatic adaptive detection and prevention of buffer-overflow attacks","volume":"98","author":"Cowan","year":"1998","journal-title":"USENIX Secur. Symp."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"326","DOI":"10.1109\/TIV.2021.3122898","article-title":"A Progressive Review: Emerging Technologies for ADAS Driven Solutions","volume":"7","author":"Nidamanuri","year":"2021","journal-title":"IEEE Trans. Intell. Veh."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2133375.2133377","article-title":"Return-oriented programming: Systems, languages, and applications","volume":"15","author":"Roemer","year":"2012","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Lin, C.-W., and Sangiovanni-Vincentelli, A. (2012, January 14\u201316). Cyber-security for the controller area network (CAN) communication protocol. Proceedings of the 2012 International Conference on Cyber Security, IEEE, Alexandria, VA, USA.","DOI":"10.1109\/CyberSecurity.2012.7"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1109\/MWC.2019.1800289","article-title":"TSP security in intelligent and connected vehicles: Challenges and solutions","volume":"26","author":"Li","year":"2019","journal-title":"IEEE Wirel. Commun."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/15\/5\/185\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:38:06Z","timestamp":1760125086000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/15\/5\/185"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,18]]},"references-count":19,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2023,5]]}},"alternative-id":["fi15050185"],"URL":"https:\/\/doi.org\/10.3390\/fi15050185","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,18]]}}}