Information Security Management - Guidelines for Cyber Insurance Date: 16-Apr (Tue)Time: 7:00pm...
Build a Secure Cyberspace 2019"Phishing scams? No more!" Seminar Date: 2019-05-03Time: 14:30 –...
DevSecOps - Web Application Firewall in a CI/CD Workflow Date: 10 April 2019 (Wed)Time:...
Time: 2:00 pm to 4:30 pm
Date: 14 Jan, 2017 (Sat)
Venue: Room Z414, Block Z, The Hong Kong Polytechnics University
We discover severe vulnerabilities in popular telematics systems, through which attackers can remotely replace their firmware with the malicious one and then launch attacks on the vehicles. We have confirmed these vulnerabilities through POC attacks on real vehicles. Moreover, we propose several approaches for fixing these vulnerabilities. We have informed the corresponding companies about the vulnerabilities and the fixing approaches with the help of HKCERT. In this talk, we first introduce the background knowledge of telematics and its attack surface. Then, we detail how to identify and exploit the vulnerability in two telematics systems. Moreover, we discuss how to fix this vulnerability.
Lei Xue is a PhD student in the Department of Computing, the Hong Kong Polytechnic University, working with Dr. Daniel Xiapu Luo. He has been working on network and system security for many yearsand published several papers in top venues (e.g., ICSE, INFOCOM, etc.). His current research interests include network and mobile security.
One CPE can be claimed for the (ISC2) Credential Holder.