Certified Information Systems Security Professional (CISSP®) certification Date: 25-29 June,...
GDPR Hands-on workshop 2018 Date: 26th June, 2018 (Tue)Time: 9:00am - 6:00PM (Whole day workshop...
1. CISSP Online Instructor-Led Training30 Apr - 27 Jun 2018 (19:00-21:30 | GMT+8)Training Only:...
Time: 2:00 pm to 4:30 pm
Date: 14 Jan, 2017 (Sat)
Venue: Room Z414, Block Z, The Hong Kong Polytechnics University
We discover severe vulnerabilities in popular telematics systems, through which attackers can remotely replace their firmware with the malicious one and then launch attacks on the vehicles. We have confirmed these vulnerabilities through POC attacks on real vehicles. Moreover, we propose several approaches for fixing these vulnerabilities. We have informed the corresponding companies about the vulnerabilities and the fixing approaches with the help of HKCERT. In this talk, we first introduce the background knowledge of telematics and its attack surface. Then, we detail how to identify and exploit the vulnerability in two telematics systems. Moreover, we discuss how to fix this vulnerability.
Lei Xue is a PhD student in the Department of Computing, the Hong Kong Polytechnic University, working with Dr. Daniel Xiapu Luo. He has been working on network and system security for many yearsand published several papers in top venues (e.g., ICSE, INFOCOM, etc.). His current research interests include network and mobile security.
One CPE can be claimed for the (ISC2) Credential Holder.