Free Republic
Browse · Search
Smoky Backroom
Topics · Post Article

Skip to comments.

Truck-to-truck worm could infect – and disrupt – entire US commercial fleet
the register ^

Posted on 03/21/2024 5:31:42 PM PDT by algore

Vulnerabilities in common Electronic Logging Devices (ELDs) required in US commercial trucks could be present in over 14 million medium- and heavy-duty rigs, according to boffins at Colorado State University.

In a paper presented at the 2024 Network and Distributed System Security Symposium, associate professor Jeremy Daily and systems engineering graduate students Jake Jepson and Rik Chatterjee demonstrated how ELDs can be accessed over Bluetooth or Wi-Fi connections to take control of a truck, manipulate data, and spread malware between vehicles.

"These findings highlight an urgent need to improve the security posture in ELD systems," the trio wrote [PDF].

The authors did not specify brands or models of ELDs that are vulnerable to the security flaws they highlight in the paper. But they do note there's not too much diversity of products on the market. While there are some 880 devices registered, "only a few tens of distinct ELD models" have hit the road in commercial trucks.

A federal mandate requires most heavy-duty trucks to be equipped with ELDs, which track driving hours. These systems also log data on engine operation, vehicle movement and distances driven – but they aren't required to have tested safety controls built in.

And according to the researchers, they can be wirelessly manipulated by another car on the road to, for example, force a truck to pull over.

The academics pointed out three vulnerabilities in ELDs. They used bench level testing systems for the demo, as well as additional testing on a moving 2014 Kenworth T270 Class 6 research truck equipped with a vulnerable ELD.

"In our evaluation of ELD units procured from various resellers, we discovered that they are distributed with factory default firmware settings that present considerable security risks," the authors noted.

This included an exposed API that permits over-the-air (OTA) updates. The devices also have Wi-Fi and Bluetooth enabled by default, with a "predictable" Bluetooth identifier and Wi-Fi Service Set Identifier (SSID) and weak default password. That makes it easy to connect to the device and then obtain network access to the rest of the vehicle's systems – at least for attackers within wireless range.

This can be achieved via a drive-by attack, or by hanging out at truck stops, rest stops, distribution centers, ports – basically anywhere that heavy-duty trucks tend to congregate.

The ELDs use a Controller Area Network (CAN) bus to communicate. For one of the attacks, the boffins showed how anyone within wireless range could use the device's Wi-Fi and Bluetooth radios to send an arbitrary CAN message that could disrupt of some of the vehicle's systems.

A second attack scenario, which also required the attacker to be within wireless range, involved connecting to the device and uploading malicious firmware to manipulate data and vehicle operations.

Finally, in what the authors described as the "most concerning" scenario, they uploaded a truck-to-truck worm. The worm uses the compromised device's Wi-Fi capabilities to search for other vulnerable ELDs nearby.

Here's how it knows the devices are vulnerable:

It specifically looks for devices with SSIDs starting with "VULNERABLE ELD:". Although this may sound contrived the SSID of the ELD we examined was predictable and could be used to identify the vulnerable devices.


TOPICS: Heated Discussion
KEYWORDS: donate; elds; firmware; truck; trucking; usurped; worm
Firmware writer,

It's the dirty story of a dirty man,

And his clinging wife doesn't understand,

His son is working for the Daily Mail,

It's a steady job but he wants to be a firmware writer,

Firmware writer a Firmware writer

It's a thousand pages, give or take a few,

I'll be writing more in a week or two I can make it longer if you like the style I can change it 'round and I want to be a firmware writer Firmware writer

If you really like it you can have the rights,

It could make a million for you overnight,

If you must return it, you can send it here,

But I need a break and I want to be a firmware writer...

1 posted on 03/21/2024 5:31:42 PM PDT by algore
[ Post Reply | Private Reply | View Replies]

To: algore

Paper logs again?
Yea!!!!


2 posted on 03/21/2024 5:37:12 PM PDT by sausageseller (If you want to cut your own throat, don't come to me for a bandage. M, Thatcher)
[ Post Reply | Private Reply | To 1 | View Replies]

To: algore
Here is one of the little buggers!


3 posted on 03/21/2024 5:39:07 PM PDT by E. Pluribus Unum (The worst thing about censorship is █████ ██ ████ ████s████ █ ███████ ████. FJB.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sausageseller

I’d vote for paper logs again. All of this tech in a somewhat rough environment of a vlass-8 truck is bound to be hackable.


4 posted on 03/21/2024 5:41:30 PM PDT by Spacetrucker (George Washington didn't use his freedom of speech to defeat the British - HE SHOT THEM .. WITH GUNS)
[ Post Reply | Private Reply | To 2 | View Replies]

To: E. Pluribus Unum

Doesn’t look like firmware


5 posted on 03/21/2024 5:45:02 PM PDT by Pollard ( Seed Room Wx: 75 degrees - 23% humidity )
[ Post Reply | Private Reply | To 3 | View Replies]

To: algore

This is a case where overrides and workarounds will come into play as needed.


6 posted on 03/21/2024 5:46:19 PM PDT by Fester Chugabrew (In a world of parrots and lemmings, be a watchdog.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Spacetrucker

I am going to the Mid America Truck Show in Louisville this weekend.
Going to print the article out and see what some of the ELD providers say.


7 posted on 03/21/2024 5:47:00 PM PDT by sausageseller (If you want to cut your own throat, don't come to me for a bandage. M, Thatcher)
[ Post Reply | Private Reply | To 4 | View Replies]

To: algore

There will be pushback from the guys that like to show up at sites that have no onsite parking before claiming they’re out of time and thus have to stay.
All while blocking gates, driveways, various accessways, etc.


8 posted on 03/21/2024 5:48:44 PM PDT by Darksheare (Those who support liberal "Republicans" summarily support every action by same. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

I’m surprised they didn’t blame it on Russia Russia Russia !!! hackers.
(Yet, anyway)


9 posted on 03/21/2024 6:19:34 PM PDT by LegendHasIt
[ Post Reply | Private Reply | To 1 | View Replies]

To: algore

I drive a f-150 with a logo’d trailer on occasion for my job. The trailer is merely a means to get my demonstration supplies to the shows I do.

So of course, DOT says I need a ELD. I despise the stupid thing because most of the time I have no trailer, thus no need to log.

I got a new truck a couple months ago and kinda forgot to connect the ELD because I haven’t had the trailer connected. I almost feel free.


10 posted on 03/21/2024 6:23:33 PM PDT by cyclotic (Don’t be part of the problem. Be the entire problem)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pollard

More like flaccidware.


11 posted on 03/21/2024 6:24:15 PM PDT by moovova ("The NEXT election is the most important election of our lifetimes!“ LOL...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: algore
A federal mandate requires most heavy-duty trucks to be equipped with ELDs, which track driving hours.
If there is really a vulnerability here, it's the fault of big gov.
12 posted on 03/21/2024 6:45:10 PM PDT by citizen (Put all LBQTwhatever programming on a new subscription service: PERV-TThose look good)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pollard

It needs “This one simple trick…”


13 posted on 03/21/2024 7:15:07 PM PDT by Tijeras_Slim
[ Post Reply | Private Reply | To 5 | View Replies]

To: algore

Imagine what kind of malware might be infiltrated into EV systems through charging stations. Also malware might be designed to migrate from traveling vehicles and infect other charger installations.


14 posted on 03/21/2024 8:13:38 PM PDT by Pennsyltucky Boy (bitterly clinging to our constitutional rights in PA)
[ Post Reply | Private Reply | To 1 | View Replies]

To: algore
"...there's not too much diversity of products on the market."

I spotted the problem right there -- not enough DEI in the trucking industry.

15 posted on 03/21/2024 8:23:19 PM PDT by ProtectOurFreedom (“Occupy your mind with good thoughts or your enemy will fill them with bad ones.” ~ Thomas More)
[ Post Reply | Private Reply | To 1 | View Replies]

To: algore

Bluetooth is a common invasion path.


16 posted on 03/21/2024 8:30:11 PM PDT by linMcHlp
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum

Those live in Idaho. Giant Palouse earthworms.


17 posted on 03/21/2024 8:34:06 PM PDT by Disambiguator
[ Post Reply | Private Reply | To 3 | View Replies]

To: sausageseller

When you do, please bring their response back here, I’d really love to hear it.


18 posted on 03/22/2024 12:53:23 AM PDT by Spacetrucker (George Washington didn't use his freedom of speech to defeat the British - HE SHOT THEM .. WITH GUNS)
[ Post Reply | Private Reply | To 7 | View Replies]

To: algore; Liz; LS; SunkenCiv; Red Badger

WHEN (not “if”) China declares war on the US to capture Taiwan, China can even now then stop all overseas shipping from leaving its ports with a single phone call.

And with this malware program, China can stop all shipping inside the US too.

Instant victory.


19 posted on 03/22/2024 3:25:27 AM PDT by Robert A Cook PE (Method, motive, and opportunity: No morals, shear madness and hatred by those who cheat.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sausageseller
Going to print the article out and see what some of the ELD providers say.

I'd be interested in hearing whatever comments they may have. The fact that these systems require NO AUTHENTICATION is insane. Whoever thought this up is obviously working for the government.

20 posted on 03/22/2024 8:02:06 AM PDT by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Smoky Backroom
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson