news
Study Uncovers Security Weaknesses in Next-Generation Vehicle Technology
Primary tabs
Georgia Tech researchers have identified seven previously unknown security flaws in next-generation communication standards that connect in-vehicle computers. These flaws create vulnerabilities that could allow attackers to take control of key driver-assistance functions in personal vehicles.
The team also found that the new standard's core rules for sending messages and handling errors retain every known security weakness of older versions.
The vulnerabilities could allow an attacker who has already gained access to a vehicle's internal computer network to change or intercept messages, take individual vehicle computers offline, send different information to different systems, or disrupt network communication.
CAN Extra Long (CAN XL), the latest version of the controller area network (CAN), is designed for future cars and other vehicles that need to move large amounts of data between onboard computers. The technology is not yet widely deployed in production vehicles, giving manufacturers an opportunity to address security concerns before it becomes more common.
“Because it isn't widely deployed yet, we have a narrow window to get its security right,” said Associate Professor Saman Zonouz of the School of Cybersecurity and Privacy and the School of Electrical and Computer Engineering, one of the researchers on the project.
“Fixing a standard now is far easier than fixing it once it's built into the hardware of millions of cars that stay on the road for a decade or more.”
Zonouz said CAN XL is expected to become the primary version of CAN, the network that enables computers inside a vehicle to communicate. It is also expected to serve as the main network for driver-assistance systems in future vehicles.
The researchers confirmed the seven vulnerabilities in commercial CAN XL hardware and demonstrated attacks using a physical test setup that mimics a vehicle network.
Modern vehicles can have dozens of electronic control units that manage systems such as sensors, brakes, steering, and entertainment. These computers need to communicate quickly and reliably.
For decades, many vehicles have used CAN for this communication. However, the original version, known as classic CAN, was not designed to handle the volume of data generated by newer vehicle technologies.
CAN XL was developed to provide faster communication, larger messages, and new security features, but the researchers wanted to know whether the new standard’s basic rules were secure. Their testing revealed that they weren’t. They discovered that an attacker who controls one computer on the network could intercept and replace messages or take a targeted computer offline.
“These flaws are in the standard itself, so every device built to follow it inherits them,” Zonouz said. “With CAN XL, there's still time to fix these problems before they reach the road.”
The attacks would require an attacker to first gain control of a computer connected to the vehicle's internal network. The research does not show that CAN XL itself provides a means to break into a vehicle. Instead, it shows what an attacker could do after gaining access.
Several attacks were also faster and harder to detect than similar attacks against classic CAN, according to the authors.
The researchers proposed changes to the CAN XL rules to prevent several of the attacks. They also recommended additional security measures, including message authentication and systems that can detect unusual activity.
The team reported the vulnerabilities and informed the manufacturers of the commercial devices it tested about the bugs it found. One company has already released a fix. The researchers hope their findings will help manufacturers address security weaknesses before the technology becomes more widely used.
A Formal Security Analysis of CAN XL was published in the Proceedings of the 35th USENIX Security Symposium, held Aug. 12-14 in Baltimore, MD. The paper was also named a runner-up for a distinguished paper award.
The study was conducted by Georgia Tech Ph.D. student ZhaozhouTang, Professor Vijay Ganesh, Zonouz, and Provost and Executive Vice President for Academic Affairs Raheem Beyah, along with Khaled Serag of the Qatar Computing Research Institute and Z. Berkay Celik of Purdue University.
The paper and its findings result from projects sponsored by the Hyundai America Technical Center, the Georgia Department of Transportation, and the $7 million CHORUS Center through the National Science Foundation’s Cyber-Physical System Frontier Program.
Groups
Status
- Workflow status: Published
- Created by: John Popham
- Created: 09/24/2026
- Modified By: John Popham
- Modified: 09/24/2026
Keywords
User Data