{"692805":{"#nid":"692805","#data":{"type":"news","title":"Study Uncovers Security Weaknesses in Next-Generation Vehicle Technology","body":[{"value":"\u003Cp\u003EGeorgia Tech researchers have identified seven previously unknown security flaws in next-generation communication standards that connect in-vehicle computers. These flaws create vulnerabilities that could allow attackers to take control of key driver-assistance functions in personal vehicles.\u003C\/p\u003E\u003Cp\u003EThe team also found that the new standard\u0027s core rules for sending messages and handling errors retain every known security weakness of older versions.\u003C\/p\u003E\u003Cp\u003EThe vulnerabilities could allow an attacker who has already gained access to a vehicle\u0027s internal computer network to change or intercept messages, take individual vehicle computers offline, send different information to different systems, or disrupt network communication.\u003C\/p\u003E\u003Cp\u003ECAN Extra Long (CAN XL), the latest version of the controller area network (CAN), is designed for future cars and other vehicles that need to move large amounts of data between onboard computers. The technology is not yet widely deployed in production vehicles, giving manufacturers an opportunity to address security concerns before it becomes more common.\u003C\/p\u003E\u003Cp\u003E\u201cBecause it isn\u0027t widely deployed yet, we have a narrow window to get its security right,\u201d said Associate Professor \u003Cstrong\u003ESaman\u003C\/strong\u003E \u003Cstrong\u003EZonouz\u003C\/strong\u003E of the \u003Ca href=\u0022https:\/\/scp.cc.gatech.edu\/\u0022\u003ESchool of Cybersecurity and Privacy\u003C\/a\u003E and the \u003Ca href=\u0022https:\/\/ece.gatech.edu\/\u0022\u003ESchool of Electrical and Computer Engineering\u003C\/a\u003E, one of the researchers on the project.\u0026nbsp;\u003C\/p\u003E\u003Cp\u003E\u201cFixing a standard now is far easier than fixing it once it\u0027s built into the hardware of millions of cars that stay on the road for a decade or more.\u201d\u003C\/p\u003E\u003Cp\u003EZonouz said CAN XL is expected to become the primary version of CAN, the network that enables computers inside a vehicle to communicate. It is also expected to serve as the main network for driver-assistance systems in future vehicles.\u003C\/p\u003E\u003Cp\u003EThe researchers confirmed the seven vulnerabilities in commercial CAN XL hardware and demonstrated attacks using a physical test setup that mimics a vehicle network.\u003C\/p\u003E\u003Cp\u003EModern vehicles can have dozens of electronic control units that manage systems such as sensors, brakes, steering, and entertainment. These computers need to communicate quickly and reliably.\u003C\/p\u003E\u003Cp\u003EFor decades, many vehicles have used CAN for this communication. However, the original version, known as classic CAN, was not designed to handle the volume of data generated by newer vehicle technologies.\u003C\/p\u003E\u003Cp\u003ECAN XL was developed to provide faster communication, larger messages, and new security features, but the researchers wanted to know whether the new standard\u2019s basic rules were secure. Their testing revealed that they weren\u2019t. They discovered that an attacker who controls one computer on the network could intercept and replace messages or take a targeted computer offline.\u003C\/p\u003E\u003Cp\u003E\u201cThese flaws are in the standard itself, so every device built to follow it inherits them,\u201d Zonouz said. \u201cWith CAN XL, there\u0027s still time to fix these problems before they reach the road.\u201d\u003C\/p\u003E\u003Cp\u003EThe attacks would require an attacker to first gain control of a computer connected to the vehicle\u0027s internal network. The research does not show that CAN XL itself provides a means to break into a vehicle. Instead, it shows what an attacker could do after gaining access.\u003C\/p\u003E\u003Cp\u003ESeveral attacks were also faster and harder to detect than similar attacks against classic CAN, according to the authors.\u003C\/p\u003E\u003Cp\u003EThe researchers proposed changes to the CAN XL rules to prevent several of the attacks. They also recommended additional security measures, including message authentication and systems that can detect unusual activity.\u003C\/p\u003E\u003Cp\u003EThe team reported the vulnerabilities and informed the manufacturers of the commercial devices it tested about the bugs it found. One company has already released a fix. The researchers hope their findings will help manufacturers address security weaknesses before the technology becomes more widely used.\u003C\/p\u003E\u003Cp\u003E\u003Ca href=\u0022https:\/\/www.usenix.org\/conference\/usenixsecurity26\/presentation\/tang-zhaozhou\u0022\u003E\u003Cem\u003EA Formal Security Analysis of CAN XL\u003C\/em\u003E\u003C\/a\u003E was published in the Proceedings of the \u003Ca href=\u0022https:\/\/www.usenix.org\/conference\/usenixsecurity26\u0022\u003E35th USENIX Security Symposium\u003C\/a\u003E, held Aug. 12-14 in Baltimore, MD. The paper was also named a runner-up for a distinguished paper award.\u003C\/p\u003E\u003Cp\u003EThe study was conducted by Georgia Tech Ph.D. student \u003Cstrong\u003EZhaozhouTang\u003C\/strong\u003E, Professor \u003Cstrong\u003EVijay\u003C\/strong\u003E \u003Cstrong\u003EGanesh\u003C\/strong\u003E, Zonouz, and Provost and Executive Vice President for Academic Affairs \u003Cstrong\u003ERaheem\u003C\/strong\u003E \u003Cstrong\u003EBeyah\u003C\/strong\u003E, along with \u003Cstrong\u003EKhaled\u003C\/strong\u003E \u003Cstrong\u003ESerag\u003C\/strong\u003E of the Qatar Computing Research Institute and Z. Berkay Celik of Purdue University.\u003C\/p\u003E\u003Cp\u003EThe paper and its findings result from projects sponsored by the Hyundai America Technical Center, the Georgia Department of Transportation, and the $7 million CHORUS Center through the National Science Foundation\u2019s Cyber-Physical System Frontier Program.\u003C\/p\u003E","summary":"","format":"limited_html"}],"field_subtitle":"","field_summary":[{"value":"\u003Cp\u003EGeorgia Tech researchers found seven security flaws in CAN XL, a vehicle network standard intended for future driver-assistance systems. The findings show risks remain before the technology becomes widely deployed. \u2022 Attackers with access to a vehicle\u2019s internal network could alter or intercept messages, disable computers, provide conflicting information, or disrupt communication; some attacks were faster and harder to detect than those targeting classic CAN. \u2022 Researchers confirmed the flaws on commercial hardware, proposed rule changes, and recommended message authentication and unusual-activity detection; one tested manufacturer has released a fix.\u003C\/p\u003E","format":"limited_html"}],"field_summary_sentence":[{"value":"Georgia Tech researchers found seven security flaws in CAN XL, a vehicle network standard intended for future driver-assistance systems."}],"uid":"36253","created_gmt":"2026-09-24 14:34:10","changed_gmt":"2026-09-24 14:36:29","author":"John Popham","boilerplate_text":"","field_publication":"","field_article_url":"","location":"Atlanta, GA","dateline":{"date":"2026-09-24T00:00:00-04:00","iso_date":"2026-09-24T00:00:00-04:00","tz":"America\/New_York"},"extras":[],"hg_media":{"681243":{"id":"681243","type":"image","title":"Car-security.png","body":null,"created":"1790260526","gmt_created":"2026-09-24 14:35:26","changed":"1790260526","gmt_changed":"2026-09-24 14:35:26","alt":"A digital image of a car with a lock on it","file":{"fid":"265612","name":"Car-security.png","image_path":"\/sites\/default\/files\/2026\/09\/24\/Car-security.png","image_full_path":"http:\/\/hg.gatech.edu\/\/sites\/default\/files\/2026\/09\/24\/Car-security.png","mime":"image\/png","size":758850,"path_740":"http:\/\/hg.gatech.edu\/sites\/default\/files\/styles\/740xx_scale\/public\/2026\/09\/24\/Car-security.png?itok=q0gzPjyJ"}},"675758":{"id":"675758","type":"image","title":"Saman Zonouz.jpg","body":null,"created":"1733171394","gmt_created":"2024-12-02 20:29:54","changed":"1733171394","gmt_changed":"2024-12-02 20:29:54","alt":"man in a pullover smiling","file":{"fid":"259421","name":"Saman Zonouz.jpg","image_path":"\/sites\/default\/files\/2024\/12\/02\/Saman%20Zonouz.jpg","image_full_path":"http:\/\/hg.gatech.edu\/\/sites\/default\/files\/2024\/12\/02\/Saman%20Zonouz.jpg","mime":"image\/jpeg","size":20769150,"path_740":"http:\/\/hg.gatech.edu\/sites\/default\/files\/styles\/740xx_scale\/public\/2024\/12\/02\/Saman%20Zonouz.jpg?itok=L0vEl8C_"}}},"media_ids":["681243","675758"],"groups":[{"id":"47223","name":"College of Computing"},{"id":"1188","name":"Research Horizons"},{"id":"660406","name":"School of Cybersecurity \u0026 Privacy"},{"id":"660367","name":"School of Cybersecurity and Privacy"}],"categories":[{"id":"153","name":"Computer Science\/Information Technology and Security"},{"id":"145","name":"Engineering"},{"id":"135","name":"Research"}],"keywords":[],"core_research_areas":[{"id":"145171","name":"Cybersecurity"}],"news_room_topics":[],"event_categories":[],"invited_audience":[],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[{"value":"\u003Cp\u003EJohn Popham\u003C\/p\u003E\u003Cp\u003ECommunications Officer for the School of Cybersecurity and Privacy\u003C\/p\u003E","format":"limited_html"}],"email":["jpopham3@gatech.edu"],"slides":[],"orientation":[],"userdata":""}}}