VULNERABILITY ASSESSMENT OF AUTOMOTIVE INFOTAINMENT SYSTEMS SECURITY

Student: Wareez Abidemi Busari
Supervisor: Prof John Kolo Alhassan
HOD: Prof Ismaila Idris
Department of Cyber Security Science
Information Comunication Technology
Federal University of Technology, Minna, Niger State

Abstract

The increasing integration of in-vehicle infotainment (IVI) systems in modern automobiles has introduced significant cybersecurity challenges. The aim of this study is to analyse security vulnerabilities in automotive infotainment systems, particularly Controller Area Network (CAN) bus and Wi-Fi communication protocols, and propose effective countermeasures to mitigate the associated risks that threatens vehicle safety and passenger security. Experimental design was adopted to simulate an automotive infotainment system using Automotive Grade Linux (AGL) and employed tools like Parrot OS, VMware Workstation, Wireshark and various CAN utilities to assess vulnerabilities in CAN bus and Wi-Fi protocols. The data analysis carried out employed quantitative and statistical methods to assess the severity and correlation of identified vulnerabilities, revealing a positive correlation between system complexity and the number of exploitable security weaknesses where system complexity of; low, medium and high complexities are having vulnerability count of; 2, 4 and 6 with severity breakdown of; (high:2, critical:0), (high:2, critical:2) and (high:2, critical:4) respectively. Results indicate that automotive infotainment systems are highly vulnerable to attacks like CAN bus message injection, eavesdropping, denial-of-service, and replay attacks, as well as Wi-Fi traffic capture and unauthorized access through open ports. The proposed countermeasures include encryption of CAN bus communications, implementation of message authentication protocols, and enhanced Wi-Fi security configurations.

Full-Text Access Notice

In accordance with the NERD Policy on promoting peer-reviewed publication, public access to the full text of a project, thesis or dissertation is restricted for three years, allowing the author and supervisors sufficient time to pursue peer-reviewed publication. During this period, researchers with legitimate academic or research purposes may request authorisation directly from the author to enable NERD to release the indexed full texts of the work using the form below.

Request authorisation from the author