What this course is about
The definitive 4-day hands-on automotive cybersecurity training. This comprehensive program covers the entire spectrum of vehicle security, from analyzing CAN bus traffic and exploiting diagnostic protocols on days 1 and 2, through firmware reverse engineering and secure boot analysis on Day 3, to RF hacking with Software Defined Radio on Day 4. Work with real ECUs, tackle 30+ CTF challenges, and build practical skills using open-source tools on a Raspberry Pi lab environment. Suitable for both beginners and experienced professionals.
Agenda
Day 1: Vehicle Networks and Tools
Theory
- Modern car network layouts and gateway architectures
- Physical and link layer standards: CAN, CAN FD, LIN, FlexRay, Automotive Ethernet
- Hardware attacks on CAN bus and mitigation strategies
- Real-world CAN traffic with integrity checks, counters and checksums
- SecOC (Secure Onboard Communication) and cryptographic developments
Hands-on
- Analyzing live CAN traffic using Wireshark and Cabana
- Creating DBC files from CAN signals
- Physical layer attacks on CAN bus
- Checksum algorithm reverse engineering
- Message spoofing and replay attacks
Day 2: Diagnostic Protocols and Hardware
Theory
- Diagnostic protocols: OBD-II, KWP2000, UDS (ISO 14229-1)
- Calibration protocols: CCP and XCP
- Microcontroller architectures used in automotive ECUs
- PCB reverse engineering and firmware extraction methods
- Fault injection attacks and countermeasures
Hands-on
- UDS endpoint scanning and service enumeration
- CCP/XCP endpoint communication and data extraction
- Diagnostics over IP (DoIP) exploration
- ECU firmware extraction using debug probes and multiple methods
Day 3: Reverse Engineering
Theory
- Firmware extraction from manufacturer update files
- UDS flashing procedures and update mechanisms
- Fault injection techniques against ECU hardware
- Introduction to Ghidra for automotive firmware analysis
- Common automotive firmware patterns and architectures
- Firmware integrity checks and secure boot mechanisms
Hands-on
- Reverse engineering ECU security access algorithms
- Creating custom seed-key bypass tools
- Loading and analyzing automotive firmware in Ghidra
- Building custom flashing and calibration tools
Day 4: RF Hacking with Software Defined Radio
Theory
- Tire Pressure Monitoring System (TPMS) protocol and communications
- Modern FM radio attack surfaces, RDS, HD Radio, DAB+
- Keyfob protocols and attack techniques (replay, relay, rollback)
- EV-to-charging station powerline communication (ISO 15118)
- Software Defined Radio fundamentals and tooling
Hands-on
- Receiving and decoding TPMS sensor transmissions
- Spoofing TPMS sensor data
- Keyfob signal capture and replay attacks
- Analyzing EV charging communication protocols
