World Congress 2024 • Aug 20, 2024 • Session details

A Hitchhikers Guide to Container Security - Automotive Edition 2024

Reinhard

Can a compromised software container hijack a car's physical hardware? Watch a live instrument cluster hack. Then, discover how eBPF acts as both a defensive shield and stealthy threat.

Pause
Mute Enter Fullscreen
#1 about 3 min

Analyzing past internet attacks on distributed vehicle systems

Early attacks leveraged command injection and port scanning to compromise independent electronic control units via infotainment networks.

#2 about 3 min

Overcoming physical wiring constraints in legacy automotive networks

Traditional vehicle architectures rely on deeply segmented networks of microcontrollers connected by complex wire harnesses.

#3 about 2 min

Centralizing vehicle networks with high performance computers

Modern automotive architectures adopt cloud-like centralized computing and operating systems to facilitate regulatory updates and virtualization.

#4 about 2 min

Deploying isolated container runtimes on embedded Linux systems

Running standard bare metal hypervisors and container orchestration engines introduces resource friction on constrained embedded chips.

#5 about 4 min

Injecting network messages directly from compromised container environments

Exposing physical hardware interfaces directly to Docker networks allows process environments to manipulate mission-critical systems like brakes and dashboard speedometers.

#6 about 3 min

Protecting hardware access controls using eBPF security hooks

Compiling secure byte code logic within the Linux kernel stops rogue system calls and network packets without altering local processes.

#7 about 4 min

Intercepting and filtering automotive network traffic with eBPF

Integrating standard cloud egress monitoring with embedded vehicle protocols enables software-defined networking oversight across local vehicle interfaces.

#8 about 2 min

Blocking unauthorized peripheral updates via SPI bus monitoring

Programming kernel-level listeners selectively drops volatile bus transactions before hardware flashing overwrites root device partitions.

#9 about 3 min

Uncovering stealthy offensive eBPF rootkits in critical infrastructure

Offensive kernel interventions manipulate memory states dynamically and suppress application tracing mechanisms while leaving little to no defensive footprint.

Matching moments

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:13 min

Ecosystem of tooling and future capabilities of eBPF

Mohammed Aboullaite Mohammed Aboullaite · World Congress 2024

52 sec

Introduction to eBPF as a secure virtual machine

Ayesha Kaleem · World Congress 2023

9:13 min

Tackling functional complexity with localized vehicle electronic architectures

Hans-Jürgen Eidler · LIVE

5:56 min

Interfacing with core vehicle systems and handling software permissions

Stephan Schuster · World Congress 2022

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE