Vehicle OBD-II Telemetry Sniffing, CAN ID Arbitration, Frame Injection, and ECU Spoofing

Hardware & Systems Takeaway

Controller Area Network (CAN) is the nervous system of modern automobiles. Designed in the 1980s for fault tolerance, CAN bus lacks authentication and encryption: any device connected to the OBD-II port can read vehicle telemetry and inject spoofed steering or braking packets.

Empirical Architecture Comparison: CAN Bus Protocol Architecture vs. Traditional Serial Networks

Protocol AttributeStandard UART / RS-232Controller Area Network (CAN 2.0B)
Signaling MediumSingle-ended voltage (Sensitive to noise)Differential balanced pair (CAN_High & CAN_Low; immune to EM noise)
Addressing SchemePoint-to-point / Master-Slave device addressesMessage-based arbitration IDs (No device addresses; broadcast network)
Bus ContentionCollisions corrupt transmissionsNon-destructive bitwise arbitration (Dominant 0 overwrites Recessive 1)
Error HandlingManual parity checkingHardware bit-stuffing, 15-bit CRC, frame check, and automatic fault confinement
SecurityUnencrypted point-to-pointBroadcast medium; zero authentication, zero encryption on standard bus

1. The Physical and Data Link Layers of CAN

Vehicular electronic control units (ECUs)—governing everything from the engine and transmission to ABS and power steering—communicate over a two-wire twisted pair: CAN High and CAN Low. Logical values are differential voltages:
  • Recessive Bit (Logical 1): Both wires sit at $2.5$V (Differential voltage $\Delta V = 0$V).
  • Dominant Bit (Logical 0): CAN_H rises to $3.5$V and CAN_L drops to $1.5$V (Differential voltage $\Delta V = 2.0$V).
Because dominant bits electrically override recessive bits on the bus wire, nodes with lower numerical Arbitration IDs (e.g., $0x001$ Emergency Brake vs. $0x3F2$ Air Conditioning) win bus arbitration without packet collision.

2. Sniffing Vehicle Traffic with SocketCAN and Cangaroo

Accessing vehicular network telemetry requires tapping into the internal High-Speed CAN bus (500 kbps) via the under-dash OBD-II diagnostic port (Pins 6 and 14). Using a USB-CAN adapter (such as a Canable running candlelight firmware), Linux exposes the bus as a standard network interface:
# Setting up SocketCAN interface in Linux
sudo ip link set can0 type can bitrate 500000
sudo ip link set up can0

# Dumping live vehicular telemetry frames
candump can0

# Example output stream:
# can0  0C9   [8]  20 00 1A 4F 00 00 18 90
# can0  1A4   [4]  FF 02 12 00
# can0  280   [8]  10 24 10 24 00 00 00 00

3. Reverse Engineering Proprietary Payloads via Differential Analysis

Because manufacturers keep CAN DBC (Database CAN) matrices strictly confidential, reverse engineering requires differential packet analysis:
  1. Idle Baseline: Record 60 seconds of traffic with vehicle engine idling in park.
  2. Action Capture: Press the accelerator pedal to 50% while capturing packets.
  3. Delta Isolation: Tools like `cansniffer` highlight bytes that change dynamically with pedal movement. A 2-byte integer in CAN ID `0x1DC` scaling from `0x0000` to `0x7FFF` isolates the accelerator pedal position sensor.

4. Packet Injection Attacks & Modern SecOC Defenses

Because CAN bus does not authenticate sender identity, an attacker injecting spoofed CAN frames at higher frequencies ($100$ Hz) than legitimate ECUs can override vehicular controls (e.g., injecting speedometer spoofing or lane-keep steering nudges). Modern automotive security combats this via AUTOSAR SecOC (Secure Onboard Communication), which appends an 8-byte Message Authentication Code (MAC) and freshness sequence counter to every frame, ensuring unauthorized frames are discarded at the transceiver.