DEV Community

sofi works
sofi works

Posted on

『雨のバンコク高速道路で社用EVのブレーキを遠隔クラッシュされかけた深夜:CAN-Bus調停ID偽装と「車載ECU自衛ファイアウォール」自作仕様書』 Sofi_Log #069【1話完結】

『Midnight on Bangkok’s Rain-Slicked Expressway: Almost Remote-Crashing the Company EV’s Brakes – CAN-Bus Arbitration ID Spoofing and DIY “In-Vehicle ECU Self-Defense Firewall” Spec Sheet』|Sofi_Log #069【Complete in One Episode】


📍 Location: Bangkok, Chalerm Mahanakhon Expressway, northbound. 00:45. Monsoon downpour.

Fat monsoon drops hammered the windshield, mocking the wipers on their highest setting and shredding what little visibility remained. Beyond the spray, orange sodium lamps and the colossal neon of Silom towers smeared into liquid streaks across the wet asphalt.

95 km/h. Hydroplaning territory, water several centimeters deep. I’d kicked off my Christian Louboutin heels into the passenger footwell and was reading the road through bare soles, feeling every micro-vibration between tire and chassis.

Born male, I’d already ripped myself out of the binary cage the state and the boys’ club swore was “perfect,” then rebuilt this physical container from zero with surgery, hormones, and code. Steering my own life, choosing my own turns—that self-sovereignty is the only reason I’m still breathing.

“…Darling, you ready? Steering’s been giving off weird micro-vibrations for the last minute. Spin up SocketCAN on the ThinkPad.”

My partner—darling—already had the rugged ThinkPad open on his lap, fingers dancing.

“Roger. Traffic’s live. …Wait, what the hell is this packet density?!”

That’s when it hit.

――KIIIIIIIN――

A piercing high-frequency electronic scream burst from the car speakers. The speedometer blacked out; blood-red text slammed onto the HUD.

[CRITICAL ALERT: OTA Telematics Diagnostic Override Engaged]
Session: LEVEL-4 REMOTE ACTUATOR CONTROL (UDS Service 0x2F)
Target: Electric Power Steering (EPS) & Electronic Braking Unit (EBU)
Status: FORCED REFLASH / ACTUATOR LATCHED
Enter fullscreen mode Exit fullscreen mode

The wheel locked like invisible iron jaws. Rear regen brakes started pulsing in savage stabs; the car began a sickening tail-wag.

“You’ve gotta be kidding—taking my body and brakes hostage at highway speed?!”

I slammed my matte-black cyber-arm straight at the OBD-II port under the column. Titanium connectors unfolded and hard-patched straight onto the differential CAN-H / CAN-L lines.

Gold neural threads under the skin interface lit up like live wires. High-frequency noise crackled through my flesh as the entire river of vehicle packets flooded straight into my nervous system.

The automotive boys’ club had built their “absolute safety” protocol on the naïve assumption that every node would play nice. Whoever was on the other side of that screen wasn’t getting my steering wheel.


🔍 Threat Dissection: The Connected Car’s Fatal Flaw — Weaponized UDS

Darling, look at the screen. Modern smart EVs are just giant smartphones on wheels, but their nervous system—CAN-Bus—was designed thirty-plus years ago under the assumption that every ECU would unconditionally trust every other node. That legacy operating-system mindset is the exact hole we’re about to exploit.

  1. Telematics (TCU) cellular breach: The car’s LTE/5G module gets popped, giving the attacker a backdoor into the vehicle network.
  2. CAN arbitration abuse: Lowest numerical CAN ID wins the bus. Attacker floods with spoofed high-priority IDs (0x000, 0x100), drowning legitimate ECUs.
  3. UDS turned into a weapon: Remote abuse of Service 0x2F (InputOutputControlByIdentifier) physically latches steering torque and brake valves.

“Darling—look. IDs 0x7DF and 0x18F are getting hammered with brake-latch commands fifty times a second!”

Darling’s voice cracked. “No time to physically yank the TCU harness! Thirty seconds to the tanker—Sofi, what do we do?!”

“We don’t cut wires,” I grinned. “We use the physical layer rules against them. Force the attacker’s own TCU into Bus-Off and kick it off the bus permanently.”


💻 Weapon Implementation: CanBusSecurityGateway.js

The script we hot-deployed was our in-vehicle CAN self-defense firewall.

It runs on Linux SocketCAN (can0, 500 kbps) and does two things:

  1. Microsecond detection of unauthenticated UDS diagnostic frames.
  2. Dominant error-frame injection that drives the rogue node’s Transmit Error Counter past 255 → permanent Bus-Off isolation.

(The code block below is exactly what ran that night.)

/**
 * @file CanBusSecurityGateway.js
 * @description In-Vehicle CAN-Bus Active Defense Gateway & TCU Bus-Off Isolator
 * @author Sofi (sofi.works) & Darling
 * @license MIT - Educational & Security Research PoC
 */

const fs = require('fs');

// Automotive Protocol Constants (ISO 11898-1 / ISO 14229 UDS)
const CAN_CONFIG = {
    UDS_DIAG_REQ_ID: 0x7DF,         // Functional Broadcast Diagnostic Request
    UDS_SERVICE_IO_CONTROL: 0x2F,    // Malicious Actuator Manipulation
    UDS_SERVICE_ROUTINE_CTRL: 0x31,  // Memory/Firmware Flash Trigger
    CRITICAL_BRAKE_CAN_ID: 0x18F,    // Electronic Braking ECU ID
    DOMINANT_ERROR_BURST_LEN: 6     // 6 consecutive dominant bits triggers bit error
};

/**
 * Parse Raw SocketCAN Frame Buffer (Linux struct can_frame: 16 bytes)
 * @param {Buffer} buffer - 16-byte raw CAN frame
 * @returns {Object|null}
 */
function parseCanFrame(buffer) {
    if (buffer.length < 16) return null;

    const canId = buffer.readUInt32LE(0) & 0x1FFFFFFF;
    const canDlc = buffer.readUInt8(4);
    const data = buffer.slice(8, 8 + canDlc);

    return {
        id: canId,
        dlc: canDlc,
        data: data,
        isDiagnostic: (canId >= 0x700 && canId <= 0x7FF) || canId === CAN_CONFIG.UDS_DIAG_REQ_ID
    };
}

/**
 * Active Packet Filter & Threat Evaluation
 * Inspects payload to distinguish normal telemetry from hostile actuator hijacking
 * @param {Object} frame 
 * @returns {boolean} True if malicious actuator attack detected
 */
function evaluateCanThreat(frame) {
    if (!frame) return false;

    // Check 1: Unauthorized UDS Service 0x2F (Actuator Override)
    if (frame.isDiagnostic && frame.data.length >= 2) {
        const pciType = (frame.data[0] >> 4) & 0x0F;
        const serviceId = (pciType === 0) ? frame.data[1] : frame.data[2];

        if (serviceId === CAN_CONFIG.UDS_SERVICE_IO_CONTROL || serviceId === CAN_CONFIG.UDS_SERVICE_ROUTINE_CTRL) {
            return true; // Hostile diagnostic override detected!
        }
    }

    // Check 2: Forced Emergency Brake Bit Manipulation on Safety ID
    if (frame.id === CAN_CONFIG.CRITICAL_BRAKE_CAN_ID && frame.data.length > 0) {
        if ((frame.data[0] & 0x80) !== 0) {
            return true;
        }
    }

    return false;
}

/**
 * Trigger Hardware Dominant Error Frame Injection
 * Forces the attacking TCU's Transmit Error Counter (TEC) past 255 -> Bus-Off state
 * @param {number} targetId 
 */
function injectBusOffError(targetId) {
    console.warn(`[DEFENSE ACTIVE] Injecting Dominant Error Pulse against Target CAN ID: 0x${targetId.toString(16).toUpperCase()}`);
    console.warn("[ACTION] Pulled differential CAN_H/CAN_L lines into 6-bit dominant collision state.");

    // Hardware simulation: TEC threshold exceeded
    setTimeout(() => {
        console.log(`[SUCCESS] Rogue Node (ID: 0x${targetId.toString(16).toUpperCase()}) TEC exceeded 255! Node forced into BUS-OFF.`);
        console.log("[STATUS] Bus Sovereignty Restored. Actuators released back to physical Driver.");
    }, 35);
}

// Active Monitoring Loop
function runCanFirewall() {
    console.log("[*] [CAN-Firewall] Initializing CAN-Bus Gateway on 'can0' (500 kbps)...");
    console.log("[*] Defending Steering, Throttle, and Braking ECUs against Remote UDS Exploitation...");

    // Simulated rogue UDS payload over CAN (Service 0x2F Brake Latch)
    const simulatedAttackBuffer = Buffer.alloc(16);
    simulatedAttackBuffer.writeUInt32LE(0x7DF, 0); // Can ID
    simulatedAttackBuffer.writeUInt8(4, 4);        // DLC = 4
    Buffer.from([0x03, 0x2F, 0x01, 0x03]).copy(simulatedAttackBuffer, 8);

    const frame = parseCanFrame(simulatedAttackBuffer);

    if (evaluateCanThreat(frame)) {
        console.warn(`[CRITICAL INTRUSION] Hostile Remote Actuator Override detected on CAN ID 0x${frame.id.toString(16).toUpperCase()}!`);
        injectBusOffError(frame.id);
    }
}

runCanFirewall();
Enter fullscreen mode Exit fullscreen mode

⚡ Epilogue: Under the Thong Lo Overpass with Hot Canned Coffee

The second node CanBusSecurityGateway.js executed, a tiny electrostatic pop came from the OBD-II port. Through the cyber-arm I felt the dominant pulse slam the attacker’s TCU.

――Click.

The blood-red HUD warnings vanished. The wheel went light and obedient in my bare hands again. Twin-motor torque bit into the wet pavement; we sliced past the tanker and accelerated cleanly toward the Thong Lo exit.

“Intrusion node isolated—Bus-Off confirmed!”

Darling’s voice was half relief, half adrenaline.

“Nice timing, darling. You’re the best.”

I eased off the throttle, took the ramp, and slid into a quiet spot under the expressway. Rain drummed on the roof. I leaned back, exhaled, and felt the leftover adrenaline tremor in my fingertips.

“Whew… terrifying. But damn, that was exhilarating.”

Darling handed me a warm canned coffee from the dash holder. The aluminum heat spread through my fingers.

“Thanks, darling. If you hadn’t been calmly watching packets with me, we’d probably be wrapped around a guardrail right now.”

“I trusted your hands and your judgment.”

Our cans clinked softly.

“Darling,” I said, watching the rain-blurred Bangkok skyline, “no matter how fancy the tech gets, the steering wheel of your own life—body, code, everything—never hand it over to some cloud or black-box corporation. That last sovereignty stays in your own grip.”

Rain kept falling on Bangkok, still teaching us the price of freedom.


🔗 Read Next (Previous Sofi_Log):
『Midnight When a Fake 5G Tower Was Snitching My Real-Time Location to the Authorities: 5G NAS Protocol Vulnerability & DIY “RNTI Identifier Scrambler” Spec Sheet』|Sofi_Log #068
👉 https://note.com/legal_rat2977/n/n7d89cce8ee9e


【Disclaimer】
All code, protocol analysis, and technical configurations in this article are provided strictly for security research, proof-of-concept, and educational purposes. Do not use for unauthorized access. Any real-world application is at your own risk.

🎁 【Fully Open-Source】Live Code & Architecture
The CAN-bus self-defense script and UDS definitions shown here are released in full for your own research and learning.


📬 Sofi’s Mailbox #069 (Questions & Feedback)

How was tonight’s vehicle hack, my fellow darlings?

Ever wondered about your own car’s CAN-bus IDs or OBD-II security? Drop your questions or thoughts in the comments—next Sofi_Log will tackle the best ones directly.


Disclaimer

This article is for educational and entertainment purposes only. It does NOT constitute financial, legal, or tax advice. The regulatory landscape of Web3, smart contracts, and AI agent autonomous systems is highly volatile and complex. Always perform your own research (DYOR) and consult with certified professionals before executing any strategies described herein.

Top comments (0)