Skip to content
Conference

Penetration testing of the CAN bus-based XCP protocol for automotive ECMs

Sep 2026 · International Conference on Signal Processing and Communication Security · Vol 14374, pp. 143740R - 143740R-6 · 0 citations · 10 references
Engineering

Abstract

With the development of automotive intelligence and connectivity, the security vulnerabilities of the XCP protocol adopted by in-vehicle ECUs have become increasingly prominent. Conducting targeted penetration testing is crucial for safeguarding in-vehicle security. This paper takes the ECM engine controller as the research object, builds a test environment based on CAN FD-200U hardware and Kali Linux, and uses SocketCAN and CaringCaribou tools. It designs and conducts penetration tests covering three typical XCP attack scenarios: node scanning, information disclosure, and calibration data tampering. A layered test architecture tailored for ECM applications is constructed, security risks of the XCP protocol under unauthenticated and weak-permission scenarios are identified, and engineering-oriented mitigation strategies are proposed. The research results can provide references for security testing, vulnerability mining, and protection system construction of the XCP protocol for in-vehicle ECUs.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.