Penetration testing of the CAN bus-based XCP protocol for automotive ECMs
Abstract
With the development of automotive intelligence and connectivity, the security vulnerabilities of the XCP protocol adopted by in-vehicle ECUs have become increasingly prominent. Conducting targeted penetration testing is crucial for safeguarding in-vehicle security. This paper takes the ECM engine controller as the research object, builds a test environment based on CAN FD-200U hardware and Kali Linux, and uses SocketCAN and CaringCaribou tools. It designs and conducts penetration tests covering three typical XCP attack scenarios: node scanning, information disclosure, and calibration data tampering. A layered test architecture tailored for ECM applications is constructed, security risks of the XCP protocol under unauthenticated and weak-permission scenarios are identified, and engineering-oriented mitigation strategies are proposed. The research results can provide references for security testing, vulnerability mining, and protection system construction of the XCP protocol for in-vehicle ECUs.