Network Sniffing

Adversaries may gain unauthorized access to vehicle systems by using network sniffing technique. This method allows them to capture information about the vehicle's network, including authentication material passed over the network. Network sniffing involves monitoring or capturing information sent over a wired or wireless connection, providing adversaries with valuable data about the vehicle's network activity.

Most of fundamental protocol of in-vehicle networks, such as CAN Bus, operates as a broadcasting network where every device on the bus can read transmitted messages. When sensitive information is sent over the CAN Bus, adversaries can leverage network sniffing techniques to intercept and obtain this data discreetly. This presents a grave risk to the confidentiality and integrity of in-vehicle network communications, potentially granting unauthorized access and control.

ID: T2037
Sub-techniques:  No sub-techniques
Version: 1.0
Created: 03 December 2023
Last Modified: 03 December 2023
ATT&CK Reference:  T1040

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.