IT Forensics · Car

Forensic investigation of CAN bus attacks – Forensically detecting tampering with the vehicle data bus

The CAN bus connects a vehicle’s central control units and can be the target of deliberate attempts at manipulation, such as by injecting fake messages to interfere with vehicle functions.

Enquire without obligation

A forensic investigation examines available log data and technical anomalies that may indicate such an attack.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

The examination is, as a matter of principle, carried out exclusively on a forensic copy, a forensic image or a data source captured in a technically equivalent manner that preserves the integrity of the evidence. The original evidence remains unchanged and is stored in a manner that preserves its integrity.

Our services

We examine available control unit data for technical anomalies that may indicate a CAN bus attack, and document our findings in a manner that is forensically verifiable.

Typical areas of application

•Investigation into suspected CAN bus tampering
•Investigating the technical causes of unusual vehicle behaviour
•Support in the event of vehicle cyber security incidents
•Supplement to ECU and fault memory analyses
•Judicial and non-judicial expert reports
•Collaboration with manufacturers and IT security experts

This is how a CAN bus attack analysis is carried out

Once the relevant control units have been backed up, the available communication protocols and fault memory entries are checked for technical anomalies that might indicate tampering with the bus communication.

Why is CAN bus attack analysis relevant to forensic investigation?

A successful attack on the vehicle data bus can have significant implications for safety-critical functions and is therefore of great forensic importance.

As CAN bus attacks are technically complex and cannot always be conclusively proven, the limitations of the investigation are communicated transparently.

Frequently Asked Questions

Can every CAN bus attack be proven beyond doubt through forensic analysis?+
Not in every case; modern attack methods can vary considerably; we examine the available data carefully and communicate any technical limitations transparently.
What tools does LanCologne use for this analysis?+
We analyse the available ECU data using our established forensic tools, in particular Belkasoft X and X-Ways Forensics.
Is a CAN bus attack the same as a keyless relay attack?+
No, these are different types of attack, each of which is considered separately.

LanCologne – Vehicle IT Forensics, Cologne

Do you require a professional forensic investigation into „forensic analysis of CAN bus attacks"? LanCologne can assist you with the court-admissible preservation of digital evidence and the transparent analysis of relevant vehicle artefacts.

Get in touch now