Podcast Episode

When a Vehicle Detects the Attack but Cannot Safely Block It

About this episode

Detecting a cyberattack inside a moving vehicle is only the beginning. The harder question is what the vehicle should do once malicious traffic has been identified. In this episode, we examine the AutoHack dataset and a 2023 Hyundai vehicle experiencing synchronised anomalies across its C-CAN, P-CAN and B-CAN networks. The research provides a rare view of how attacks can propagate across multiple in-vehicle buses and produce observable consequences in a real cyber-physical system. We break down the architecture that makes these attacks possible. The CAN protocol was designed for speed, reliability and deterministic communication—not sender authentication. Once an attacker reaches the network, priority arbitration can be abused to flood the bus, suppress legitimate messages or impersonate an ECU through a carefully timed masquerade attack. The detection problem is equally difficult. Real vehicle traffic is noisy, irregular and event-driven. Diagnostic communication such as UDS does not follow a perfect timing pattern, meaning an intrusion detection system that performs well against a clean laboratory dataset may generate false positives or miss sophisticated attacks under real driving conditions. We then examine how the AUTOSAR Intrusion Detection System Manager processes security events while operating with limited memory, bandwidth and computing capacity. Filtering and rate limitation protect the ECU from resource exhaustion, but they can also discard the event that contains the most valuable forensic evidence. That creates the central operational decision: should the vehicle actively block suspicious communication, even when doing so could interrupt a safety-critical function, or should it continue monitoring while the attack may still be active? The episode pressure-tests a consequence-driven response based on reversible and traceable measures. Rather than immediately severing CAN communication, the proposed decision uses the IDSM in reporting mode, preserves qualified events locally, forwards relevant evidence to the backend SOC and validates stronger blocking controls in HIL environments before deploying them to the production fleet. The final lesson is that automotive cybersecurity cannot be demonstrated by detection accuracy alone. A defensible capability must connect a credible attack, its preconditions, its physical consequences, the observable signal, the detection mechanism and a response that remains safe under real operational constraints. Cybersecurity Under Pressure explores real attack techniques, their operational consequences and the engineering decisions required to protect cyber-physical products. Websitehttps://cybersecurityunderpressure.com Telegramhttps://t.me/cybersecurityunderpressure