ECUInjector: An Automotive ECU Security Analysis Tool

Authors

DOI:

https://doi.org/10.34190/eccws.25.1.4704

Keywords:

Automotive security, Reverse-engineering, Embedded system security

Abstract

Electronic Control Units (ECUs) are responsible for a significant number of systems in modern day vehicles. If these systems are compromised, the resulting attacks will result in road accidents. Therefore, increased adoption of these systems has significantly widened vehicle attack surfaces. As a result, it is important to devise methods of identifying and investigating vulnerabilities within automotive control systems, allowing them to be patched before they are exploited by an attacker. To this end, we present ECUInjector, an open-source application designed to assist in the discovery of vulnerabilities within diagnostic interfaces and ECU communications. The software is designed in a modular way allowing it to be universal across ECU vendors and provides the ability to communicate via vehicle diagnostics buses and build vulnerability detection tools that can assist in locating potential weaknesses. We also provide some of our applications of using the software to communicate with and analyse various ECUs.

Downloads

Published

2026-06-15