Yashin Mehaboobe

Security Consultant Xebia

BIOGRAPHY

Yashin Mehaboobe is a security consultant at Xebia and has more than 8 years experience in the embedded systems security domain. His primary areas of interest is blackbox vulnerability analysis and pentesting of common IoT devices with focus on Internet facing scalable attacks. He’s also identified several fault injection attacks in open source embedded software and modern microcontrollers. In his spare time he likes to travel, take photographs, bake and read.

Attacking Vehicle Fleet Management Systems

For the last 10 years, the automotive industry has been involved in an electrification and automation process that is revolutionizing the way we drive. The fundamentals of this deep transformation are the battery-powered engines, the self-driving cars and the connected vehicles. These technological advances – specially the connectivity of the vehicles – brings many new cybersecurity challenges that need to be addressed in the coming years.

The goal of the work we present here is to assess the current state of the connected vehicles security. Compared with other works already published where the researchers chose to attack a popular modern car, we focused in other automotive components and systems that security experts – and car designers – usually overlook and that could be abused to launch scalable and massive attacks. The analyzed devices like T-boxes, OBD2 dongles, 5G modems, MQTT servers and mobile apps. We aimed to get a broader picture of the automotive security and not a limited view based exclusively on the car security.

Our research resulted in multiple vulnerability issues that can be exploited remotely to get full control of an entire fleet of vehicles, including cars, heavy-duty trucks and cranes. Although our work is limited to few devices – not enough to make an industry-wide conclusion – it indicates that these kind of security issues might be common and the security of connected automotive systems needs to be improved.

Are you the next cyber security superstar?

If you are passionate about an information security topic or you have strong technical skills developing researches on your own, you should definitely Apply at Call for Papers. By submitting you will have the chance to showcase your work to +2000 attendees.

Other speakers joining this year

Abdullah Al-Sultani

Product Security Engineer TikTok

Joey Geralnik

Software Security Consultant Hypr

Todor Todorov

Senior Software Engineer Payhawk

Ready for this year's presentations?

By registering you will unlock access to 60+ speakers and two full days with cyber security news & showcases from worldwide leaders.

SPEAKERS
0
COUNTRIES
0
ATTENDEES
0
HACKING
COMPETITIONS
0
COMPANIES
0

Sponsors & Partners

They help us make this conference possible.

POWERED BY

Orange Romania is part of the Orange Group, one of the largest global telecommunications operators that connects hundreds of millions of customers worldwide. With over 11 million local customers and an annual turnover exceeding 1.5 billion euros, Orange Romania connects 1 in 2 Romanians and offers an extensive range of communication solutions for both individual and corporate customers, from basic connectivity services to complete mobile, fixed internet, TV packages, and complex IT&C solutions through Orange Business

Orange Romania is the number 1 operator in terms of network performance, and also holds nine consecutive Top Employer certifications, which confirm that Orange Romania, in addition to the remarkable products and services it offers, pays special attention to its employees and working environment. In the past 3 years Orange has launched two 5G Labs in Bucharest and Iasi, that aim to support researchers, startups and companies to test their 5G solutions in advance. 

In addition, Orange is a long-term supporter of the startup ecosystem through the Orange Fab accelerator program designed to support entrepreneurs in the development of innovative products and their distribution locally and internationally.

Gold Partners

Silver Partners

Bronze Partner
HACKING VILLAGE PARTNERS

COMMUNITY & MEDIA PARTNERS