When a Vehicle Detects the Attack but Cannot Safely Block It episode artwork

EPISODE · Aug 31, 2026 · 1H 16M

When a Vehicle Detects the Attack but Cannot Safely Block It

from Cybersecurity Under Pressure. Real Attacks, Real Lessons · host Antonio Gonzalez

Detecting a cyberattack inside a moving vehicle is only the beginning. The harder question is what the vehicle should do once malicious traffic has been identified.In this episode, we examine the AutoHack dataset and a 2023 Hyundai vehicle experiencing synchronised anomalies across its C-CAN, P-CAN and B-CAN networks. The research provides a rare view of how attacks can propagate across multiple in-vehicle buses and produce observable consequences in a real cyber-physical system.We break down the architecture that makes these attacks possible. The CAN protocol was designed for speed, reliability and deterministic communication—not sender authentication. Once an attacker reaches the network, priority arbitration can be abused to flood the bus, suppress legitimate messages or impersonate an ECU through a carefully timed masquerade attack.The detection problem is equally difficult. Real vehicle traffic is noisy, irregular and event-driven. Diagnostic communication such as UDS does not follow a perfect timing pattern, meaning an intrusion detection system that performs well against a clean laboratory dataset may generate false positives or miss sophisticated attacks under real driving conditions.We then examine how the AUTOSAR Intrusion Detection System Manager processes security events while operating with limited memory, bandwidth and computing capacity. Filtering and rate limitation protect the ECU from resource exhaustion, but they can also discard the event that contains the most valuable forensic evidence.That creates the central operational decision: should the vehicle actively block suspicious communication, even when doing so could interrupt a safety-critical function, or should it continue monitoring while the attack may still be active?The episode pressure-tests a consequence-driven response based on reversible and traceable measures. Rather than immediately severing CAN communication, the proposed decision uses the IDSM in reporting mode, preserves qualified events locally, forwards relevant evidence to the backend SOC and validates stronger blocking controls in HIL environments before deploying them to the production fleet.The final lesson is that automotive cybersecurity cannot be demonstrated by detection accuracy alone. A defensible capability must connect a credible attack, its preconditions, its physical consequences, the observable signal, the detection mechanism and a response that remains safe under real operational constraints.Cybersecurity Under Pressure explores real attack techniques, their operational consequences and the engineering decisions required to protect cyber-physical products.Websitehttps://cybersecurityunderpressure.comTelegramhttps://t.me/cybersecurityunderpressure

Episode metadata supplied by the publisher feed · Published Aug 31, 2026

Embed this episode

Ready to play

When a Vehicle Detects the Attack but Cannot Safely Block It

0:00 1:16:14

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Cybersecurity Under Pressure. Real Attacks, Real Lessons?

This episode is 1 hour and 16 minutes long.

When was this Cybersecurity Under Pressure. Real Attacks, Real Lessons episode published?

This episode was published on August 31, 2026.

Can I download this Cybersecurity Under Pressure. Real Attacks, Real Lessons episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!