Álvaro de Castro
tech & mngt staff
Edificio de Investigación Ada Byron
C/ Arquitecto Francisco Peñalosa, nº 18
Ampliación Campus de Teatinos. Universidad de Málaga
29071 Málaga (Spain)
Phone: +34 951 952 934
E-mail: alvarodc@uma.es
Publications
Alvaro de Castro, Antonio Muñoz
Attack Modelling and Intrusion Detection in a CAN-Based Smart Parking Cyber-Physical System
In: Proceedings of the 6th ACM Workshop on Secure and Trustworthy Cyber-Physical Systems (SaT-CPS ’26), pp. 33-42, ACM, Germany, 2026.
@inproceedings{decastro2026,
title = {Attack Modelling and Intrusion Detection in a CAN-Based Smart Parking Cyber-Physical System},
author = {Alvaro de Castro and Antonio Mu\~{n}oz},
url = {/wp-content/papers/decastro2026.pdf},
doi = {10.1145/3806008.3811701},
year = {2026},
date = {2026-06-22},
urldate = {2026-06-22},
booktitle = {Proceedings of the 6th ACM Workshop on Secure and Trustworthy Cyber-Physical Systems (SaT-CPS '26)},
pages = {33-42},
publisher = {ACM},
address = {Germany},
abstract = {Controller Area Network (CAN) is still widely used in industrial parking installations because it provides simple and predictable communication, but its lack of built-in authentication leaves sensing and actuation exposed to message injection and bus-flooding attacks. In this paper, we study a smart parking cyber-physical system in which ultrasonic occupancy sensors, gas and temperature sensors, a ventilation controller, and a servo-driven entry barrier exchange messages over a shared CAN bus. Vehicle access is handled by an Automatic Number Plate Recognition (ANPR) pipeline based on YOLO for plate detection and PaddleOCR for character recognition. We define attack scenarios covering CAN flooding, false-data injection, and command spoofing, and we also examine attacks affecting the ANPR path. We relate these attacks to concrete system-level effects, including reduced parking availability, unauthorized barrier operation, and missed ventilation responses. To detect CAN-side attacks, we implement a passive intrusion detector that combines identifier allowlisting, DLC checks, range validation, rate thresholds, and payload deviation monitoring. In our experiments, this detector reliably identifies disruptive CAN attacks with low false positive rates and little interference with benign traffic, but it is less effective against stealthier manipulations that remain within expected ranges and timing patterns. These results suggest that simple passive monitoring can strengthen legacy CAN-based industrial CPS, while low-profile and cross-boundary attacks require richer temporal or cross-layer defenses.},
keywords = {},
pubstate = {published},
tppubtype = {inproceedings}
}
Controller Area Network (CAN) is still widely used in industrial parking installations because it provides simple and predictable communication, but its lack of built-in authentication leaves sensing and actuation exposed to message injection and bus-flooding attacks. In this paper, we study a smart parking cyber-physical system in which ultrasonic occupancy sensors, gas and temperature sensors, a ventilation controller, and a servo-driven entry barrier exchange messages over a shared CAN bus. Vehicle access is handled by an Automatic Number Plate Recognition (ANPR) pipeline based on YOLO for plate detection and PaddleOCR for character recognition. We define attack scenarios covering CAN flooding, false-data injection, and command spoofing, and we also examine attacks affecting the ANPR path. We relate these attacks to concrete system-level effects, including reduced parking availability, unauthorized barrier operation, and missed ventilation responses. To detect CAN-side attacks, we implement a passive intrusion detector that combines identifier allowlisting, DLC checks, range validation, rate thresholds, and payload deviation monitoring. In our experiments, this detector reliably identifies disruptive CAN attacks with low false positive rates and little interference with benign traffic, but it is less effective against stealthier manipulations that remain within expected ranges and timing patterns. These results suggest that simple passive monitoring can strengthen legacy CAN-based industrial CPS, while low-profile and cross-boundary attacks require richer temporal or cross-layer defenses.


