Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points
L.H. Gebauer, H. Trsek, G. Lukas, in: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA), IEEE, Piscataway, NJ, 2022.
Download
Es wurde kein Volltext hochgeladen. Nur Publikationsnachweis!
Konferenz - Beitrag
| Veröffentlicht
| Englisch
Autor*in
Abstract
The reduction of CO2 emissions caused by auto-mobile traffic relies on the development of electric mobility infrastructure which in turn relies on efficient communication between charge points, used to connect electric vehicles to the power network, and central systems, used to manage users and transactions. The Open Charge Point Protocol (OCPP) is an open communication protocol designed to connect charge points to a central system. An important aspect of the communication between these entities is the security of the connection. It is conceivable, for instance, that an adversary could compromise a central system to attack charge points.This work devises three different attack scenarios which could be executed by a malicious OCPP central system to attack an OCPP charge point. It also assesses the feasibility and potential consequences of such attacks. Additionally, it presents an approach of an "evil" OCPP server implementation, based on the SteVe server which was originally developed at the RWTH Aachen. The "evil" OCPP server implements various attack scenarios and is intended to be used for penetration testing of OCPP charge points that connect to the central system via WebSockets/JSON or SOAP/XML.
Erscheinungsjahr
Titel des Konferenzbandes
2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA)
Konferenz
27th International Conference on Emerging Technologies and Factory Automation (ETFA)
Konferenzort
Stuttgart
Konferenzdatum
2022-09-06 – 2022-09-09
ISBN
ELSA-ID
Zitieren
Gebauer LH, Trsek H, Lukas G. Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points. In: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). IEEE; 2022. doi:10.1109/ETFA52439.2022.9921430
Gebauer, L. H., Trsek, H., & Lukas, G. (2022). Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points. 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). 27th International Conference on Emerging Technologies and Factory Automation (ETFA), Stuttgart. https://doi.org/10.1109/ETFA52439.2022.9921430
Gebauer LH, Trsek H and Lukas G (2022) Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points. 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). Piscataway, NJ: IEEE.
Gebauer, Lisa Helene, Henning Trsek, and Georg Lukas. “Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points.” In 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). Piscataway, NJ: IEEE, 2022. https://doi.org/10.1109/ETFA52439.2022.9921430.
Gebauer, Lisa Helene, Henning Trsek und Georg Lukas. 2022. Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points. In: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). Piscataway, NJ: IEEE. doi:10.1109/ETFA52439.2022.9921430, .
Gebauer, Lisa Helene ; Trsek, Henning ; Lukas, Georg: Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points. In: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). Piscataway, NJ : IEEE, 2022
L.H. Gebauer, H. Trsek, G. Lukas, Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points, in: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA), IEEE, Piscataway, NJ, 2022.
L. H. Gebauer, H. Trsek, and G. Lukas, “Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points,” presented at the 27th International Conference on Emerging Technologies and Factory Automation (ETFA), Stuttgart, 2022. doi: 10.1109/ETFA52439.2022.9921430.
Gebauer, Lisa Helene, et al. “Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points.” 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA), IEEE, 2022, https://doi.org/10.1109/ETFA52439.2022.9921430.
Gebauer, Lisa Helene/Trsek, Henning/Lukas, Georg: Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points, in: o. Hg.: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA), Piscataway, NJ 2022.
Gebauer LH, Trsek H, Lukas G. Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points. In: 2022 IEEE 27th International Conference on Emerging Technologies and Factory Automation (ETFA). Piscataway, NJ: IEEE; 2022.