Tuesday, March 4, 2025
HomeSecurity HackerPASTA - A New Car Hacking Tool Developed by Toyota to Test...

PASTA – A New Car Hacking Tool Developed by Toyota to Test The Security Vulnerabilities

Published on

SIEM as a Service

Follow Us on Google News

Toyota builds a new car hacking tool called PASTA (Portable Automotive Security Testbed) an open source tool for researchers to test the security vulnerabilities in modern cars.

A Team of security researchers from Toyota carried a tool box to present their research in BLACKHAT EUROPE 2018, London and they demonstrate the PASTA testing platform in front of blackhat audience.

Cyber criminals often compromising the cars since everything connected to the Internet, a poor security configuration or poor programming of the devices open the possibility of an attack that alters the functions of the vehicle, remotely gaining control of it.

Also still its challenging in case of automated driving, securing vehicles that running under sophisticated driving-assist technologies against cyber attacks.

Toyota’s building this tool to perform security testing automobile manufacturers to perform testing and exposing holes in the automated and networked features in their vehicles.

                                                                                  Structure of PASTA

PASTA car hacking tool is contained in an 8 kg portable briefcase and they integrated with a driving simulator program

Toyota security researchers propose this tools by Considering some important requirement including, security electronic control unit (ECU)  by places tough restrictions in order to test vulnerabilities and exploits.

An electronic control unit (ECU) is at the center of the development of cybersecurity technology, and each supplier develops its own automotive information security technology for ECUs in its own environment.

In this case, anyone will be able to apply technology and evaluate that technology with ECU when creating a platform with transparent ECUs with high adaptability.

Toyota researcher said during the demonstration, “Simulating an actual vehicle through hardware is also required for assessing threats of cyberattacks. We need not only to provide an adaptable platform for developing measures for existing cybersecurity but also simulate any function in actual vehicles using white-box ECUs.”

It simulates the remote operation of wheels, brakes, windows, and other car features rather than “the real thing,” for safety reasons. “It’s small and portable so users can study, research, and hack with it anywhere.”

Driving simulator connected to PASTA

Researchers believe that Car Hacking Tool PASTA has the possibility to contribute to a comprehensive development platform against vehicle cyberattacks.

Also, Toyota plans to share the specifications on Github, as well as initially Toyota sell the fully built system in Japan.

Please find the complete white paper and Presentation for Car Hacking Tool project.

• Download Presentation Slides
• Download White Paper

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March...

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Routers Under Attack as Scanning Attacks on IoT and Networks Surge to Record Highs

In a concerning trend, the frequency of scanning attacks targeting Internet of Things (IoT)...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March...

Paragon Partition Manager Vulnerabilities Allow Attackers to Escalate Privileges and Trigger DoS Attacks

Security researchers have uncovered five significant vulnerabilities in Paragon Partition Manager's BioNTdrv.sys driver, affecting...

Substack Custom Domain Vulnerability Exposes Thousands to Potential Hijacking

A newly disclosed vulnerability in Substack's custom domain setup could allow malicious actors to...