Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Endianness”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

CAN-D: A Modular Four-Step Pipeline for Comprehensively Decoding Controller Area Network Data

Controller area networks (CANs) are a broadcast protocol for real-time communication of critical vehicle subsystems. Original equipment manufacturers of passenger vehicles hold secret their mappings of CAN data to vehicle signals, and these definitions vary according to make, model, and year. Without these mappings, the wealth of real-time vehicle information hidden in the CAN packets is uninterpretable, severely impeding vehicle-related research, including CAN cybersecurity and privacy studies, aftermarket tuning, efficiency and performance monitoring, and fault diagnosis to name a few. Guided by the four-part CAN signal definition, we present CAN-D (CAN-Decoder), a modular, four-step pipeline for identifying each signal's boundaries (start bit and length), endianness (byte ordering), signedness (bit-to-integer encoding), and by leveraging diagnostic standards, augmenting a subset of the extracted signals with meaningful, physical interpretation. En route to CAN-D, we provide a comprehensive review of the CAN signal reverse engineering research. All previous methods ignore endianness and signedness, rendering them incapable of decoding many standard CAN signal definitions. Incorporating endianness grows the search space from 128 to 4.72E21 signal tokenizations and introduces a web of changing dependencies. In response, we formulate, formally analyze, and provide an efficient solution to an optimization problem, allowing identification of the optimal set of signal boundaries and byte orderings. In addition, we provide two novel, state-of-the-art signal boundary classifiers—both of which are superior to previous approaches in precision and recall in three different test scenarios—and the first signedness classification algorithm, which exhibits a $>$ 97% F-score. Altogether, CAN-D is the only solution with the potential to extract any CAN signal that is also the state of the art. In evaluation on 10 vehicles of different makes, CAN-D's average $\ell ^1$ error is five times better (81% less) than all previous methods and exhibits lower average error, even when considering only signals that meet prior methods’ assumptions. Finally, CAN-D is implemented in lightweight hardware, allowing for an on-board diagnostic (OBD-II) plugin for real-time in-vehicle CAN decoding.

42 ENGINEERING↗

SST-TG-P1F4R3200: Decaying Stably-Stratified Turbulence (SST), Initialized Using Taylor-Green Vortices (TG) at Prandtl Number Pr=1, Froude Number Fr=4, Reynolds Number Re=3200

This dataset comprises direct numerical simulations (DNS) of decaying stably-stratified turbulence influenced by a linear background density gradient, initialized using an array of Taylor-Green vortices, as described in [Riley & de Bruyn Kops (2003)](https://doi.org/10.1063/1.1578077). The initial Prandtl, Froude, and Reynolds numbers are (Pr, Fr, Re) = (1, 4, 3200). A total of 15,000 snapshots are recorded at uniform time intervals, each with a spatial resolution of 512x512x256 grid points. Four flow variables are associated with each snapshot: the three velocity components (u,v,w) and the perturbed density field (rho) away from the background gradient. All fields are stored in binary format (32-bit little-endian), each with a size of 255 MB, yielding a total dataset size of 15.3 TB. Further details are referenced in the attached README file, and a current list of publications and associated analysis tools are provided at https://stratified-turbulence.github.io/web/.

42 ENGINEERING↗

SST-TG-P50F4R3200: Decaying Stably-Stratified Turbulence (SST), Initialized Using Taylor-Green Vortices (TG) at Prandtl Number Pr=50, Froude Number Fr=4, Reynolds Number Re=3200

This dataset comprises direct numerical simulations (DNS) of decaying stably-stratified turbulence influenced by a linear background density gradient, initialized using an array of Taylor-Green vortices, extending the Pr=1 simulations performed in [Riley and de Bruyn Kops (2003)](https://doi.org/10.1063/1.1578077). The initial Prandtl, Froude, and Reynolds numbers are (Pr, Fr, Re) = (50, 4, 3200). A total of 1,680 snapshots are recorded at uniform time intervals, each with a spatial resolution of 3584x3584x1792 grid points. Four flow variables are associated with each snapshot: the three velocity components (u,v,w) and the perturbed density field (rho) away from the background gradient. All fields are stored in binary format (32-bit little-endian), each with a size of 85.8 GB, yielding a total dataset size of 577 TB. Further details are referenced in the attached README file, and a current list of publications and associated analysis tools are provided at https://stratified-turbulence.github.io/web/.

42 ENGINEERING↗

SST-TG-P7F4R3200: Decaying Stably-Stratified Turbulence (SST), Initialized Using Taylor-Green Vortices (TG) at Prandtl Number Pr=7, Froude Number Fr=4, Reynolds Number Re=3200

This dataset comprises direct numerical simulations (DNS) of decaying stably-stratified turbulence influenced by a linear background density gradient, initialized using an array of Taylor-Green vortices, extending the Pr=1 simulations performed in [Riley and de Bruyn Kops (2003)](https://doi.org/10.1063/1.1578077). The initial Prandtl, Froude, and Reynolds numbers are (Pr, Fr, Re) = (7, 4, 3200). A total of 15,250 snapshots are recorded at uniform time intervals, each with a spatial resolution of 1280x1280x640 grid points. Four flow variables are associated with each snapshot: the three velocity components (u,v,w) and the perturbed density field (rho) away from the background gradient. All fields are stored in binary format (32-bit little-endian), each with a size of 4 GB, yielding a total dataset size of 244 TB. Further details are referenced in the attached README file, and a current list of publications and associated analysis tools are provided at https://stratified-turbulence.github.io/web/.

42 ENGINEERING↗

Controller area network decoder (CAN-D)

A system and method for decoding an unknown automotive controller area network (“CAN”) message definitions. CAN data vehicle signal mappings are typically held in secret and varied by automotive model and year. Without knowledge of the mappings, the wealth of real-time vehicle data hidden in the automotive CAN packets is uninterpretable—impeding research, after-market tuning, efficiency and performance monitoring, fault diagnosis, and privacy-related technologies. This technology can ascertain the CAN signals' boundaries (start bit and length), endianness (byte ordering), signedness (binary-to-integer encoding) from raw CAN data. This allows conversion of CAN data to time series. Interpreting the translated CAN data's physical meaning and finding a linear mapping to standard units (e.g., knowing the signal is speed and scaling values to represent units of miles per hour) can be achieved for many signals by leveraging diagnostic standards to obtain real-time measurements of in-vehicle systems. The system and method can be integrated into lightweight hardware enabling an OBD-II plugin for real-time in-vehicle CAN decoding or run on standard computers. The system can output a standard DBC file with the signal definition information.

Verma, Kiren E.↗

Forensic Analysis of SOHO Router Binaries

Small Office/Home Office (SOHO) routers are used by millions of consumers across the United States, and are commensurately vulnerable. Forensic analysis of SOHO router firmware helps to understand and mitigate those vulnerabilities. This poster focused particularly on analysis of BusyBox executables, a software suite that provides several Unix utilities in a single file. Three main tools were used to analyze the binaries. BinWalk was used to extract the files, but also to build entropy graphs, extract Linux kernel images, and identify CPU architectures; WiiBin processed the binaries to find endianness, architecture, the percent compressed/encrypted, and compiler data; and @DisCo, a machine learning tool used to determine function similarity in disassembled binaries, analyzed similarities and determined versions of extracted BusyBox files from each router. These tools found that venders from all five routers utilized the same version of the BusyBox software across different firmware updates, demonstrating the importance of constant firmware scrutiny to protect against security vulnerabilities.

24 POWER TRANSMISSION AND DISTRIBUTION↗

System for controller area network payload decoding

A system for decoding an unknown automotive controller area network (“CAN”) message definitions. CAN data vehicle signal mappings are typically held in secret and varied by automotive model and year. Without knowledge of the mappings, the wealth of real-time vehicle data hidden in the automotive CAN packets is uninterpretable—impeding research, after-market tuning, efficiency and performance monitoring, fault diagnosis, and privacy-related technologies. This system can ascertain the CAN signals' boundaries (start bit and length), endianness (byte ordering), signedness (binary-to-integer encoding) from raw CAN data. This allows conversion of CAN data to time series. Interpreting the translated CAN data's physical meaning and finding a linear mapping to standard units (e.g., knowing the signal is speed and scaling values to represent units of miles per hour) can be achieved for many signals by leveraging diagnostic standards to obtain real-time measurements of in-vehicle systems. The system can be integrated into lightweight hardware enabling an OBD-II plugin for real-time in-vehicle CAN decoding or run on standard computers. The system can output a standard DBC file with the signal definition information.

Verma, Kiren E.↗

Binary Analysis with Architecture and Code Section Detection using Supervised Machine Learning

When presented with an unknown binary, which may or may not be complete, having the ability to determine information about it is critical to future reverse engineering, particularly in discovering the binary’s intended use and potentially malicious nature. This paper details techniques to both identify the machine architecture of the binary, as well as to locate the important code segments within the file. This identification of unknown binaries makes use of a technique called byte histogram in addition to various machine learning (ML) techniques, which we call “What is it Binary” or WiiBin. Benefits of byte histograms reflect the simplicity of calculation and do not rely on file headers or metadata, allowing for acceptable results when only a small portion of the original file is available. Utilizing WiiBin, we were able to accurately (>80%) determine the architecture of test binaries with as little as a 20% contagious portion of the file present. We were also able to determine the location of code sections within a binary by utilizing the WiiBin framework. Ultimately, the more information that can be gleaned from a binary file, the easier it is to successfully reverse engineer.

99 GENERAL AND MISCELLANEOUS↗