1
00:00:03,300 --> 00:00:03,951
CanLab.

2
00:00:03,951 --> 00:00:09,159
A desktop workstation for reverse-engineering a CAN bus.

3
00:00:09,159 --> 00:00:12,972
Here is a tour of it, on real recordings.

4
00:00:14,317 --> 00:00:19,946
This is a real recording from a CANedge logger, loaded
straight from its MDF four file:

5
00:00:19,946 --> 00:00:24,475
nine thousand six hundred frames across fifty arbitration
identifiers,

6
00:00:24,475 --> 00:00:27,257
every one of them twenty-nine bit extended.

7
00:00:27,257 --> 00:00:31,333
Nothing here was simulated and nothing was labelled in
advance.

8
00:00:32,283 --> 00:00:37,123
The work is grouped into five workspaces rather than sixteen
tabs in a row.

9
00:00:37,123 --> 00:00:41,770
Capture is what is on the wire, Explore is what it looks like
over time,

10
00:00:41,770 --> 00:00:47,255
Detect is the automatic analysis, Define is where you write
down what you worked out,

11
00:00:47,255 --> 00:00:49,707
and Bus is everything that talks back.

12
00:00:50,650 --> 00:00:53,236
First question on an unknown bus:

13
00:00:53,236 --> 00:00:54,098
what is it.

14
00:00:54,098 --> 00:00:59,036
Twenty-nine bit identifiers usually mean a truck running
J1939,

15
00:00:59,036 --> 00:01:06,481
but these carry data page one in the hundred and twenty-six
thousand range, which is NMEA 2000.

16
00:01:06,481 --> 00:01:07,656
This is a boat.

17
00:01:07,656 --> 00:01:12,202
Vessel heading, rate of turn, wind, satellite positioning.

18
00:01:13,150 --> 00:01:19,022
Which the decoded fields then confirm, from two messages that
have no reason to agree unless

19
00:01:19,022 --> 00:01:20,426
the layouts are right.

20
00:01:20,426 --> 00:01:26,107
Position puts the vessel at forty-two point six six north,
eighty-one point two one west,

21
00:01:26,107 --> 00:01:27,320
which is Lake Erie.

22
00:01:27,320 --> 00:01:30,065
Heading reads one point nine eight radians,

23
00:01:30,065 --> 00:01:35,362
and the magnetic variation beside it reads nought point one
five five radians west,

24
00:01:35,362 --> 00:01:37,533
which is eight point nine degrees:

25
00:01:37,533 --> 00:01:39,958
the published value for exactly there.

26
00:01:40,917 --> 00:01:46,400
The frames table is a log, which is the wrong shape for the
question you ask at the bench.

27
00:01:46,400 --> 00:01:49,629
The sniffer collapses the bus to one row per message:

28
00:01:49,629 --> 00:01:55,173
a byte turns green when it rises and red when it falls, and
bytes that never move stay dim.

29
00:01:56,117 --> 00:01:58,125
Notch is why this beats scrolling.

30
00:01:58,125 --> 00:02:02,495
It records every bit that is moving right now and ignores it
from then on,

31
00:02:02,495 --> 00:02:08,165
so the counters that never stop go quiet and the next thing
that lights up is the thing you did.

32
00:02:09,117 --> 00:02:14,421
One press masked four hundred and sixty four bits of steady
traffic on this log.

33
00:02:15,383 --> 00:02:19,409
The detectors run with no knowledge of the protocol at all.

34
00:02:19,409 --> 00:02:24,186
Here they find twenty-four counter bytes across twenty-three
messages,

35
00:02:24,186 --> 00:02:30,600
twenty-one of them in byte zero, and on five of those the
count wraps at two hundred and fifty

36
00:02:30,600 --> 00:02:30,873
one.

37
00:02:30,873 --> 00:02:35,923
NMEA 2000 calls byte zero the sequence identifier and
specifies that wrap.

38
00:02:35,923 --> 00:02:38,447
The detector got there from the data.

39
00:02:39,383 --> 00:02:43,635
Entropy per bit finds where one field ends and the next
begins.

40
00:02:43,635 --> 00:02:50,046
Each candidate boundary carries a confidence, which is a match
fraction over the frames loaded,

41
00:02:50,046 --> 00:02:50,855
not a proof.

42
00:02:51,817 --> 00:02:55,427
A signal is a message, a start bit, a length and a scale.

43
00:02:55,427 --> 00:02:59,671
The preview decodes real frames through the definition as you
type,

44
00:02:59,671 --> 00:03:04,041
so it is checked against the bus rather than against your
arithmetic.

45
00:03:04,041 --> 00:03:06,764
Nought point seven seven metres per second:

46
00:03:06,764 --> 00:03:10,945
light air, which is what a moored boat on a calm lake should
read.

47
00:03:11,883 --> 00:03:14,216
Drag across the grid to claim bits.

48
00:03:14,216 --> 00:03:20,479
Motorola byte order and non-contiguous layouts go through the
same coordinate map the exporter

49
00:03:20,479 --> 00:03:23,811
uses, so what you select is what gets written out.

50
00:03:24,750 --> 00:03:28,938
Plotted against time is where a definition is confirmed or
refuted.

51
00:03:28,938 --> 00:03:32,376
Both traces are the same two bytes of the same message.

52
00:03:32,376 --> 00:03:38,127
The upper one reads them little-endian and wanders between
nought point seven two and nought

53
00:03:38,127 --> 00:03:40,378
point eight seven metres per second.

54
00:03:40,378 --> 00:03:46,191
The lower one reads them the other way round and swings
between a hundred and eighty four and

55
00:03:46,191 --> 00:03:48,004
two hundred and twenty three.

56
00:03:48,004 --> 00:03:51,942
You do not need the spec to see which of those is a wind
speed.

57
00:03:52,883 --> 00:03:57,327
Everything that can put a frame on a wire is behind one gate.

58
00:03:57,327 --> 00:04:02,135
ARM TX is off by default and it covers injection, replay,
fuzzing,

59
00:04:02,135 --> 00:04:05,631
gateway forwarding and every diagnostic request.

60
00:04:05,631 --> 00:04:09,419
Disarming stops a running worker within two seconds.

61
00:04:10,383 --> 00:04:14,110
Before any of that, the page shows the frame it would send.

62
00:04:14,110 --> 00:04:19,100
Byte one holds four D, which is seventy-seven hundredths of a
metre per second,

63
00:04:19,100 --> 00:04:22,195
and the bytes the signal does not touch stay dim.

64
00:04:22,195 --> 00:04:27,879
If the vehicle profile writes a counter or a checksum, the
bytes it overwrites turn amber.

65
00:04:28,817 --> 00:04:31,506
The controls themselves are three rows:

66
00:04:31,506 --> 00:04:34,265
which signal, what value, and how often.

67
00:04:34,265 --> 00:04:37,852
The slider spans whatever range the signal declares,

68
00:04:37,852 --> 00:04:41,921
and every send lands in the log underneath with its result.

69
00:04:42,883 --> 00:04:44,950
Three things can run alongside:

70
00:04:44,950 --> 00:04:50,882
a REST API, an MCP server that lets an assistant drive the
analysis, and the plugin list.

71
00:04:50,882 --> 00:04:54,415
None of the twenty-five assistant tools can transmit;

72
00:04:54,415 --> 00:04:59,347
putting frames on a wire stays behind the gate where a person
is watching.

73
00:05:00,283 --> 00:05:02,028
Hardware is picked here.

74
00:05:02,028 --> 00:05:05,664
Every python-can backend is available, plus GVRET,

75
00:05:05,664 --> 00:05:09,809
which CanLab adds itself for the boards SavvyCAN runs on.

76
00:05:09,809 --> 00:05:16,498
Detect finds what is plugged in, and Test opens the adapter
and listens for a second without

77
00:05:16,498 --> 00:05:17,443
transmitting.

78
00:05:18,383 --> 00:05:21,965
A second recording, and a different vehicle entirely:

79
00:05:21,965 --> 00:05:25,682
twenty-three minutes off a car, eleven bit identifiers,

80
00:05:25,682 --> 00:05:28,453
a hundred and fifty five thousand frames.

81
00:05:28,453 --> 00:05:32,981
One identifier carries a hundred and thirty three thousand of
them.

82
00:05:32,981 --> 00:05:37,847
The sniffer folds the whole capture into sixteen rows in under
a second.

83
00:05:38,783 --> 00:05:42,962
Load a capture, work out what the bytes carry, write it down,

84
00:05:42,962 --> 00:05:45,565
and export a DBC other tools can read.

85
00:05:45,565 --> 00:05:51,935
Everything shown here ran against real recordings from
hardware this project did not produce.

86
00:05:53,533 --> 00:05:56,829
CanLab is open source, under the MIT licence.

87
00:05:56,829 --> 00:06:03,421
The source and the Linux build are on GitHub, and the
documentation is at the second link.
