/* ---- Google Analytics Code Below */
Showing posts with label Vehicle Hacking. Show all posts
Showing posts with label Vehicle Hacking. Show all posts

Thursday, July 08, 2021

Automotive Cybersecurity

Vehicles in particular will require specialized cybersecurity as their autonomy increases.

Keeping Control of the Wheel   By David Geer   in ACM

The rising need for cybersecurity will trigger investments over the next few years. We expect to see the market grow from US$4.9 billion in 2020 to US$9.7 billion in 2030, with software business representing half of the market by 2030," according to "Cybersecurity in automotive: Mastering the challenge," a 2020 market study by global management consulting firm McKinsey & Company.

The study "Automotive Cybersecurity Market: the Development of Autonomous Cars and Other Notable Growth Drivers," by market intelligence firm Infinity Research, identifies the market forces advancing automotive cybersecurity as including:

The development of autonomous vehicles with wireless connections.

The increasing number of in-vehicle electronic control units and their wireless connections.

Regulatory mandates and standards targeting the cyber-safety of vehicles and data .

Nobody wants criminal hackers in the driver's seat. "Much of the motivation to implement enhanced security systems stems from advances in in-vehicle capabilities. Progress in these internal capabilities includes Advanced Driver Assistance Systems (ADAS). These systems necessitate heightened computer control over sensitive actuators (drive by wire, including steer by wire, throttle by wire, and brake by wire)," says Josh Siegel, assistant professor of computer science and engineering at Michigan State University (MSU).

According to the 2021 HSB Cyber Car Tech Survey by cyber risk insurer HSB Group, more than a third of U.S. consumers say they are concerned about the cybersecurity of connected cars. Another third say they fear a computer virus, hacking incident, or other cyberattack that could damage or destroy their vehicle's data, software, or operating systems.

To MSU's Siegel, growing hacker expertise suggests automotive cyberattacks are unleashed by criminal hackers with malicious intent, and not just discovered by researchers to bring vulnerabilities to light. There have been targeted hacks turning vehicles into espionage devices at military bases and disabling engines, so the individual has to take other transportation to work, says Siegel. "I assume that nation-states or well-resourced entities are executing these attacks," says Siegel.

The 2021 Global Automotive Cybersecurity Report by connected vehicle cybersecurity provider Upstream Security, found that malicious blackhat hackers last year carried out 55% of automotive cyberhacks to disrupt business, steal property, and demand ransom. Whitehat hackers and researchers, including those participating in automotive bug bounty programs, performed 38.6% of hacks, the report says. Bug Bounty programs pay white hat hackers a reward or "bounty" for finding critical vulnerabilities in an organization's software.  ... '

Tuesday, May 04, 2021

Tesla Hacked from Drone without a Click

But, It is stated that you cannot get driving control of the car from the hack.

Tesla Car Hacked Remotely From Drone via Zero-Click Exploit

By Eduard Kovacs   in SecurityWeek   Via piece in Schneier  (Which often will contain thoughtful comments) 

Two researchers have shown how a Tesla — and possibly other cars — can be hacked remotely without any user interaction. They carried out the attack from a drone.

This was the result of research conducted last year by Ralf-Philipp Weinmann of Kunnamon and Benedikt Schmotzle of Comsecuris. The analysis was initially carried out for the Pwn2Own 2020 hacking competition — the contest offered a car and other significant prizes for hacking a Tesla — but the findings were later reported to Tesla through its bug bounty program after Pwn2Own organizers decided to temporarily eliminate the automotive category due to the coronavirus pandemic.

The attack, dubbed TBONE, involves exploitation of two vulnerabilities affecting ConnMan, an internet connection manager for embedded devices. An attacker can exploit these flaws to take full control of the infotainment system of a Tesla without any user interaction.  ... 

Monday, December 23, 2019

Vehicle Hacking Spreads

Increasing amount of vehicle hacking is occuring.  Note the increasing ability to effect these cybercrimes remotely.    Some telling statistics.

New Study Shows Just How Bad Vehicle Hacking Has Gotten
in CNet   By Kyle Hyatt
December 18, 2019

A new report from Israeli security firm Upstream.auto has painted a grim picture of the state of vehicular cybersecurity. Automobiles have not been immune to the tsunami of Internet-connected upgrades that has swept through everyday life in recent times. The increased connectivity has made life easier, but it has also opened up more opportunities for hackers scheming to seize unauthorized control of automobiles. According to Upstream, there were 150 cases of vehicle hacking in 2019, a 99% increase from 2018. Moreover, the auto industry has experienced 94% year-over-year growth in hacks since 2016. Car manufacturers have turned to white hat hackers and bug bounty programs to expose flaws before malicious actors can exploit them, but bad actors are still responsible for 57% of cybersecurity incidents in the auto industry. About 82% of the hacks are done remotely, an alarming indication that hackers are capable of breaking into cars from the comfort of their own homes. .... "