Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Connected Cars Moving Targets for Hackers

As cars evolve into rolling mobile computers, the potential for disastrous cyber attacks has become a new road hazard.

Israeli cybersecurity firm GuardKnox demonstrated the threat in a Formula 1 driving simulation at the Consumer Electronics show this week in Las Vegas.

As cars evolve into rolling mobile computers, the potential for disastrous cyber attacks has become a new road hazard.

Israeli cybersecurity firm GuardKnox demonstrated the threat in a Formula 1 driving simulation at the Consumer Electronics show this week in Las Vegas.

Moments into the virtual drive, a GuardKnox engineer playing the role of hacker struck and the steering wheel no longer controlled the speeding car.

The faux race was over for the driver, stuck on the side of the road in a scenario that cybersecurity specialists say could become very real.

New car models are packed with computer chips, sensors and mobile technology that hackers could exploit to sabotage systems or commandeer controls.

Opportunities for attacks are being revved up by the trend of self-driving, electric cars communicating in real-time with the cloud, smart city infrastructures, and one another.

GuardKnox chief executive Moshe Shlisel gave an example of a hacker remotely taking control of a fuel tanker truck, sending it to crash into a building.

“It’s September 11 on wheels,” Shlisel said in an interview at CES.

Advertisement. Scroll to continue reading.

Cybersecurity has become as integral to vehicle engineering as crash safety and fuel efficiency, according to Henry Bzeih, a former member of the Council for Automobile Cybersecurity, who spoke at the Las Vegas event.

“Connectivity is the reason why this is happening,” Bzeih said.

“Now, all elements have to be designed with cybersecurity in mind.”

– ‘Anything is possible’ –

Israeli startup Upstream logged more than 150 cybersecurity incidents involving automobiles last year, twice as many as in 2018.

The majority of those hacks involve remotely car door locks, but an increasing number targeted software applications or connections to the cloud.

Last year in Chicago, dozens of luxury cars were stolen by hacking Daimler’s Car2Go app.

“The ultimate worst-case scenario would be if somebody applies one of the car functions when it’s not supposed to do that, and does that across multiple vehicles,” said Upstream vice president Dan Sahar.

“For example, someone hits the brakes on all vehicles of a specific model at the same time. That would be catastrophic.”

Since cars in model lines share engineering specifications, they share system vulnerabilities by design.

“If you can design an attack and execute it on a computer, and that computer is attached to a car, anything is possible,” said Ralph Echemendia, expert in cybersecurity and self-described “ethical hacker.”

Five years ago, a pair of cybersecurity researches remotely commandeered the controls of a Jeep Cherokee by taking advantage of a vulnerability in its infotainment system, triggering a recall of vehicles.

– Never-ending battle –

Carmakers have responded to the menace by offering bounties for vulnerabilities found by researchers and paying partners to build security into components.

Upstream collects data shared to the cloud by vehicles, scouring it in real time for strange activity that could signal hackers are up to no good.

GuardKnox engineers drew on their experience in the Israeli air force to design a processor that protects computers in vehicles and also serves as a secure operating system.

As in the world of smartphones and desktop computing, hackers relentlessly seek ways to infiltrate new software or features in automobiles in an ever-escalating battle with defenders.

RelatedConnected Cars Could be a Threat to National Security, Group Claims

Related: Flaws in Smart Alarms Exposed Millions of Cars to Dangerous Hacking

Related: Senators Question NHTSA on Risks of Connected Vehicles

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.

IoT Security

An innocent-looking portable speaker can hide a hacking device that launches CAN injection attacks, which have been used to steal cars.

ICS/OT

The overall effect of current global geopolitical conditions is that nation states have a greater incentive to target the ICS/OT of critical industries, while...

CISO Strategy

Cybersecurity-related risk is a top concern, so boards need to know they have the proper oversight in place. Even as first-timers, successful CISOs make...

ICS/OT

Municipal Water Authority of Aliquippa in Pennsylvania confirms that hackers took control of a booster station, but says no risk to drinking water or...

ICS/OT

Mandiant's Chief analyst urges critical infrastructure defenders to work on finding and removing traces of Volt Typhoon, a Chinese government-backed hacking team caught in...