IoT
11/10/2017
02:50 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

FASTR consortium announces release of 'Automotive Industry Guidelines for Secure Over-the-Air Updates'

Document provides evaluators with comprehensive, objective guidelines by which to analyze automotive software over-the-air (SOTA) update systems

WILMINGTON, Del. (Nov. 8, 2017) – FASTRSM, a nonprofit research consortium dedicated to automotive cybersecurity, today announced the availability of “Automotive Industry Guidelines for Secure Over-the-Air Updates.”

The guidelines are intended to assist automotive manufacturers and others involved in evaluating platforms for secure updates, describing the threat models, providing recommended cryptographic algorithms and detailing a step-by-step checklist for evaluating SOTA systems.The documentilluminates one area of opportunity for research and innovation in the automotive security ecosystem.

“Today’s modern automotive ecosystem requires a robust, adaptable approach to maintain the security and integrity of the growing intelligently connected vehicles on the roads. Provenance and operational verification of software components in a forensically sound manner is critical,” said Craig Hurst, FASTR executive director. “These guidelines will serve as a comprehensive, objective resource to help OEMs analyze SOTA systems and make wise design choices.”

Founded by Aeris, Intel and Uber in 2016, FASTR seeks to accelerate automotive security by marshaling industry-wide collaboration on crucially needed research. To become a member of FASTR, get involved and lend expertise to plans for 2018 activities, go to https://fastr.org/membership/.

 

About FASTR

FASTR—Future of Automotive Security Technology Research—is a neutral nonprofit automotive security research consortium working to drive systematic coordination of cybersecurity across the entire supply chain and ensure trust in the connected and autonomous vehicle of the future. For more information, please visit fastr.org

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Who Takes Responsibility for Cyberattacks in the Cloud?
Kelly Sheridan, Staff Editor, Dark Reading,  1/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: On the SS7 network, nobody knows you're a dog.
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18812
PUBLISHED: 2019-01-16
The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability that might theoretically fail to restrict users with read-only access from modifying files stored in the Spotfire Library, only when the S...
CVE-2018-18813
PUBLISHED: 2019-01-16
The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent and reflected cross-site scripting attacks. Affected releases are TIBCO Software Inc. TIBCO Spotfire...
CVE-2018-18814
PUBLISHED: 2019-01-16
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the authentication that theoretically may allow an attacker to gain full access to a target account, indep...
CVE-2018-5740
PUBLISHED: 2019-01-16
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is i...
CVE-2018-5741
PUBLISHED: 2019-01-16
To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update ...