Risk
5/16/2010
09:39 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Automobiles Growing Vulnerable To Hacks

Carmakers are rolling automobiles off the assembly line with plenty of fancy new high-tech features. Unfortunately, security is -- once again -- treated as an afterthought.

Carmakers are rolling automobiles off the assembly line with plenty of fancy new high-tech features. Unfortunately, security is -- once again -- treated as an afterthought.

Modern automobiles are no longer mere mechanical devices; they are pervasively monitored and controlled by dozens of digital computers coordinated via internal vehicular networks. While this transformation has driven major advancements in efficiency and safety, it has also introduced a range of new potential risks.

So starts the research report, Experimental Security Analysis of a Modern Automobile, published by a team of IT security researchers from the University of California, San Diego and the University of Washington.

Anyone who is interested in the security of information systems might want to give this paper a read. Although those who have been following the security of IT infrastructure and PCs during the past fifteen years may be struck with an eerie feeling of Déjà Vu.

Just as PCs became increasingly networked in the 1990s, and operating systems were crammed with new features, security risks also increased. And when PCs and LANs were connected to the Internet: those risks went parabolic. There wasn't much attention paid to how adversaries - virus writers, curiosity seeking hackers, and outright criminals would use systems to snoop, disrupt, and destroy.

It seems carmakers may be repeating the mistakes of the IT industry, according to the report:

The attack surface for modern automobiles is growing swiftly as more sophisticated services and communications features are incorporated intovehicles. In the United States, the federally-mandated On-Board Diagnostics (OBD-II) port, under the dash in virtuallyall modern vehicles, provides direct and standard access to internal automotive networks. User-upgradable subsystems such as audio players are routinely attached to these same internal networks, as are a variety of shortrange wireless devices (Bluetooth, wireless tire pressure sensors, etc.). Telematics systems, exemplified by General Motors' (GM's) OnStar, provide value-added features such as automatic crash response, remote diagnostics, and stolen vehicle recovery over a long-range wireless link. To do so, these telematics systems integrate internal automotive subsystems with a remote command center via a wide area cellular connection. Some have taken this concept even further-proposing a "car as a platform" model for third-party development.

The researchers found that attackers can grab control of a range of functions of the car, and override driver input, such as disabling breaks and even stopping the engine. Here's what one of the researchers had to say to The New York Times regarding their research:

"We noticed the extent to which automobiles were becoming computerized," said Stefan Savage, a computer scientist at U.C.S.D. who was a member of one of two groups that have been studying the electronic control units of two different cars to look for network vulnerabilities that could be exploited by a potential attacker. "We found ourselves thinking we should try to get in front of this before it suddenly becomes an issue."

Many of the vulnerabilities of automotive systems that make attacks possible will sound familiar to IT security professionals such: poor authentication, weak access control, and poor challenge-response mechanisms to protect against unauthorized system tampering.

Hopefully it's not too late for car manufacturers to (at least) bring the same level of engineering scrutiny to software aspects of their products as they do the mechanical. Because it's one thing to tolerate shoddy software engineering (now, that's an oxymoron isn't it) within PC and enterprise applications: it's a number of magnitudes greater to have to worry about attackers gaining control of any aspect of your vehicle while cruising down the highway.

For my security and technology observations throughout the day consider following me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2004-2771
Published: 2014-12-24
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

CVE-2014-3569
Published: 2014-12-24
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshak...

CVE-2014-4322
Published: 2014-12-24
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call, which allows attackers to gain privileges or c...

CVE-2014-6132
Published: 2014-12-24
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML vi...

CVE-2014-6153
Published: 2014-12-24
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.