IoT
11/10/2017
02:50 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

FASTR consortium announces release of 'Automotive Industry Guidelines for Secure Over-the-Air Updates'

Document provides evaluators with comprehensive, objective guidelines by which to analyze automotive software over-the-air (SOTA) update systems

WILMINGTON, Del. (Nov. 8, 2017) – FASTRSM, a nonprofit research consortium dedicated to automotive cybersecurity, today announced the availability of “Automotive Industry Guidelines for Secure Over-the-Air Updates.”

The guidelines are intended to assist automotive manufacturers and others involved in evaluating platforms for secure updates, describing the threat models, providing recommended cryptographic algorithms and detailing a step-by-step checklist for evaluating SOTA systems.The documentilluminates one area of opportunity for research and innovation in the automotive security ecosystem.

“Today’s modern automotive ecosystem requires a robust, adaptable approach to maintain the security and integrity of the growing intelligently connected vehicles on the roads. Provenance and operational verification of software components in a forensically sound manner is critical,” said Craig Hurst, FASTR executive director. “These guidelines will serve as a comprehensive, objective resource to help OEMs analyze SOTA systems and make wise design choices.”

Founded by Aeris, Intel and Uber in 2016, FASTR seeks to accelerate automotive security by marshaling industry-wide collaboration on crucially needed research. To become a member of FASTR, get involved and lend expertise to plans for 2018 activities, go to https://fastr.org/membership/.

 

About FASTR

FASTR—Future of Automotive Security Technology Research—is a neutral nonprofit automotive security research consortium working to drive systematic coordination of cybersecurity across the entire supply chain and ensure trust in the connected and autonomous vehicle of the future. For more information, please visit fastr.org

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3483
PUBLISHED: 2019-03-25
Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3484
PUBLISHED: 2019-03-25
Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2019-6240
PUBLISHED: 2019-03-25
An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.
CVE-2015-3953
PUBLISHED: 2019-03-25
Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospi...
CVE-2015-3954
PUBLISHED: 2019-03-25
Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior give unauthenticated users root privileges on Port 23/TELNET by default. An unauthorized user could issue commands to the pump. Hospira recommen...