Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

3/7/2016
04:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Automakers In The Hotseat For Vehicle Cybersecurity

Car cybersecurity one to three years behind threats, as drivers look to automakers to secure vehicles from hacking.

As new-model vehicles increasingly come equipped with third-party applications and Internet connectivity, the majority of consumers say the car manufacturers are liable for the safety and security of their cars.

A pair of separate studies released last week at the RSA Conference in San Francisco shed light on the escalating pressures on automakers to address cybesecurity of their vehicles – even though many of the new software and connectivity features come from their third-party suppliers and cellular providers.

Nearly 90% of drivers in an IDC and Veracode study said car manufacturers should be responsible for locking down the cybersecurity and related safety issues of the vehicles, even if the car’s apps were created by a separate software company.

Kelley Blue Book found in its survey that more than 55% of drivers consider carmakers responsible for providing security software to protect cars from being hacked, and 44% say carmakers hold the most responsibility for securing a car, while two-thirds believe carmakers are partially responsible for car hacks. Half of consumers say carmakers should provide insurance for car-hacking losses.

“Whenever you have a supply chain and the more complicated it is, and the more individual pieces it has, the more difficult it is to do security,” says Chris Wysopal, CTO and co-founder of Veracode. “There are so many different parties involved: infotainment, connectivity, and they’re going with someone else to do the OS, like Apple Car Play, for example. Ford and Toyota are going with their own OSes. Who’s building the apps? [Likely] a third party.”

Wyospal says the software security issues with a traditional complex enterprise supply chain is challenging enough. This model for car comes with physical safety ramifications as well.

“Why the stakes are higher, and we should not replicate all [that was] done with enterprise security,” he says.

IDC and Veracode also surveyed and interviewed Bosh, Delphi, Fiat-Chrysler, Scania, Seat, and ADAC, Germany’s automotive industry association. The European carmakers say it will take one to three years for them to catch up with cybersecurity threats, and they all say they are concerned about the security of their “critical systems” amid the emergence of third-party apps in the car. Their worry is that vehicle safety would be out of the manufacturer’s control with these apps in play.

Veracode’s Wysopal thinks one year may be too optimistic, given the complicated mesh of suppliers for connected cars. And even the conventional wisdom calling for the car’s features to run on a different and air gapped network from the infotainment system and apps isn’t realistic today. “The software is intermingled” via the same user interface as car features, he says. “An airgap isn’t going to work. So you have to think: is there a certain class of app that gets more rigorous testing, is certified” and can’t communicate directly with the car’s performance systems. This needs to be thought through.”

The IDC-Veracode report points to how Tesla allows Internet-based software updates to its performance elements of the vehicle rather than updating software when the driver takes his vehicle in for maintenance.

Traditional automakers also are starting to beef up their cybersecurity profiles. General Motors now has a bug bounty program underway as well as a product security officer position. “Those all seem like steps in the right direction, that they get it: they are becoming a software company,” Wysopal says. “Security and software are coming to their business and they have to organize that way.”

“For at least three years they are going to have to deal with in-bound vulns at a rate higher than today and have to respond to them,” says Wysopal.

“Manufacturers cannot afford to be complacent when it comes to application and overall system security within vehicles,” said Duncan Brown, research director at IDC’s European Security Practice. “Manufacturers should increase their focus on how to secure applications that enhance car functionality, such as the many driving aids currently being developed.”

Millennials, meanwhile, are less likely to consider car hacking a big problem: about half say it will be a frequent issue in the next three years, while 70% of all respondents say so.

 

Related Content:

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.