Automotive cyber security: Keeping hackers out of cars – Lowell Sun Online

Automotive cyber security: Keeping hackers out of cars

Cyber security is becoming increasingly significant, whether you are a politician, surfing your private laptop or smartphone, or driving your car.

Now that vehicles are turning into computers with steering wheels and tires, hacking into them to cause accidents is a real threat. But there are real computer geeks working to prevent it.

“Attacks will get lighter and more profitable unless we take steps now to make to make it tighter,” Justin Cappos tells me as he explains a fresh cyber security program called Uptane, designed to identify and kill vehicle software bugs before the bad guys can exploit them.

Cappos is an assistant professor of systems and security at Fresh York University’s Tandon School of Engineering. He’s part of a team of 30-somethings working with software and vehicle manufacturers to prevent hackers from disabling your steering or brakes, locking you out of or inwards your vehicle until you pay a ransom, or stealing your identity through the apps and emails you link to your vehicle’s infotainment system.

NYU has partnered with the University of Michigan Transportation Research Institute on the Uptane security system, which is being suggested free to any vehicle-related company. Its creators also are inviting hackers to attempt to break the codes, as a way of identifying flaws. What?

You may reminisce latest headlines when hackers broke into a two thousand fourteen Jeep Cherokee and remotely disabled it while it was driving in traffic.

“We want hackers to look at what we are doing and help us find and fix issues before they influence lives,” Cappos tells me. He is deadly serious (pardon the pun) when he contemplates hundreds of deaths because hackers disconnect steering or braking across a manufacturer’s model line or entire model year.

Automotive cyber security also involves financial security, via the cyber version of corporate espionage. Consider these screenplays: a rental car or trucking company disables the vehicles of its competitors to put them out of business, or cyber criminals cause enough accidents in vehicles of one manufacturer that their sales and stock price drop.

Cappos explains that there are as many as one hundred lil’ computers in today’s vehicles, from ones controlling cabin climate and the pre-tensioner in your seatbelt to the one with as many as a million lines of code driving your infotainment and navigation system. That’s more than the F-22 Raptor, one of the most high-tech military aircraft in use today, according to Industrial Safety and Security Source.

They all communicate with one another, so the brakes know you’ve engaged cruise control, the rear-view cameras know you’re backing up out of the driveway, and so on. Also, the computers communicate with outward sources, like Bluetooth and GPS. Every one of those connections has hidden dangers that can occur whenever software is updated. Updates, he explains, tell hackers where the vulnerabilities are, since updates are designed to fix them.

A big problem with automotive cyber security is that vehicle manufacturers generally use the same software, from tip-of-the-tongue suppliers such as Google and Microsoft to smaller tech companies such as Docker, Fedora, Apache, and GitHub. That means hacker-prone glitches also are collective by many vehicle manufacturers.

So one of the Uptane solutions is a “dual key” security control. Think of it as similar to the nuclear launch codes, which require two operators to throw the switches, or turn the keys, at the same time. Uptane’s automotive cyber security version requires switches to codes from two different software providers at the same time, making it that much stiffer for hackers.

Cappos says he wants to make automotive hacking a “moving target.” In the meantime, he proceeds to drive his beloved one thousand nine hundred seventy seven Chevy Corvette, a purely mechanical car model with no computers. He admits with a smile that he has a higher risk of an accident, because it has no high-tech safety systems like lane-departure warning and adaptive cruise control, but a lower risk of being hacked.

Related movie:

Leave a Reply

Your email address will not be published. Required fields are marked *