Showing posts with label cars. Show all posts
Showing posts with label cars. Show all posts

Friday, March 18, 2016

FBI issues PSA on cars' cybersecurity citing work by Jacobs School researchers

Last summer, computer scientists at the Jacobs School demonstrated that they could wirelessly control thousands of vehicles via a gadget that's often used by insurance companies to monitor cars. The team, led by Professor Stefan Savage, has worked to raise awareness of flaws in the cybersecurity of cars since 2010.

On March 17, the Federal Bureau of Investigation issued a public service announcement titled "Motor Vehicles Increasingly Vulnerable to Remote Exploits," which alludes to the researchers' work:
As previously reported by the media in and after July 2015, security researchers evaluating automotive cybersecurity were able to demonstrate remote exploits of motor vehicles. The analysis demonstrated the researchers could gain significant control over vehicle functions remotely by exploiting wireless communications vulnerabilities. While the identified vulnerabilities have been addressed, it is important that consumers and manufacturers are aware of the possible threats and how an attacker may seek to remotely exploit vulnerabilities in the future. Third party aftermarket devices with Internet or cellular access plugged into diagnostics ports could also introduce wireless vulnerabilities.
The PSA also says:
The FBI and NHTSA are warning the general public and manufacturers – of vehicles, vehicle components, and aftermarket devices – to maintain awareness of potential issues and cybersecurity threats related to connected vehicle technologies in modern vehicles.
The agency recommends that vehicle owners check the safercar.gov website twice a year for recalls on their cars.

Tuesday, February 10, 2015

Watch a Jacobs School scientist on CBS's 60 Minutes


It's not every day that you get to hack into a car driven by a celebrity news correspondent--with their permission. But that's exactly what Karl Koscher, a postdoctoral fellow in the Department of Computer Science and Engineering at the Jacobs School, got to do for an episode of CBS's 60 Minutes that aired Sunday, Feb. 8.

The show was focusing on security flaws within the Internet of Things--the effort to connect appliances, computers and other devices, including cars, in a network that would make users' lives easier.  Watch the full show here: http://www.cbsnews.com/news/darpa-dan-kaufman-internet-security-60-minutes/

Koscher was putting into practice knowledge accumulated over the years by researchers in the Systems and Networking group here at the Jacobs School and in the Security and Privacy Research Lab at the University of Washington. The team first presented a ground-breaking paper on the topic in May 2010 at the IEEE Symposium on Security and Privacy in Oakland, Calif. They summed up in a press release at the time:

Modern automobiles are becoming increasingly computerized — with many components controlled partially or entirely by computers and networked both internally and externally. This architecture is indeed the basis for significant advances in safety (e.g., anti-lock brakes), fuel efficiency, and convenience. However, increasing computerization also creates new risks that must be addressed as well. Our research mission is to help ensure that these future automotive systems can enjoy the benefits of a computerized architecture while providing strong assurances of safety, security, and privacy.

Our research consists of three complementary strands: conceptual, experimental, and developmental. We conceptually evaluate the computer security landscape for potential future automobiles in order to guide our experimental and developmental research. Weexperimentally evaluate real examples of today's technologies to create informed understandings of potential computer security risks with future automobiles, as well as understandings of the challenges for overcoming those risks. We then develop new security technologies to overcome those challenges and mitigate the associated risks.
However, the researchers were quick to point out that car owners should not panic:
 
 We believe that car owners today should not be overly concerned at this time. It requiressignificant sophistication to develop the capabilities described in our paper and we are unaware of any attackers who are even targeting automobiles at this time.

However, we do believe that our work should be read as a wake-up call. While today's car owners should not be alarmed, we believe that it is time to focus squarely on addressing potential automotive security issues to ensure that future cars — with ever more sophisticated computer control and broader wireless connectivity — will be able to offer commensurately strong security guarantees as well.
More info about the research here:  http://www.autosec.org/