Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Friday, March 18, 2016

FBI issues PSA on cars' cybersecurity citing work by Jacobs School researchers

Last summer, computer scientists at the Jacobs School demonstrated that they could wirelessly control thousands of vehicles via a gadget that's often used by insurance companies to monitor cars. The team, led by Professor Stefan Savage, has worked to raise awareness of flaws in the cybersecurity of cars since 2010.

On March 17, the Federal Bureau of Investigation issued a public service announcement titled "Motor Vehicles Increasingly Vulnerable to Remote Exploits," which alludes to the researchers' work:
As previously reported by the media in and after July 2015, security researchers evaluating automotive cybersecurity were able to demonstrate remote exploits of motor vehicles. The analysis demonstrated the researchers could gain significant control over vehicle functions remotely by exploiting wireless communications vulnerabilities. While the identified vulnerabilities have been addressed, it is important that consumers and manufacturers are aware of the possible threats and how an attacker may seek to remotely exploit vulnerabilities in the future. Third party aftermarket devices with Internet or cellular access plugged into diagnostics ports could also introduce wireless vulnerabilities.
The PSA also says:
The FBI and NHTSA are warning the general public and manufacturers – of vehicles, vehicle components, and aftermarket devices – to maintain awareness of potential issues and cybersecurity threats related to connected vehicle technologies in modern vehicles.
The agency recommends that vehicle owners check the safercar.gov website twice a year for recalls on their cars.

Tuesday, February 17, 2015

There is no reason that companies should be sucking up data willy nilly, says Eric Horvitz from Microsoft Research

We attended the "Privacy in the Era of Big Data" session at the AAAS conference in San Jose, Calif., on Feb. 15 and came away with a new appreciation of how complex the subject truly is. Below is a series of tweets we posted during the meeting, as well as a brief abstract.












Abstract:

Privacy in an Era of Big Data: Directions, Advances, and Reflections

Sunday, 15 February 2015: 10:00 AM-11:30 AM
Room 210AB (San Jose Convention Center)
Science, technology, and businesses are being rapidly transformed by innovative ways to collect, organize, and analyze more information. Along with the growth of reliance on big data comes the realities and perceptions about big incursions into personal privacy. This session considers three perspectives on addressing concerns about the access and usage of personal data by organizations such as online services, biotech companies, or research institutes: first, research directions in the development of privacy-protecting technologies that make computing systems and data analysis more secure; second, methods that consider user preferences about the balance between privacy and personalized services, including methods that provide guarantees on minimizing data access; and third, legal and ethical implications of large-scale data collection and mining.
Organizer:
Ersin Uzun, Palo Alto Research Center 
Speakers:
Ersin UzunPalo Alto Research Center 
Privacy Enhancing Technologies and New Research Directions
Deirdre K. MulliganUniversity of California 
The Management of Privacy Processes: The CPO and Beyond

Wednesday, January 7, 2015

Cybercrime? It's all about the money, Jacobs School computer scientist says

Photo: Erik Jepsen/UC San Diego Publications
It's all about the money, Stefan Savage, a computer science professor at the Jacobs School, says in the Los Angeles Times. 

“Ninety-nine percent of what you and I deal with when it comes to computer security is motivated by economics,” Savage said. “Data breaches? It’s all about the money. Spam? It’s all about the money. Malware? It’s all about the money. The problem is we are looking at this as a purely technical problem.”
 Over the years, Savage and colleagues at the Jacobs School and the International Computer Science Institute, an independent nonprofit in Berkeley, have probed the economics of cyber crime. The LA Times explains:

Throughout 2011 and 2012, he and a team of researchers posed as buyers of counterfeit goods sold on the Internet and, by tracking the flow of money in these transactions, showed that only a handful of banks were involved in these activities. Working with a Washington, D.C.-based anti-piracy organization called the International Anti-Counterfeiting Coalition (IACC), they helped create a framework whereby brandholders and credit card companies could work together to shut down the counterfeiter's financial accounts, effectively cutting off their economic lifeblood.
Full LA Times article here.

 More about Savage's work here, here  and  here.

Monday, August 11, 2014

Computer scientists in the spotlight on the Torrey Pines Mesa

Several Jacobs School computer scientists and their work are highlighted in a UT San Diego story about the history of the scientific institutions on the Torrey Pines Mesa.

Under the major science accomplishments section:

•Computer scientist Kenneth Bowles and his students modified the Pascal programming language, allowing a program to be moved around from machine to machine, a technique now widely used to build mobile applications.

 •George Varghese and Stefan Savage developed the first automated method for automatically identifying worm and virus attacks across the Internet and other high-speed networks almost as soon as the outbreaks occur. Cisco acquired the technology.
We also spotted computer scientists Ryan Kastner and Mia Minnes in the video accompanying the story:

Cybersecurity experts call for better automotive cyber safety, echoing Jacobs School research findings

A group of cybersecurity experts has announced a Five Start Automotive Cyber Safety Program at the annual Defcon conference in Las Vegas this week to prevent cars from being hacked, a threat that was first pointed out by a team of computer scientists here at UC San Diego and at the University of Washington back in 2010.

The group, called I am the Cavalry, breaks down the five stars as follows:
Safety by Design
Third Party Collaboration
Evidence Capture
Security Updates
Segmentation and Isolation

Savage and colleagues explain the threat in the video below (courtesy of Motherboard):



More on the research here

Wednesday, September 18, 2013

Star-studded line up for cybersecurity forum

PayPal. eBay. Lockheed Martin. These are some of the companies sending their tech leaders to talk about cybersecurity during a think-tank-style event at the Gordon Engineering Leadership Center Sept. 23 and 24 here at the Jacobs School.

 The featured speaker is the principal scientist for consumer security at PayPal, Markus Jakobsson, who will be speaking about the spiraling threat of online fraud and how to address is. Here is the abstract:

The Internet owes its growth and sustenance to commercial developments. However, the spectacular scalability of online fraud threatens this stability. While the human factor is a notable aspect of the problem, traditional security measures treat Internet security as a pure-bred technical challenge. Using examples relating to authentication, Nigerian scams and malware, I will show how we can improve our understanding of and defenses against online fraud by recognizing that it is a socio-technical problem.

 A number of Jacobs School faculty also will be speaking, including computer scientists Stefan Savage, Sorin Lerner, Hovav Schacham and Daniele Miccinacio. 

More info about the event here: http://bit.ly/1aWBsA6