In 2016 the FBI said: “The industry will likely face a range of malicious activity shortly as the data collected by connected and autonomous vehicles become a target for nation and state and financially motivated actors.”
Though terrorism and sabotage are possible, experts believe financial crime is far more likely.
Andy Davis, Transport Cyber Security Practice Director at NCC Group, says: “Media reports tend to focus on the physical attacks, but most cyberattacks come from organized crime groups – and they want to make money, not kill the general public.”
Car hackers can be expected to use the same methods they use on PC users.
Ransomware, for example.
Here, criminals will hack into a vehicle, disable it, and demand money from drivers or manufacturers to relinquish control. Davis says: “You get in the car, and a message on the infotainment system says: ‘Send money if you want your car to start.’ I can also see hackers stealing ID and card details from cars to sell on the black market.”
Why is this?
What compounds the car cybersecurity threat is the sheer number of entry points into the vehicle. Criminals can sneak in via telematics systems or even the radio.
They can also hack into the many external devices – phones, key cards – that drivers link to the car’s electronic control unit (ECU).
Regrettably, car cybersecurity crimes are now rising.
Car manufacturers need to build-in security from the start, rather than patch ‘holes’ as they arise. This will require multi-party collaboration, given the hundreds of suppliers producing parts for today’s cars.
The process will start with securing the connected car’s firmware and software applications (using public key infrastructure, or PKI, and other tools).
But it’s also critical to encrypt the data transmitted to and from the car, both at rest and in motion.
Of course, this security must extend across the life of the vehicle.
Manufacturers should be able to disable connected services during shipping, for example, and can deliver over-the-air software updates to prevent data breaches.
Connected car cybersecurity and the future
The good news is that carmakers are working hard to address the growing threat against connected car security.
They are teaming up with security experts and investing in new technology. Last year, for example, a consortium of car manufacturers invested US$30 million in-car cybersecurity startup Upstream.
Of course, it's not just manufacturers that need to wise up. Motorists must take responsibility too. After all, no end of technical protection will help if hackers can just use social engineering to dupe the connected car driver.
In 2016, security firm Promon proved this when it created a free WiFi hotspot and asked drivers to install an app on their phones. The app was infected with malware and gave hackers the ability to take control of the car.
And what persuaded the drivers to install such a dangerous app?
The connected vehicle is at the crossroads of multiple stakes. Among those stakes, two are of particular interest to car manufacturers (OEMs), equipment suppliers (Tier 1 and Tier 2) and drivers: connectivity and cybersecurity. The development of the connected and, ultimately autonomous vehicle requires all types of embed reliable connectivity capable of withstanding the rigors of urban environments while supporting both critical systems and infotainment applications.
Cybersecurity is complex and quickly evolving. Leveraging advanced and proven expertise in digital security and IoT, the Thales Trusted Key Manager provides car makers with support for digital transformation while ensuring the end-to-end security of the automotive ecosystem.
For more information regarding our services and solutions contact one of our sales representatives. We have agents worldwide that are available to help with your digital security needs. Fill out our contact form and one of our representatives will be in touch to discuss how we can assist you.
Please note we do not sell any products nor offer support directly to end users. If you have questions regarding one of our products provided by e.g. your bank or government, then please contact them for advice first.