Skip to main content

CVs vulnerable to ‘low skill’ cyberattacks: report

17% of potential attack scenarios on connected vehicles identified as high-risk, finds Trend Micro 
By Ben Spencer February 23, 2021 Read time: 2 mins
Trend Micro says 66% of attacks are medium-risk while 17% are low-risk (© Melpomenem | Dreamstime.com)

A report published by Trend Micro has revealed high-risk cyberattacks against a connected vehicle (CV) can be carried out by a 'low-skill' attacker. 

The cybersecurity firm says attacks such as a distributed denial of service (DDoS) could overwhelm connected vehicle communications. 

DDoS renders a machine or network resource unavailable to the user by disrupting services of a host connected to the internet. 

Launching a DDoS assault on an exposed ITS infrastructure could have devastating consequences - especially if connected vehicles rely on it for driving decisions, the company adds. 

This is just one of 29 real-world scenarios flagged up in Cybersecurity for Connected Cars Exploring Risks in 5G, Cloud and other Connected Technologies.

Trend Micro identifies 17% as high-risk, 66% as medium-risk and 17% as low-risk. 

The firm says other dangerous attacks include electronically jamming connected vehicle safety systems or wireless transmissions to disrupt operations.

Medium-risk attacks can include sending incorrect or improper commands to back-end ITS.

Remotely transmitting and installing malicious firmware and/or apps fall into the low-risk category. 

Rainer Vosseler, threat research manager for Trend Micro, says the research shows there are “ample opportunities” for attackers looking to abuse connected vehicle technology. 

“Fortunately, there are currently limited opportunities for attacks, and criminals have not found reliable ways to monetise such attacks,” Vosseler continues.

“With the UN's recent regulations requiring all connected cars to include cybersecurity, as well as a new ISO standard underway, now is the time for stakeholders across the industry to better identify and address cyber risk as we accelerate towards a connected and autonomous vehicle future."

Trend Micro has issued guidance for protecting CVs, which includes establishing effective alert, containment and mitigation processes.

The firm also recommends protecting the end-to-end data supply chain across the car's E/E network, the network infrastructure, back-end servers and vehicle security operations centre.

It also emphasises the importance of applying lessons learned to prevent repeat incidents, using security technologies such as firewall, device control, app security, vulnerability scanner and code signalling. 


 

Related Content

  • February 16, 2022
    TRL publishes C/AV roadmap for 2035
    Document themes cover industry, vehicle and technology and infrastructure
  • August 18, 2021
    How to secure critical infrastructure networks from cyber attacks

    With increasing OT-IT convergence, critical infrastructure networks and other industrial control systems are exposed to cyberattacks. Ensuring compliance with multiple strict national cybersecurity regulations and balancing them with cost and productivity considerations is not easy. Find out how you can implement end-to-end cybersecurity for modern as well as legacy systems while gaining the flexibility to choose the software that is right for your OT network using RUGGEDCOM hardware.

  • June 28, 2018
    Harnessing the power of smart technology
    Keeping the public safe in a changing world requires smart thinking and sensible deployment of technology. Peter Jones of Hitachi Europe examines some available options From human threats, such as terrorism, to digital threats like hacking, the growing sophistication of crime is posing serious challenges to public safety. At the same time, mass urbanisation threatens to exacerbate these problems as there are more people to keep safe. According to a new whitepaper from Hitachi and Frost & Sullivan, Public
  • May 15, 2023
    ITS European Congress 2023: ‘It’s about mobility’
    ITS European Congress 2023 in Lisbon will deliberately focus on a broad range of transport modes. Joost Vantomme and Lisa Boch-Andersen from organiser Ertico explain why