Skip to main content

SwRI investigates cybersecurity weaknesses in transportation management systems

Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.
November 6, 2017 Read time: 2 mins

Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support 588 SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.

SwRI’s assessment will include white hat hacking (penetration testing) to assess vulnerabilities and recommend mitigation strategies. These recommendations will also consider how agencies with limited resources can implement cybersecurity measures.

For future research, SwRI will evaluate potential access points where hackers could exploit connected vehicles. Government agencies and the automotive industry are preparing vehicles and transportation infrastructure to include more wireless networking to enable safer driving with vehicle-to-vehicle and vehicle-to-infrastructure communications.

Figures revealed from the institute show that more than 400,000 traffic signal systems across the United States have varying levels of network access and embedded security. System managers and government stakeholders may be unaware of cyber risks to controllers, dynamic message signs, road-weather information systems, and other devices that relay data.

Daniel Zajac, SwRI engineer and principal investigator, said: “The goal is to create security guidance for traffic management centres,”

IT and security personnel need to understand threats to their equipment, standards for managing passwords, and then move up to advanced network security.”

For more information on companies in this article

Related Content

  • Bhatt: 'Critical opportunity' for cybersecurity
    July 22, 2021
    ITS America CEO Shailen Bhatt tells US Senate funds are needed to 'manage vulnerabilities'
  • US DOT issues federal guidance for improving motor vehicle cyber security
    October 25, 2016
    The US Department of Transportation's National Highway Traffic Safety Administration (NHTSA) is taking a proactive safety approach to protect vehicles from malicious cyber-attacks and unauthorised access by releasing proposed guidance for improving motor vehicle cyber security. The proposed cyber security guidance focuses on layered solutions to ensure vehicle systems are designed to take appropriate and safe actions, even when an attack is successful. The guidance recommends risk-based prioritised ident
  • SwRI to launch EssEs consortium
    May 21, 2012
    Southwest Research Institute (SwRI) will launch a new cooperative research project focusing on safe, reliable, cost-effective energy storage systems for electric and hybrid-electric vehicle applications. The Energy Storage System Evaluation and Safety (EssEs) consortium is intended to help vehicle manufacturers and battery suppliers develop pre-competitive, detailed cell-level test data on electrochemical storage systems and perform research to advance testing methodologies to evaluate batteries. The four-y
  • Keeping cyber criminals from your website
    November 10, 2017
    If a hacker can penetrate your website, they can do business as you. Joe Dysart explains how you and your customers may not discover the fraud for some time. In the latest twist on identity theft, hackers are clandestinely taking over business websites - and then brazenly billing visiting customers as if the sites are their own.