Skip to main content

SwRI investigates cybersecurity weaknesses in transportation management systems

Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.
November 6, 2017 Read time: 2 mins

Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support 588 SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.

SwRI’s assessment will include white hat hacking (penetration testing) to assess vulnerabilities and recommend mitigation strategies. These recommendations will also consider how agencies with limited resources can implement cybersecurity measures.

For future research, SwRI will evaluate potential access points where hackers could exploit connected vehicles. Government agencies and the automotive industry are preparing vehicles and transportation infrastructure to include more wireless networking to enable safer driving with vehicle-to-vehicle and vehicle-to-infrastructure communications.

Figures revealed from the institute show that more than 400,000 traffic signal systems across the United States have varying levels of network access and embedded security. System managers and government stakeholders may be unaware of cyber risks to controllers, dynamic message signs, road-weather information systems, and other devices that relay data.

Daniel Zajac, SwRI engineer and principal investigator, said: “The goal is to create security guidance for traffic management centres,”

IT and security personnel need to understand threats to their equipment, standards for managing passwords, and then move up to advanced network security.”

For more information on companies in this article

Related Content

  • DoTs can benefit from high fibre content
    January 14, 2020
    Existing fibre architecture may be one of the most important assets for DoTs going forward: Skyline’s Paul Lennon explains the importance of evaluating ITS network infrastructure maturity
  • ‘Just 6%’ of transport companies can tackle cyberattacks, says Irdeto
    June 21, 2019
    Transport companies are under concerted attack from hackers, according to security specialist Irdeto – and most don’t know how to respond. New research from the group says that 77% of organisations in transport and automotive have experienced an Internet of Things (IoT)-focused cyberattack in the past year – but only 6% “have what they need to combat cyberattacks”. The survey of 225 companies in China, Germany, Japan, UK and US found that the incursions had an impact on 91% of those which experience
  • Outsourcing security weakness for Sweden’s driver and vehicle data
    October 24, 2017
    The security of driver and vehicle data hit the headlines this summer in Sweden and its authorities are still dealing with the fallout. David Crawford reports. epercussions from Sweden’s vehicle data outsourcing scandal continue to reverberate. Transportstyrelsen, the government’s transport agency, came under fire this summer for risking the personal security of over five million motorists by failing to implement full security checks on personnel in other countries to whom individual work packages could
  • Connected car data – both opportunities and challenges for auto OEMs, says KPMG
    November 14, 2016
    Data collected through connected cars will present automakers with tremendous business opportunities to enhance customer experiences while at the same time also posing inherent risks, according to a new KPMG report, Your Connected Car is Talking: Who's Listening? KPMG's national automotive leader, Gary Silberg, notes that, while OEMs can use data collected through connected vehicles to optimise performance, reliability and safety of vehicles they produce, failure to get cyber-security right could have a