Skip to main content

Guidelines on cyber security for connected and automated vehicles ‘doesn’t go far enough’

David Barzilai, chairman and co-founder of automotive cyber-security firm, Karamba Security, has applauded the UK government for taking pre-emptive action and zeroing in on preventing cyber-attacks as critical for the adoption of self-driving cars on a mass scale. However, he says the guidelines don’t go far enough toward effectively preventing car hacking, saying cars are not servers or mobile phones that can sustain the risk of hidden security bugs. The time it takes to remediate such bugs in production,
August 8, 2017 Read time: 3 mins
David Barzilai, chairman and co-founder of automotive cyber-security firm, 8519 Karamba Security, has applauded the UK government for taking pre-emptive action and zeroing in on preventing cyber-attacks as critical for the adoption of self-driving cars on a mass scale.
 
However, he says the guidelines don’t go far enough toward effectively preventing car hacking, saying cars are not servers or mobile phones that can sustain the risk of hidden security bugs. The time it takes to remediate such bugs in production, while hackers exploit them and create damage, can compromise consumers’ safety.

Smart vehicles are increasingly becoming the norm on British roads, allowing drivers to access maps, travel information and new digital radio services from the driving seat. But while smart cars and vans offer new services for drivers, it is feared would-be hackers could target them to access personal data, steal cars that use keyless entry, or even take control of technology for malicious reasons.

Tough new %$Linker: 2 External <?xml version="1.0" encoding="utf-16"?><dictionary /> 0 0 0 oLinkExternal government guidance false http://www.gov.uk/government/publications/principles-of-cyber-security-for-connected-and-automated-vehicles false false%> aims to ensure engineers developing smart vehicles will have to toughen up cyber protections and help design out hacking. The government is also looking at a broader programme of work announced in this year’s Queen’s speech under the landmark Autonomous and Electric Vehicles Bill that aims to create a new framework for self-driving vehicle insurance.

The guidance contains eight principles, setting out how the automotive sector can make sure cyber security is properly considered at every level, from designers and engineers, through to suppliers and senior level executives. These include:

  • Organisational security is owned, governed and promoted at board level:
  • Security risks are assessed and managed appropriately and proportionately, including those specific to the supply chain:
  • Organisations need product aftercare and incident response to ensure systems are secure over their lifetime;
  • All organisations, including sub-contractors, suppliers and potential 3rd parties, work together to enhance the security of the system;
  • Systems are designed using a defence-in-depth approach;
  • The security of all software is managed throughout its lifetime;
  • The storage and transmission of data is secure and can be controlled;
  • The system is designed to be resilient to attacks and respond appropriately when its defences or sensors fail.

Barzilai says cars enter production with thousands of hidden security bugs. It is unavoidable, as all software has bugs and cars have between 10m to 100m lines of code, in each car. As autonomous cars get more sophisticated and as more human navigation tasks, such as looking around and steering, move to the car, the danger increases. Hackers can hack into a car through its internet-connected features such as the vehicle-to-vehicle (V2V) communications system, and once in, they can work their way into the rest of the car’s controls.
 
However, he says, cars have a significant cyber-security enabler, which should not be overlooked. Cars should run as they operate in-factory. Any unauthorised change to factory settings must be malware. Hardening the car’s externally-connected controllers according to their factory settings prevents cyber-attacks, when hackers try to exploit security bugs, before hackers succeed to infiltrate the car and without sending frequent security patches to the field.

UTC

Related Content

  • January 17, 2019
    Car2Go launches e-car rental service in central Paris
    Daimler subsidiary Car2go has made its electric car rental service available to Parisian users in a 77km square area within the city’s Périphérique motorway. Drivers are charged between €0.24 to €0.34 per minute depending on the location and time of the rental, and can charge the vehicles at around 1,100 charging stations in the French capital. The details flesh out Car2go’s announcement last year of plans to deploy 400 electric Smart EQ Fortwo vehicles in the city. The company intends to add more ve
  • May 1, 2015
    2015 Best of ITS Awards announced
    ITS America has announced the list of finalists for the 2015 Best of Intelligent Transportation Systems (ITS) Awards which recognises the most innovative projects and influential achievements in the high-tech transportation community. The Best of ITS Awards recognises organisations whose projects have demonstrated specific and measurable outcomes and exemplified innovation by establishing a “new dimension” of performance.
  • October 14, 2019
    Most pedestrian detection systems ‘hit pedestrians at 30mph’
    In-car automatic emergency braking systems with pedestrian detection mostly fail to avoid hitting pedestrians - and are “completely ineffective at night”, according to new research. In shocking findings, the American Automobile Association (AAA) revealed that most systems hit a simulated pedestrian target at 30mph. A collision also occurred 89% of the time when a vehicle operating at 20mph encountered a child darting between two cars. In tests, all vehicles collided with an adult pedestrian immediately fo
  • May 1, 2013
    Designers explore the future of transport and passenger experience
    Industrial designers from around the world are meeting in London next month to explore the future of transport systems, how to improve the passenger journey from home to destination and how greater integration and connectivity can enhance the transport user experience. Paul Priestman, designer and co-founding director of international design consultancy Priestmangoode will lead the debate in the Wired Transport: Connected trains, planes and automobiles session at the Product Design and Innovation Conference