Stories
Slash Boxes
Comments

SoylentNews is people

posted by cmn32480 on Sunday July 24 2016, @01:46PM   Printer-friendly
from the not-just-locking-the-doors-anymore dept.

The Automotive Information Sharing and Analysis Center has published an executive summary of their Automotive Cybersecurity Best Practices.

From the summary

As vehicles become increasingly connected and autonomous, the security and integrity of automotive systems is a top priority for the automotive industry. The Proactive Safety Principles released in January 2016 demonstrate the automotive industry's commitment to collaboratively enhance the safety of the traveling public. The objective of the fourth Principle, "Enhance Automotive Cybersecurity," is to explore and employ ways to collectively address cyber threats that could present unreasonable safety or security risks. This includes the development of best practices to secure the motor vehicle ecosystem.

Unfortunately the public executive overview is somewhat content free and refers to NIST documents on security practices but something is better than nothing. It's been six years since the publication of Experimental Security Analysis of a Modern Automobile and five years since Comprehensive Experimental Analyses of Automotive Attack Surfaces . In those research papers compsci students splay open the control system of a car through standard security analysis techniques such as fuzzing. My favorite technique they used was to install custom software into the QNX powered OnStar device then use it to bridge between the body bus and the bus that handles the engines, brakes, steering, etc. Very clever indeed.

How does the community feel about the poorly secured two ton (metric or imperial, you pick) rolling robot that the modern vehicle has become?


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by mhajicek on Sunday July 24 2016, @04:36PM

    by mhajicek (51) on Sunday July 24 2016, @04:36PM (#379431)

    If the car is fly-by-wire as more and more are, you would also lose brakes and steering.

    --
    The spacelike surfaces of time foliations can have a cusp at the surface of discontinuity. - P. Hajicek
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 2) by Knowledge Troll on Sunday July 24 2016, @06:20PM

    by Knowledge Troll (5948) on Sunday July 24 2016, @06:20PM (#379452) Homepage Journal

    If the car is fly-by-wire as more and more are, you would also lose brakes and steering.

    Can you name models that do not include a direct mechanical linkage that is boosted? True fly by wire would require no direct linkage at all between the brake pedal and brake pads or steering wheel and steering rack.

    Boosted systems can be fully robot and look like fly by wire but the only pedal that I know of that lost the direct connection is the gas pedal. The gas pedal is now attached to a position or angle sensor and the butterflies in the throttle body are operated by a servo. Might be tempted to call it throttle by wire but actually its FADEC [wikipedia.org].

    As far as I know fly by wire can't be used to describe any vehicle that is on the road.