The Cybersecurity Risks Threatening The Automotive Industry, And How To Combat Them

The automotive industry is changing rapidly, and cars are getting smarter and smarter. With more elaborate electronic components, more sophisticated infotainment systems, and more ADAS (Advanced Driver Assistance Systems) on board, they are essentially large computers on wheels. All these high-tech features bring numerous advantages, of course, but they can also pose a risk on the cybersecurity front, amply illustrated by VW’s latest data flaw that left the personal information of hundreds of thousands of VW owners accessible online for months.



Related

VW Data Flaw Left The Private Info Of 800,000 Cars Accessible For Months

The data was publicly available, including the locations and movements of cars owned by some German politicians.

Every connected feature is a potential vulnerable point for hackers to attack: in a world where some of a car’s functions can be controlled fully remotely, a cybersecurity breach can turn into a safety issue, potentially putting a vehicle’s occupants in danger. As a result, automakers have been focusing on boosting their products’ cybersecurity defenses, as well as implementing good cybersecurity practices in their operations and their manufacturing and design processes. Here are some of the challenges currently faced by the automotive world of today, and some of the ways the industry is responding to stay on top of these challenges.

The information in this feature illustrates the current state of car cybersecurity art, but the status quo can change at a moment’s notice, so always stay abreast of the latest developments.



What Cybersecurity Challenges Is The Automotive Industry Facing?

Today’s automotive industry has to tackle a multitude of cybersecurity issues coming from several different angles. There are, of course, the run-of-the-mill cyberattacks every other industry also has to deal with; personal data leaks and theft, ransomware attacks on manufacturing facilities, and “hacktivism”-type attacks to name a few.

Cybersecurity Graphic Representation
Adi Goldstein, Unsplash

However, the automotive world is also uniquely vulnerable due to the nature of its products. Modern cars are a combination of the digital and the mechanical, where increasingly complex and connected systems exist alongside mechanical components and a human driver. This opens them up to a unique set of threats that other products, such as phones or laptops, do not face, such as key fob signal jamming.


google news icon large

Add CarBuzz to your Google News feed.

These threats, furthermore, include theft of sensitive location-based data, attacks involving driver-assistance and safety features, and the notorious keyless entry-based thefts, which have plagued multiple automakers in recent years. In more extreme cases, cars with remote control-type features (such as Tesla’s Summon) could even be exploited by hackers to move independently. When cyberattacks cross the barrier into the “real world”, putting the physical safety of a car’s occupants in danger, the matter becomes far more serious, as two hackers and one journalist found out nearly a decade ago in a public stunt that made headlines.

Related

UPDATE: Ford Drops A Layer Of Security From 2025 F-150

The feature is less popular than it once was, but it still feels unfair to have to pay for something that was always included.

A Watershed Moment: The Jeep Cherokee Incident

The incident in question happened in 2015, when Charlie Miller and Chris Valasek successfully hacked into a 2014 Jeep Cherokee, as we reported at the time. The car was in motion, driving along a St. Louis HIghway, with Wired writer Andy Greenberg behind the wheel. While the trio had previously managed to pull off a similar feat a few years earlier, Miller and Valasek had to sit in the back seat in order to access the vehicle’s system; this time, however, the hack was conducted in fully remote fashion.


The car’s vulnerable point was the Uconnect infotainment system, which the two used to access the car’s internal computer and send commands to mechanical components like the accelerator and braking system. The two hackers’ achievement revealed some problematic truths about the vulnerability of smart, connected cars, which were beginning to take the world by storm around that time. It was estimated that nearly half a million FCA vehicles could be hacked in the same way; the company acted accordingly, issuing a security patch.

Related

Why Modern Connected Cars Are Becoming A Privacy Nightmare

If your insurance premiums suddenly shot up, this might be why.

Over-the-air updates were also not commonplace at the time, which meant hundreds of thousands of customers had to go out of their way to physically install the update onto their car via an external device. From that point onward, cybersecurity became an even bigger area of focus for automakers, as companies did not want to be caught in FCA’s position.


How Is The Industry Responding To These Challenges?

The automotive industry may be exceptionally vulnerable to cybersecurity attacks, but that doesn’t mean it isn’t trying to fight back. Automakers are well aware of the threat that cybersecurity breaches pose to their business and long-term survival; they are implementing a number of measures to avoid incidents and keep their customers as safe as possible. Here are some of the actions car companies are taking to mitigate cybersecurity risk.

Over-The-Air Updates: A Double-Edged Sword

Cars from the recent past may have had digital infotainment systems, but no way of keeping them updated or connected to the outside world after the car had been delivered to its new owner. Today’s cars, on the other hand, are able to constantly stay up to date throughout their lifespan, thanks to over-the-air (OTA) updates.

Lucid Software Update
Lucid Motors


As well as the more mundane functions we all know about, such as additional media content or new navigation maps, OTA updates can be used for vital security updates as well, ensuring the car is never left vulnerable to attacks due to obsolete software. That being said, a car that can receive over-the-air updates also carries the risk of this technology being used for malicious purposes: a connected car is, by nature, more exposed to hackers than one that’s isolated from the Internet of Things.

Network Segmentation

Person Working on Laptop Stock Photo
Christine Hume/Unsplash

One way automakers are making it harder for hackers to interfere with their operations or cars is by using a practice called network segmentation. At its core, network segmentation simply means that different elements of a single network, such as a manufacturing facility’s IT system, are isolated from one another, which means if there is a breach it can be contained quickly, in a similar fashion to the watertight compartments of a ship.


Focus On Data Protection

Anyone who has interacted with technology in the past decade will be able to tell you: every app, website, or device comes with some form of data privacy agreement. This is because user data is being collected at a record rate, whether it’s image and video content, settings and preferences, or even GPS location.

2024 Nissan Altima Interior Infotainment
Nissan

Thanks to their increasingly sophisticated infotainment systems, today’s cars collect a large amount of information about their owners, from their favorite locations to their phone contacts. All this data can be very valuable if stolen; as a result, automakers are focusing heavily on measures like encryption to keep it safe and protected.


Anomaly Detection

2024 Buick Envista Interior Driver Area
Buick

One way of preventing and handling cyberattacks is through the use of IDPS (Intrusion Detection and Prevention Systems). These systems can be employed to determine the normal behavioral pattern of a user or network and detect deviations from it, which means a cyberattack can be spotted and tackled faster. Technology such as AI and machine learning can also be useful in this domain.

Preventing Keyless Entry Thefts

One high-tech aspect of modern cars that has been in the spotlight for its vulnerability is keyless entry. This feature, which, as the name suggests, allows the driver to get into their car without having to take the key out at all thanks to the car sensing the key’s presence, has proven to be very easy for car thieves to exploit. This phenomenon has also led to rising insurance premiums for owners of some models that are particularly vulnerable.


Automakers, naturally, have been scrambling to come up with fixes: in 2023, Volvo came up with an innovative tech solution to stop signal-jamming car thieves from exploiting the XC90’s keyless entry systems.

Does AI Have A Part To Play In Keeping Cars Safe?

AI is the latest tech buzzword that has invaded every aspect of our digital lives. Today, most people associate the word AI with image generation systems or language models such as ChatGPT, both of which are known for inaccuracies and what experts call “hallucinations”, that is, the production of inaccurate or made-up information. The more dubious applications of AI also extend into the automotive world: tech company Harman is planning to launch an “emotionally intelligent in-car assistant” that’s supposed to give your car feelings. We’ll let the public be the judge of that one.


AI Stock Photo
Tara Winstead/Pexels

However, AI-based systems can be used for much more than a questionable relationship with your car or drawing people with too many fingers: they can also be used for cybersecurity purposes, helping keep vehicles and their occupants safe from digital threats. One example is the behavioral pattern and anomaly detection systems we mentioned earlier; pattern recognition is a crucial skill when it comes to detecting cybersecurity threats, and this is one area where AI and machine learning have the potential to excel in the automotive world.

Sources:
Infoshare Systems, TrueFort, The Engineer, ACEA.

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous post Fantom (FTM) Poised For 50% Rally, Here’s Why
Next post Hrithik Roshan Is Afraid About Kaho Naa Pyaar Hai Re-Release