Cybersecurity in automotive: the new threats
Automotive technology has moved a long way in recent years, from autonomous driving functions through to integration with the Internet of Things. That has changed driving, and it has brought new cybersecurity problems with it. This article looks at the current threats in the automotive industry.
More connectivity in vehicles, more attacks
As digitisation has progressed, vehicles have become highly complex, connected systems, exposed to much the same cyber risk as any other IT-based infrastructure. Software-defined vehicles, for instance, let manufacturers deliver updates over the air and add new services, and they carry new security risks with them. According to Upstream’s H1 2023 Automotive Cyber Trend Report, data breaches account for 37 percent of cybersecurity incidents in the automotive industry, and attacks on backend servers for 40 percent.
Current cybersecurity risks in the automotive industry
The threat landscape in automotive changed substantially with the rise of remote attacks over network connections such as Wi-Fi, Bluetooth and mobile networks. In 2022 that class made up 97 percent of all attacks, which largely removes the need for physical proximity to a target. In parallel, the industry has seen a sharp rise in reported Common Vulnerabilities and Exposures (CVEs). These are documented security gaps in software or hardware, recorded in a central database. Such gaps give attackers a way into systems or a way to manipulate data. The database lets manufacturers address gaps before they are used, by shipping updates or issuing warnings.
-
2019: 24 new CVEs reported in the automotive industry.
-
2020: the number rose to 33.
-
2021: a jump to 139 CVEs.
-
2022: 151 CVEs.
The line from 2019 to 2022 shows how much the attack surface of the industry has grown. It is also the case for manufacturers and suppliers to look for security gaps actively rather than wait for them to be reported.
More attack vectors
The industry faces a growing variety of attack vectors. Telematics and application servers, keyless entry systems, electronic control units, automotive and smart mobility APIs, infotainment systems, mobile applications and charging infrastructure for electric vehicles all widen the field. That complexity, from mobile apps through to API-based attacks and ransomware against suppliers and dealers, means security work has to be kept current rather than done once.
Common attack methods against vehicles
-
Remote software attack: criminals use network connections to reach vehicles from a distance. The method has proved effective because it lets an attacker compromise a large number of vehicles at once, without physical access.
-
On-premises software attack: attacks requiring physical access have been overtaken by remote ones, but the method remains a threat, in particular through OBD (on-board diagnostics) ports, which give direct access to vehicle systems.
-
Key fob hacking: relay, replay and other techniques against keyless entry systems have increased substantially. Attackers intercept the communication between key and vehicle to gain access or start the car. This has driven up vehicle thefts and break-ins.
-
Attacks on EV charging stations: as electric vehicles spread, charging stations have become a new point of attack. Researchers and attackers have found weaknesses in charging stations that allow fraud, ransomware attacks, or stopping and slowing the charging function.
Automotive and rail need a systematic approach
With the threat landscape growing as fast as it is, many companies struggle to keep an overview of their own risk. That is what our VATT&EK framework, Vehicle Adversarial Tactics, Techniques & Expert Knowledge, is for: a structure for identifying, analysing and countering threats, built for the automotive and rail industries. It helps OEMs and suppliers work through threats systematically. For a detailed introduction see our article on VATT&EK, the framework for automotive and rail cybersecurity.
In short
With remote attacks rising sharply and CVE counts climbing, the automotive industry has to build security in rather than add it later. Vehicle owners can do something too. Installing software updates matters, and so does keeping track of known security gaps, including the ones an update does not close.