Hundreds of Thousands' of Vehicles At risk of Attack

Hackers_take_control_of_Jeep_Cherokee__F_3207530001_21889270_ver1.0_640_480.jpg

A security expert who recently demonstrated he could hack into a Jeep and control its most vital functions said the same could be done with hundreds of thousands of other vehicles on the road today.

Security experts Charlie Miller and Chris Valasek collaborated with Wired magazine to demonstrate how they could remotely hack into and control the entertainment system as well as more vital functions of a 2015 Jeep Cherokee.

Both hackers are experienced IT security researchers. Miller is a former NSA hacker and security researcher for Twitter and Valasek is the director of security research at IOActive, a consultancy.
As the Wired reporter drove the vehicle on a highway, the hackers were able to manipulate its radio and windshield wipers and even shut the car down.

The vehicle hack took place as Wired reporter Andy Greenberg drove the Jeep Cherokee on Rte. 40 in St. Louis. The hackers were 10 miles away at the time.
The hackers said they were able to use the cellular connection to the Jeep's entertainment system or head unit to gain access to other systems; a vehicle's head unit is commonly connected to various electronic control units (ECUs) located throughout a modern vehicle. There can be as many as 200 ECUs in a vehicle.

It took Miller and Valasek about a year to hack into Chrysler's UConnect head unit, and according to Miller, it required three steps.
•    Gain access to the vehicle's head unit/controller chip and firmware
•    Use the head unit's firmware to compromise the vehicle's controller area network (CAN), which speaks to all of the electronic control units (ECUs) throughout the car
•    Discover which CAN messaging can control various vehicle functions.

"The first step I thought would be the hardest: to find a remote vulnerability and write an exploit for it. It turned out that was actually rather easy, so I had that done in about three weeks," Miller said. "The second step I thought would be really easy, was really hard. That took us maybe three months. The final step of sending CAN messages to vehicle systems was simply an exercise in discovering which messages controlled which functions, Miller explained.

Jon Allen, a principal analyst at consultancy Booz Allen Hamilton, said he was uncertain whether the hackers' prior access to the vehicle helped enable the attack.

At the DefCon hacker conference in 2013, Miller and Valasek demonstrated they were able to hack into a Ford Escape and a Toyota Prius and control the brakes and steering. That hack, however, required physical access to the onboard diagnostics (OBD-II) computer port on each vehicle. Since 1996, OBD II ports have been standard on all U.S. vehicles, and they allow access to ECU data.
"That's no different from pouring sugar into a vehicle's gas tank. All you need is physical access. Valasec and Miller are good about getting headlines," Allen said. "They did have physical access to the vehicle before they hacked it."
Miller said the Chrysler Jeep Cherokee belonged to him, but prior access to the vehicle was not needed for the zero day-style attack to take place.
"We could have easily done the same thing on one of the hundreds of thousands of vulnerable vehicles on the road," Miller said. "We gained access by exploiting a vulnerability that was present on the head unit (i.e. the radio/navigation thingy) that was accessible over the Internet. It did not require any physical access or changes to the vehicle."
The attack, will work on any Chrysler vehicle with the Uconnect telematics system from late 2013, all of 2014, and early 2015 -- that includes Dodge, Ram and Jeep model vehicles.

The physical equipment needed to perform the vehicle hack was relatively simple: Miller and Valasek used a Kyocera Android smartphone as a W-iFi hotspot connected to a MacBook laptop. The head unit on the Chrysler was linked to the Internet by Sprint's cellular network.

Vehicle manufacturers routinely collect information on vehicles through cellular networks in order to alert drivers that maintenance or repairs may be required. Today, more vehicle manufacturers are also embedding Wi-Fi routers to enable mobile Internet connectivity.

Miller said his Jeep Cherokee has a Wi-Fi option, but that it's the cellular function that allows access from anywhere.
Through the cellular connection, Miller and Valasek are able to gain a vehicle's GPS coordinates, vehicle identification number, and, more importantly, its IP address.

Miller said the vulnerability that allowed the attack is exclusive to Chrysler's UConnect head unit, but there are likely similar types of security holes on other vehicles'  telematics systems.
Miller and Valasek have been communicating their research with Chrysler for the past nine months or so, which allowed the company to release a software patch to help prevent future attacks.

Ron Montoya, consumer advice editor with Edmunds.com, said he was surprised physical access was not required for the vehicle hack, but he also doesn't think hacking a vehicle is as easy as it may seem.
"This is a group of researchers that have been dedicating their lives the past couple of years to doing this, and they have very high skill levels. They're security engineers," Montoya said. "I don't think this is something to freak out over. It does [give] awareness to automakers that they need to take a hard look at security on their vehicles."
To create more secure vehicles, Montoya believes manufacturers must ultimately find a way to isolate driving functions from infotainment systems.

Allen agreed that widespread vehicle attacks are not likely to happen in the future because there would be little monetary incentive to them and they'd require a great deal of work.
Securing vehicles from wireless hacks has less to do with a firewalls and more to do with recognizing an attack is happening and shutting it down before it can manipulate the car.
Miller agreed.
"You need to take a layered approach, just like you do in enterprise security," Miller said. "The CAN bus is very simple. The messages on it are very predictable, but when I start sending messages to cause attacks..., those messages stand out very plainly."
Carmakers could easily upgrade software to detect malicious CAN messages and instruct critical vehicle systems, such as brakes or transmission, to ignore them, Miller thinks the best way to secure vehicles is by detecting attacks as they're happening
"An intrusion detection system for the car network. It's something we've been advocating for a long time," Miller said. "Yeah, Chrysler fixed this particular remote flaw, but there are probably others. We can't build perfect software. Someone is going to hack into another vehicle head unit someday."

Computerworld:
 

« Dating Website Admits Hackers Have Stolen Data on Millions
Automobile Industry Gears Up For Cyber-Threat »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Zadara Storage

Zadara Storage

Zadara provide complete data backup and protection delivered as a fully-managed service.

Vera Security

Vera Security

Vera is a data security platform that provides 360-degree visibility and control over critical business data, anywhere it's shared or stored.

Cimcor

Cimcor

Cimcor’s flagship software product, CimTrak, helps organizations to monitor and protect a wide range of physical, network and virtual IT assets in real-time.

National Cyber Security Centre (NCSC) - Ireland

National Cyber Security Centre (NCSC) - Ireland

The National Cyber Security Centre (NCSC) is the operational side of the Department of Communications in regard to network and information security in the Republic of Ireland.

Travelers

Travelers

Travelers is a leading writer of US commercial property casualty insurance and one of the world’s largest global insurers for cyber insurance.

PROOF

PROOF

PROOF is a Brazilian leader in cybersecurity. Our goal is to assist our Customers in managing security efficiently and in tune with business needs.

Secure Blockchain Technologies (SBT)

Secure Blockchain Technologies (SBT)

SBT is a team of Enterprise IT Security Professionals weaving security and Blockchain Technology into our customer’s operational fabric.

Lionfish Cyber Security

Lionfish Cyber Security

Lionfish Cyber Evolution & Empowerment Model™ empowers SMBs to prepare and protect themselves against cyber threats using a unique combination of on-demand training, support and managed services.

Coralogix

Coralogix

Coralogix are rebuilding the path to observability using a real-time streaming analytics pipeline that provides monitoring, visualization, and alerting capabilities without the burden of indexing.

TPx Communications

TPx Communications

TPx is a leading managed services provider offering a full suite of managed IT, unified communications, network connectivity and security services.

StarLink

StarLink

StarLink is an acclaimed Value-Added Distributor across the Middle East, Turkey and Africa regions with on-the-ground presence in 20 countries including UK and USA.

Tidelift

Tidelift

Tidelift provides the tools, data, and strategies that help organizations assess risk and improve the health, security, and resilience of the open source used in their applications.

MajorKey Technologies

MajorKey Technologies

MajorKey improves security performance by reducing user friction and business risk, empowering your people, and protecting your IP.

EPAM Systems

EPAM Systems

Since 1993, EPAM Systems has leveraged its advanced software engineering heritage to become a leading global digital transformation services provider.

Pacific Certifications

Pacific Certifications

Pacific Certifications provide accredited certification, training and support services to help you improve processes, performance and products and services.

Dynamic Standards International (DSI)

Dynamic Standards International (DSI)

Dynamic Standards International is a global standards development organization which develops certifiable ‘dynamic standards’ that pace with fast-evolving landscapes.