Feb 22, 2019

Detecting unexpected behavior could be key to securing AV systems

Illustration: Aïda Amer/Axios

Recent hacks of connected vehicles can teach AV developers how to design cybersecurity measures that are cued by anomalies in vehicle behavior.

Why it matters: Today's connected vehicles lack adequate security systems, and autonomous vehicles will have far more vulnerabilities, raising the stakes even higher.

Background: Some current vehicles have anti-malware systems adapted from the IT world, but those are not in wide use and are not robust enough to fully protect connected vehicles, let alone AVs.

  • Hackers have compromised a vehicle's onboard computer using its tire pressure monitor sensor and via SMS messages sent over 4G networks.
  • They have assumed varying degrees of control over connected vehicles using Wi-Fi connections as well, including steering and braking systems, and via over-the-air updates and onboard diagnostic ports.

AV systems are more multifaceted, creating new vulnerabilities, particularly with vehicle-to-everything connectivity in place. They also have more sensors; when sensor data is uploaded to servers, that creates another point of vulnerability.

What's needed: So far, manufacturers have responded by issuing security updates for vehicles — but a proactive system that can anticipate and prevent attacks will be imperative for AV safety. One strategy — being explored by companies like SafeRide Technologies, Vectra, PerimeterX, and ExtraHop — is to examine malware behavior.

  • A behavior-based security system could be triggered by behavior anomalies, rather than detecting a malware's signature. Triggers could include an upload to a sensor server with fewer or more bytes than typically expected or superfluous computer activity registered by the engine control unit.
  • This system could work regardless of the attack type or vulnerability targeted, which is critical given that hackers can mutate code endlessly.

What to watch: Behavior-based security systems must have the capability to learn vehicle behavior independently, without dependency on every software or hardware vendor, and regardless of data formats. Since that would require computing power that only advanced, high-end vehicles have onboard, most cars would need to rely on network bandwidth to run the detection program on the cloud.

Yossi Vardi is the CEO of SafeRide Technologies, an automotive cybersecurity startup.

Go deeper

The pandemic shows why we're never ready for the big one

Illustration: Aïda Amer/Axios

As the confirmed number of COVID-19 cases passed 1 million on Friday, two words sum up the U.S. response to the coronavirus: not enough. Not enough hospital beds, not enough ventilators, not enough protective equipment. Not enough preparation.

Why it matters: COVID-19 has demonstrated our normal defenses aren't enough in the face of a low-probability, but high-consequence catastrophe.

U.S. coronavirus updates: New York reports record 630 deaths in 24 hours

Data: The Center for Systems Science and Engineering at Johns Hopkins; Map: Andrew Witherspoon/Axios

New York reported 630 new deaths in 24 hours, Gov. Andrew Cuomo said Saturday — an "all-time increase" that beat the previous day's record of 562 deaths in a single day.

The big picture: As expected, COVID-19 death tolls are rising in the U.S., killing more than 7,100 people in total, and over 1,000 in 24 hours alone. The CDC is recommending Americans wear face coverings in public to help stop the spread, marking a significant change in messaging from the Trump administration.

Go deeperArrowUpdated 10 mins ago - Health

World coronavirus updates: Spain tracks more cases than Italy

Data: The Center for Systems Science and Engineering at Johns Hopkins, the CDC and China's Health Ministry. Note: China numbers are for the mainland only and U.S. numbers include repatriated citizens and confirmed plus presumptive cases from the CDC

Spain overtook Italy in its number of coronavirus cases on Saturday, as the global death toll surpassed 60,000, per Johns Hopkins data.

The latest: About half the planet's population is on lockdown amid the coronavirus crisis. Fatalities are exponentially increasing across Europe, with roughly half of deaths worldwide located in Italy and Spain.

Go deeperArrowUpdated 13 mins ago - Health