Illustration: Aïda Amer/Axios

Recent hacks of connected vehicles can teach AV developers how to design cybersecurity measures that are cued by anomalies in vehicle behavior.

Why it matters: Today's connected vehicles lack adequate security systems, and autonomous vehicles will have far more vulnerabilities, raising the stakes even higher.

Background: Some current vehicles have anti-malware systems adapted from the IT world, but those are not in wide use and are not robust enough to fully protect connected vehicles, let alone AVs.

  • Hackers have compromised a vehicle's onboard computer using its tire pressure monitor sensor and via SMS messages sent over 4G networks.
  • They have assumed varying degrees of control over connected vehicles using Wi-Fi connections as well, including steering and braking systems, and via over-the-air updates and onboard diagnostic ports.

AV systems are more multifaceted, creating new vulnerabilities, particularly with vehicle-to-everything connectivity in place. They also have more sensors; when sensor data is uploaded to servers, that creates another point of vulnerability.

What's needed: So far, manufacturers have responded by issuing security updates for vehicles — but a proactive system that can anticipate and prevent attacks will be imperative for AV safety. One strategy — being explored by companies like SafeRide Technologies, Vectra, PerimeterX, and ExtraHop — is to examine malware behavior.

  • A behavior-based security system could be triggered by behavior anomalies, rather than detecting a malware's signature. Triggers could include an upload to a sensor server with fewer or more bytes than typically expected or superfluous computer activity registered by the engine control unit.
  • This system could work regardless of the attack type or vulnerability targeted, which is critical given that hackers can mutate code endlessly.

What to watch: Behavior-based security systems must have the capability to learn vehicle behavior independently, without dependency on every software or hardware vendor, and regardless of data formats. Since that would require computing power that only advanced, high-end vehicles have onboard, most cars would need to rely on network bandwidth to run the detection program on the cloud.

Yossi Vardi is the CEO of SafeRide Technologies, an automotive cybersecurity startup.

Go deeper

Updated 25 mins ago - Politics & Policy

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 4 p.m. ET: 12,813,864 — Total deaths: 566,790 — Total recoveries — 7,046,535Map.
  2. U.S.: Total confirmed cases as of 4 p.m. ET: 3,286,025 — Total deaths: 135,089 — Total recoveries: 995,576 — Total tested: 39,553,395Map.
  3. States: Florida smashes single-day record for new coronavirus cases with over 15,000 — Miami-Dade mayor says "it won't be long" until county's hospitals reach capacity.
  4. Public health: Ex-FDA chief projects "apex" of South's coronavirus curve in 2-3 weeks — Coronavirus testing czar: Lockdowns in hotspots "should be on the table"
  5. Education: Betsy DeVos says schools that don't reopen shouldn't get federal funds — Pelosi accuses Trump of "messing with the health of our children."

11 GOP congressional nominees support QAnon conspiracy

Lauren Boebert posing in her restaurant in Rifle, Colorado, on April 24. Photo: Emily Kask/AFP

At least 11 Republican congressional nominees have publicly supported or defended the QAnon conspiracy theory movement or some of its tenets — and more aligned with the movement may still find a way onto ballots this year.

Why it matters: Their progress shows how a fringe online forum built on unsubstantiated claims and flagged as a threat by the FBI is seeking a foothold in the U.S. political mainstream.

Lindsey Graham says he will ask Mueller to testify before Senate

Photo: Tasos Katopodis/Getty Images

Senate Judiciary Chairman Lindsey Graham (R-S.C.) tweeted Sunday that he will grant Democrats' request to call former special counsel Robert Mueller to testify before his committee.

The big picture: The announcement comes on the heels of Mueller publishing an op-ed in the Washington Post that defended the Russia investigation and conviction of Roger Stone, whose sentence was commuted by President Trump on Friday.