Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - IoT Security and Protecting Connected Cars
Articles

IoT Security and Protecting Connected Cars

ISB Editorial StaffBy ISB Editorial StaffMay 19, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ever imagined on owning a car that can drive by itself; that not just determines the fastest route for you through its navigation system, but also finds the most fuel efficient one; that automatically registers for its servicing and renews its insurance; that is smart enough to prevent accidents by assessing driver’s vital functions and alerting the travelers of the potential problems; that drives on its own through traffic jams and highways. Yes, it is no more just a dream car. This disruption is already in progress through the integration of Internet of Things.

We call these cars as ‘Connected Cars’. A connected car is a car that is equipped with Internet access (wireless and LAN) that can be shared with other devices both inside as well as outside the vehicle. These cars are often outfitted with special technologies that tap into the internet or wireless LAN and provide additional benefits to the driver. Examples include, automatic notification of crashes, notification of speeding and safety alerts.

Unfortunately, all these sub-systems are not protected from any kind of hacking. Hence, it is a piece of cake for any hacker who has the ingenuity and talent to hack into these cars and dilute the system. For example, a hacker can apply brakes through wireless technologies when the car is moving, without the knowledge of the driver. It is not very hard to imagine the tremendous damage this act will cause when a car is in motion and suddenly stops without the knowledge of the driver knowing.

Therefore, it is imperative to prevent these types of attacks on cars and in today’s increasingly connected world of IoT, this is an immediate need of the hour.

How do we secure these connected cars?

All modern cars have computer networks to control its functions. Those networks control the engine, control the brakes, to control the ABS etc. Those networks are also used to control the entertainment systems. Those networks have a common protocol underneath the wires that carry the messages. That protocol is CAN (Controller Area Network).

The CAN network is the central part of all the communication activities taking place in a car. The CAN network carry messages to and from various nodes inside the car. These nodes might be for different functions. One might be controlling the engine and usually called Power Train Controller and another might be controlling the windows. These nodes are generically names as Electronic Control Units (ECU).

The CAN network, curiously do not have any addresses for those nodes. The nodes are address less and nameless entities on the CAN network. The source of all the insecurity in the CAN bus is related to this one decision made by the committee which created CAN. However, the CAN messages emanating from the nodes have addresses. Hence, any nodes which is interested in any message will filter the messages and will get the relevant message based only on the address of the message. As a consequence, the node which receives the message will never know from where the message has originated.

There are many CAN networks inside a car and these networks are joined in a certain way and a gateway is designed to access these CAN bus. This gateway is called OBD interface. Also, the CAN buses are tied together in the instrumentation cluster as well. Hence, is somebody accesses the CAN network through Bluetooth in the instrumentation cluster, they can send any malicious commands to the network to cause the car to stop, accelerate etc., without the knowledge of the driver.

What is the solution?

One possible solution is have a master slave relationship in the CAN network, which will be in contrast to what the CAN bus is all about. The CAN bus is a master-master network and need huge change in the mental set up of the designers to change the CAN network as a master-slave setup. This will enable the CAN network to work with encryption and the keys can be created and exchanged through the master-slave architecture. This will prevent any attacks from outside the CAN bus. Another possible solution is to move away from CAN network and utilize some other network with encryption inbuilt. One example, which a famous car company is experimenting with is Ethernet technology. By all means, CAN network is a very resilient network and may not the replaced, but these problems should be addressed to control the menace of hacking of the cars.

[su_box title=”About Shanmugasundaram M.” style=”noise” box_color=”#336588″][short_info id=’68893′ desc=”true” all=”false”][/su_box]

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}