Developing innovative automotive cybersecurity technologies and promoting strategic connected car cybersecurity projects has become a top priority for many automakers. There is also a growing awareness of cybersecurity threats and attack risks to vehicles, their components and the entire supply chain. Protecting digital systems and networks from unauthorized access, malicious attacks, and potential damage or disruption is a key concern for manufacturers, suppliers, regulators, consumers and other stakeholders. The cybersecurity market for connected cars is expected to grow at a CAGR of 18.15% from 2023 to 2032, so the penetration of connected and autonomous vehicles will also be a focus area. According to Precedence Research, the market size for cybersecurity services in 2023 will be: It is expected to be approximately US$3.66 billion.
Karthik Ramanarayanan, Head of Smart Mobility R&D at Continental Automotive India, is responsible for the Smart Mobility and Cloud Solutions business area at Continental (India). He shares with his Autocar Professional what his OEM is doing and where to go to mitigate the problem.
Can you tell us what is happening in the background at Continental when it comes to cybersecurity in the mobility sector?
Cybersecurity is one of the key topics discussed, especially in terms of connected cars. So if you look at history, the first car had embedded software in 1977, this was done by GM, and by 1981 GM had already deployed about 50,000 lines of code. I was. But if you look at today’s cars, they rely on millions of lines of code and run up to 100 network ECUs. ECUs are called electronic control units and can monitor everything from powertrains, safety, brakes, airbags, sensors, wipers, and other functions such as infotainment centers. There are separate his ECUs for each of these functions, but now we are focusing on the network ECU. Today’s cars use big data to provide premium connectivity services, especially for infotainment centers. People only want the latest and greatest, and with these connected cars, providing Over the Air (OTA) updates is also very important. Connected cars offer many opportunities by keeping consumers up-to-date. But as more connected cars hit the road, more hackers will have access to software vulnerabilities. Some use cases also mention the car you’re driving providing information to the cloud, and other cars on the road using this information to inform passengers about road conditions. .
Vehicles are more likely to be hacked if they make use of information residing in connected units or if they provide information to consumers through the environment that could compromise critical safety systems. Infotainment centers, personalized playlists, etc. not only put the user’s personal information at risk, but also the physical safety of the car. Automakers must adopt a cybersecurity approach that addresses not only the many obvious vulnerabilities in automotive software, but also the many hidden ones. As many third-party integrations are introduced, it becomes important to address these issues.
How do you deal with cybersecurity issues?
Continental acquired Argus Cyber Security in November 2017 to ensure secure data channels in vehicles and cross-platform connectivity via devices. The company is part of Continental and develops end-to-end solutions with the aim of always ensuring the highest possible level of security. Rather than waiting for an incident to occur, we take a more proactive approach that takes cybersecurity into account from day one of product development and doesn’t introduce many potential security loopholes.
Within the smart mobility business area, we do both embedded software development and cloud-based back-end development, with many products directly involved, from firmware to embedded hardware to cloud back-end, making it a holistic solution. Run an end-to-end solution. In both of these solutions, we perform a very detailed risk analysis to ensure a compliant and safe product.
We start from the ground up because we have quality security gates that require developers to maintain basic standards so that no room for vulnerability is left.
Automakers must adopt a cybersecurity approach that addresses not only the many obvious vulnerabilities in automotive software, but also the many hidden ones.
In the context of cybersecurity, what can hackers do once they get into your system? One is to change lanes or spread your engine. What other possibilities are there?
Today’s cars are becoming more and more automated, from starting remotely to turning on the air conditioning, opening and closing doors and trunks, and even braking systems. All these functions use software that is heavily embedded in the car. There are multiple potential hack points, one of which is the external interface through which the car shares information with other devices. Another is the in-vehicle network, where his ECU, where each ECU is responsible for a specific function in the car, can be hacked. All these features can make your vehicle vulnerable to attack and should be monitored.
Do you think data mining and machine learning can be leveraged as a preventative mechanism? If OEMs have a lot of data, they can use it to infer whether their drivers are behaving in a certain way, and AI or ML can Precautions can be taken to recognize that the driver will not behave in such a way. Could you?
It is possible that there is a mechanism to monitor the state of the vehicle. Continental has also considered permanently monitoring the current state of the vehicle, as communication takes place between the CAN bus and all his ECUs. Information on the CAN bus is continuously transmitted to a security operations center located outside the vehicle.
There are multiple potential hack points, one of which is the external interface through which the car shares information with other devices.
Through the Security Operations Center, we can identify many patterns emerging based on the data, but this is still early days. Applying AI and ML and observing behavioral anomalies can be hacked. If there are any anomalies, the issue is flagged for further analysis. In case the vehicle is hacked, Continental sends patches, also called over-the-air updates, which are sent immediately by the security operations center. This use case for AI and ML is certainly possible in theory. Efforts have already been made in this particular way, as a lot of information is shared from the vehicle to the Security Operations Center to flag potential hacking threats.
As a cybersecurity expert, if I could be more hands-on, could you name a case or two where a car or motorcycle has been hacked without revealing the identity of the OEM or the customer? I’d appreciate it if you could explain what happened and how that particular OEM or software vendor of her worked around it.
There was an incident in which Chrysler recalled about 1.4 million Jeeps worldwide. There was once a demonstration of a hacker being able to control a vehicle’s braking system over the internet, and the demonstration proved that it was possible, and corrective action was taken. The company recalled the vehicle and addressed the issue by replacing some ECUs as some vehicles had no possibility to fix the issue through OTA.
Tesla was one such example, with a vulnerable infotainment system that could have allowed hackers to control the car and start or stop the motors while driving. This issue was quickly resolved by sending a patch through over-the-air update. Security operations centers play an important role, especially for connected cars, as they help identify potential threats.
These two cases appear to be ethical hacking cases where a company or some ethical hackers just tried to test the vehicle for vulnerabilities. But do you have any real-life case studies of real hackers trying to do that (if you know of any)?
There is one incident that I vaguely remember. It involved GM’s Onstar, a potential cybersecurity hack where hackers tried to disable the engine or hack the braking system. But I’m not too sure about the details.
So is there a template India can borrow from more mature markets like Europe? Europe has something called UN 136 which I think is more of a recommendation than an obligation to OEMs. Are these good enough for India to implement?
This kind of template is very specific to Europe as it is very specific to that region. Some of it may also be applicable to India and could be a good starting point, but from the point of view of Indian law,
Some changes have been made to suit the Indian market. We will use that as a base and then modify it according to local demand.
This interview first appeared in the May 15, 2023 issue of Autocar Professional.
