未來某天,你也許會發(fā)現(xiàn)自己的發(fā)動機轉(zhuǎn)速指針快速從“零”跳到“爆表”,又即刻回零,而后不斷反復(fù),而你在整個過程中其實什么也沒有做,放佛有一股“外部力量”完全控制了你的汽車。
“這叫做短信息欺騙(SMSspoofing),也就是說黑客利用手機等其他電子設(shè)備,通過訪問車主安裝的車輛App來更改車輛設(shè)置,包括鎖門/開鎖等。”哈曼(Harman)北美網(wǎng)絡(luò)安全業(yè)務(wù)開發(fā)部總監(jiān)Geoffrey Wood表示,“我們的軟件則可以防止這種對車輛系統(tǒng)的入侵。”
在哈曼國際位于密歇根州諾維市的北美汽車總部中,公司正在演示向一輛處于停車狀態(tài)的汽車進(jìn)行的儀表盤入侵,以及其他基于遠(yuǎn)程控制的網(wǎng)絡(luò)攻擊。
駕駛員如果注意力分散,可能很麻煩,甚至很危險。如果黑客控制了車輛的制動和轉(zhuǎn)向系統(tǒng),后果更是不堪設(shè)想。
Wood向《汽車工程》介紹說,“盡管汽車制造商已經(jīng)采取了大量的網(wǎng)絡(luò)安全措施,但據(jù)我們所知,目前并沒有任何廠商的汽車配備了入侵檢測系統(tǒng)。”
但這種情況可能很快就會改變。目前,哈曼國際正在與多家汽車制造商就相關(guān)事宜進(jìn)行商討。Wood表示,公司的車輛入侵監(jiān)測系統(tǒng)預(yù)計將在2019年登陸一款全球范圍內(nèi)使用的汽車平臺。
目前,哈曼公司是唯一一家可以提供TCUShield、ECUShield入侵監(jiān)測系統(tǒng)及Alerts Monitor后端網(wǎng)絡(luò)安全分析平臺等端到端網(wǎng)絡(luò)安全汽車解決方案的公司。2016年,哈曼國際收購了以色列網(wǎng)絡(luò)軟件公司TowerSec,為公司的“5+1”產(chǎn)品安全架構(gòu)增加了用于信息娛樂系統(tǒng)和遠(yuǎn)程通信單元的TCUShield,及用于ECU單元的ECUShield。
現(xiàn)階段,盡管一些其他供應(yīng)商也可以向客戶提供網(wǎng)絡(luò)安全檢測解決方案,但哈曼工程師認(rèn)為,公司的端到端解決方案擁有一個競爭優(yōu)勢。“你肯定希望所有組件都能協(xié)同工作,”Wood表示,否則系統(tǒng)整體就可能出現(xiàn)漏洞。
汽車網(wǎng)絡(luò)安全系統(tǒng)面臨的挑戰(zhàn)之一在于,車輛內(nèi)置微控制器模塊的存儲空間非常有限。
“入侵檢測系統(tǒng)在網(wǎng)絡(luò)管理中已經(jīng)非常常見,但這些大型服務(wù)器的內(nèi)存空間非常充裕,”Wood解釋說,“而很多精專于網(wǎng)絡(luò)管理的公司都無法克服汽車中所特有的空間有限難題。”
哈曼宣稱,公司的入侵檢測系統(tǒng)已經(jīng)通過了由多家汽車廠商進(jìn)行的各種網(wǎng)絡(luò)安全測試。廠商會向哈曼提供車輛,以安裝哈曼的系統(tǒng),而后進(jìn)行有針對性的校準(zhǔn)測試。接著,“白帽”工程師們會開始發(fā)起網(wǎng)絡(luò)攻擊,進(jìn)行試驗。伍德說,“但我們事先并不知道他們會如何進(jìn)行攻擊。”
目前,多家專攻網(wǎng)絡(luò)安全的公司都在拼命爭奪來自汽車廠商的業(yè)務(wù)。
“我們的產(chǎn)品已經(jīng)通過了無數(shù)次網(wǎng)絡(luò)安全測試,經(jīng)過了不同廠商、多個汽車平臺的驗證。”Wood指出,“無一例外,我們的入侵檢測系統(tǒng)全部通過測試,表現(xiàn)遠(yuǎn)超過其他競爭對手的產(chǎn)品。”這說明,哈曼的入侵檢測系統(tǒng)及其OTA漏洞修復(fù)功能非常穩(wěn)定,適用于多個廠商的汽車平臺。
A vehicle’s engine tachometer needle rapidly jumps from zero to redline, dives back to zero, then repeats again and again—without a driver behind the wheel. An external source has taken control of your car.
“It’s called SMS spoofing. The hacker uses a cell phone or other electronic device to access the vehicle through the vehicle owner’s app for car settings, like doors lock/unlock," explained Geoffrey Wood, Director of Business Development North America for Cyber Security at Harman. "Our software can prevent that vehicle intrusion.”
Vehicle gauge mayhem and other remotely instituted cyber attacks on a parked vehicle were part of a recent demonstration at Harman’s North American automotive headquarters in Novi, MI.
Distracting the driver is troublesome and potentially dangerous, and it’s an absolute security risk if a hacker takes control of a vehicle’s braking and/or steering systems.
“Although automakers have taken numerous cyber security measures, to our knowledge no vehicle from any OEM is currently equipped with an intrusion detection system,” Wood told Automotive Engineering.
That could soon change. Harman is in discussions with automakers and Wood indicated that his company's intrusion-detection system could debut on a global vehicle platform in MY2019.
Harman is the only company providing an end-to-end cyber security vehicle solution via its TCUShield and ECUShield intrusion-detection systems and its Alerts Monitor backend cyber security analysis platform, Wood claimed. The company's 2016 acquisition of the Israeli cyber-software firm TowerSec added the TCUShield, which is integrated into infotainment systems and telematics units and ECUShield, embedded in ECUs, to Harman’s 5+1 security architecture.
Several suppliers offer cyber security detection solutions. But Harman engineers believe their company's end-to-end solution is a competitive advantage."You want all of the pieces to work together," Wood said, or else vulnerabilities within the overall solution are created.
One of the challenges with cyber security for vehicles is the limited memory space available on a module’s embedded micro controller.
“Intrusion detection systems are used in network management already, but those big servers have unlimited memory space,” explained Wood, “We’ve already seen network management specialist companies not be able to overcome the automotive world’s limited-space hurdle.”
Harman claims its intrusion-detection systems have passed various cyber security tests administrated by different OEMs. They provide a vehicle and Harman embeds its product on it, then calibrates and tunes it to the specific car or truck. Engineers then launch a cyber attack. "We have no clue beforehand what the attack will be,” Wood noted.
Several cyber security specialists are vying for business from automakers.
“We’ve gone through numerous cyber security tests at several different OEMs across several vehicle platforms," he reported. "And in every instance, our intrusion detection system has been proven to be best in class over the competitors." This has shown that Harman's intrusion- detection system and its over-the-air (OTA) vulnerability fix product is stable, regardless of the OEM or the vehicle platform, he added.
Author: Kami Buchholz
Source: SAE Automotive Engineering Magazine