Next cyber attack targets: Cars?

A photo illustration of mock passengers as computers. Cars now carry electronics and thousands of lines of code.

Story highlights

  • A landmark study suggested cars could one day become the victim of cyber attacks
  • Cars already contain a huge amount of electronics controlled by thousands of lines of code
  • Mobile phones, internet access, bluetooth connections all open doors for hackers
  • Unlike a PC, a cyber attack on a car could result in the loss of life

The dashboard clock starts to count down from 60 to zero and, unprompted, the car horn begins to honk. The driver looks on helplessly as cyber criminals mount a vehicle "self-destruct" attack, killing the engine and locking the passenger doors.

This is not a scene from a Hollywood movie but a scenario tested by researchers at the University of California San Diego and the University of Washington.

Their landmark study suggested cars could one day become the victim of cyber attacks that compromise electronic systems and endanger passenger safety.

Cars long ago ceased being purely mechanical machines and already contain a huge amount of electronics controlled by thousands of lines of software code which relay critical data over onboard computer networks.

As vehicles are integrated with mobile phones and gain internet access, bluetooth connections, infotainment services, diagnostics, telematics and downloadable apps, there is a risk they could suffer the same viruses and malicious cyber attacks that bedevil other IT systems. Unlike a PC, where the biggest risk lies in losing data, a cyber attack on a car could result in the loss of life.

Carmakers and suppliers say that this is currently a purely theoretical problem and there are no known cases of a cyber attack causing a car to crash.

Cars are also a less financially attractive target for cyber attackers than, say, a bank, and there are easier ways for criminals bent on sabotaging or damaging a vehicle than hacking into it.

Lamborghini sales still in the fast lane
Lamborghini sales still in the fast lane

    JUST WATCHED

    Lamborghini sales still in the fast lane

MUST WATCH

Lamborghini sales still in the fast lane 04:12
PLAY VIDEO
Electric cars and more at L.A. Auto Show
Electric cars and more at L.A. Auto Show

    JUST WATCHED

    Electric cars and more at L.A. Auto Show

MUST WATCH

Electric cars and more at L.A. Auto Show 02:23
PLAY VIDEO
Driverless car now legal in California
Driverless car now legal in California

    JUST WATCHED

    Driverless car now legal in California

MUST WATCH

Driverless car now legal in California 01:02
PLAY VIDEO
Google's self driving Prius
Google's self driving Prius

    JUST WATCHED

    Google's self driving Prius

MUST WATCH

Google's self driving Prius 02:14
PLAY VIDEO
Driverless car navigates Berlin
Driverless car navigates Berlin

    JUST WATCHED

    Driverless car navigates Berlin

MUST WATCH

Driverless car navigates Berlin 05:09
PLAY VIDEO

Nevertheless, hackers are often not motivated by financial gain but wish simply to prove their ability to crack a system for the bragging rights.

Therefore as the industry moves towards a future of "autonomous" driving where vehicles are able to steer and brake by themselves, carmakers are also waking up to the potential risks of the "connected vehicle" and investing significant resources to prevent safety-critical systems from being compromised.

"We are very much aware that we have to build firewalls into systems. As vehicles gain WiFi hotspots . . . there are more and more intrusion possibilities," says Hans Roth, director of technology marketing at Harman, the car audio and entertainment supplier. "We don't want that kind of thing to happen that [the car] is being hacked."

Indeed, safety is of paramount concern for the industry, not least because in the event that vulnerabilities or faults are discovered, vehicle recalls can be hugely expensive.

Dirk Hoheisel, board member responsible for automotive electronics and car multimedia at Bosch, the supplier, says: "Currently I don't think we have an issue -- because we have only internet connections to the infotainment system that displays information -- it's not really going deep in the architecture of the car . . . But in the next years we will have to discuss the issues that could come up."

Carmakers and suppliers have identified a number of ways to protect vehicles from hackers. One is to keep safety-critical control units such as anti-lock brakes and engine controls on a separate network from those that relate to infotainment, for example.

Although these internal networks must sometimes communicate with one another -- to display vehicle data on the head unit display, for example -- they do so via a highly secure central gateway. Often these internal vehicle networks run different operating systems, which in turn provide a kind of natural firewall.

Second, carmakers are increasingly vigilant about the software and data they allow to enter the vehicle. For example, when a Mercedes-Benz driver requests data from the internet, this is processed via an external Daimler back end server. The data then move to the car via a secure virtual private network connection.

Many carmakers now offer customers downloadable apps such as via Toyota Motor's Touch, Ford's Sync and Chrysler's Uconnect systems. However, these tend not to be fully open but rather offer a limited number of secure, approved apps.

Mr Hoheisel, at Bosch, says: "At the moment we don't have open app stores in the car industry -- these are really protected and shielded systems."

A Ford spokesman says that "the safety, privacy and security of our customers is paramount" and therefore any software updates are "code-signed" and must be recognised as coming from Ford in order to update its Sync system.

Third, carmakers have begun probing their vehicles for cyber vulnerabilities and modelling potential attack scenarios to ensure the electronics architecture is secure. Last year Bosch acquired Escrypt, a specialist in embedded system security technologies for the automotive industry. "Together with Escrypt we can offer analytics to carmakers and tier one suppliers to improve their architectures," says Mr Hoheisel.

Daimler has an in-house team that focuses exclusively on vehicle IT security and it also commissions external audits to test its vehicles for vulnerabilities.

"The car is becoming a connected device . . . so this [hacking] scenario exists and we recognise this and are very occupied with the subject of security," says Ralf Lamberti, head of telematics at Daimler's research department. "But we also have to recognise that those who style themselves as cyber criminals, or hackers, are also looking at it . . . which means that, sooner or later there could be this kind of [hacking] attempt."

        CNN Business

      • An Iraqi worker adjusts a control valve at the Daura oil refinery on November 5, 2009 in Baghdad, Iraq. Iraq and a grouping of U.S and European oil companies Exxon Mobil Corp and Royal Dutch Shell PLC signed a $50 billion contract today to develop the West Qurna oilfield, two days after the Iraqi South Oil Company signed a technical service contract with Britain's BP and China's CNPC to develop the Rumaila oilfield. The Iraqi government is trying to attract foreign investment, especially in the oil sector, in hopes of reviving its war-torn economy. Iraq has the third largest oil reserve in the world but it is producing way below its potential. (Photo by Muhannad Fala'ah/Getty Images)

        Why are Iraq oil markets stable?

        Airstrikes, rebels seizing control of oil fields, plus a severe refugee crisis are a recipe for market panic. So why are Iraq oil prices stable?
      • A view of gloves and boots used by medical staff, drying in the sun, at a center for victims of the Ebola virus in Guekedou, on April 1, 2014. The viral haemorrhagic fever epidemic raging in Guinea is caused by several viruses which have similar symptoms -- the deadliest and most feared of which is Ebola. AFP PHOTO / SEYLLOU (Photo credit should read SEYLLOU/AFP/Getty Images)

        Ebola's economic 'scare factor'

        The biggest Ebola outbreak in history is taking its toll in Western Africa, hitting some of West Africa's most vulnerable economies.
      • People enter a casino in Las Vegas, Nevada, on April 18, 2009. Las Vegas is the most populus city in the US state of Nevada and internationally renowned major resort city for gambling, shopping, fine dining and entertainment. Las Vegas which bills itself as the �Entertainment Capital of the World� is famous for the number of casino resorts and associated entertainment. AFP PHOTO/Jewel SAMAD (Photo credit should read JEWEL SAMAD/AFP/Getty Images)

        Casinos beat the banker

        Macau has overtaken Switzerland in the wealth stakes, being named the world's fourth richest territory by the World Bank.
      • spc marketplace middle east ata atmar a_00010015.jpg

        Bateel's new bakery venture

        Saudi Arabian Bateel brand is best known for its delectable dates but it now has more than a dozen cafes and a new bakery in the works.
      • Vantablack designed by Surrey NanoSystems absorbs 99.96% of all light. It however will not be the solution to the creating the world's ultimate slimming black dress! A dress made out of this material would render the curves and contours of the human body invisible and would leave the wearer looking like 'two dimensional cardboard cut-out.'

        Is this the real new black?

        A British nanotech company has created what it says is the world's darkest material. It is so dark the human eye can't discern its shape and form.
      • Move over Siri, here comes Jibo

        Jibo robot is designed to be an organizer, educator and assist family members. CNN's Maggie Lake met him and says she was impressed with his skills.
      • A picture taken on March 15, 2014 shows children playing at the sprawling desert Zaatari refugee camp in northern Jordan near the border with Syria which provides shelter to around 100,000 Syrian refugees. Syrian refugees in the seven-square-kilometre (2.8-square-mile) Zaatari camp in Jordan fear that President Bashar al-Assad's likely re-election this year will leave their dream of a return home as distant as ever. The brutal war in Syria between the regime and its foes shows no sign of abating and has killed at least 146,000 people since it erupted in mid-March 2011. And 2.5 million Syrians have fled abroad and another 6.5 million have been internally displaced. Jordan is home to more than 500,000 of the refugees.

        Jordan: Seeking calm in chaos

        Sandwiched in between Iraq and Syria, Jordan's destiny seems to be one of a constant struggle for survival. John Defterios explains.
      • SHEFFIELD, ENGLAND - NOVEMBER 18: Queen Elizabeth II wears 3 D glasses to watch a display and pilot a JCB digger, during a visit to the University of Sheffield Advanced Manufacturing Research centre, on November 18, 2010 in Sheffield, England. (Photo by John Giles - WPA Pool/Getty Images)

        Forget 3D, it's 4K now

        At the last football World Cup, it was all about 3D. This time around, it's nothing less than 4K.
      • An Iraqi worker adjusts a control valve at the Daura oil refinery on November 5, 2009 in Baghdad, Iraq. Iraq and a grouping of U.S and European oil companies Exxon Mobil Corp and Royal Dutch Shell PLC signed a $50 billion contract today to develop the West Qurna oilfield, two days after the Iraqi South Oil Company signed a technical service contract with Britain's BP and China's CNPC to develop the Rumaila oilfield. The Iraqi government is trying to attract foreign investment, especially in the oil sector, in hopes of reviving its war-torn economy. Iraq has the third largest oil reserve in the world but it is producing way below its potential. (Photo by Muhannad Fala'ah/Getty Images)

        Where is Iraq's oil?

        Iraq produces 3.3 million barrels per day and has the world's fourth-largest oil reserves. But the current crisis is putting all this in danger.
      • Valves of gas pipe-line are seen in the gas station not far from Kiev on March 4, 2014. The European Union will help Ukraine pay the $2.0 billion it owes to Russian gas giant Gazprom, a top official said Tuesday, as part of an aid package reportedly worth more than one billion euros. AFP PHOTO/ ANDREY SINITSIN (Photo credit should read ANDREY SINITSIN/AFP/Getty Images)

        Why Europe needs Russian gas

        The gas standoff between Russia and Ukraine could have a knock-on effect on Europe. Explore this map to find out why is the EU nervous.