{"id":61102,"date":"2019-11-16T00:02:45","date_gmt":"2019-11-15T16:02:45","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/different-industries-face-divergent-cyber-challenges\/"},"modified":"2019-11-16T00:02:45","modified_gmt":"2019-11-15T16:02:45","slug":"different-industries-face-divergent-cyber-challenges","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/different-industries-face-divergent-cyber-challenges\/","title":{"rendered":"Different Industries Face Divergent Cyber Challenges"},"content":{"rendered":"<\/p>\n<p>A major cybersecurity challenge for satellite manufacturers is that their products have to be designed to be beyond the reach of human hands for decades. Automobile companies face the opposite problem \u2014 their products have to spend 15 years or more being touched by human hands every day.<\/p>\n<p>Right to repair laws mean that \u201cEveryone has the right to perform maintenance on their vehicle without having to go to a dealer,\u201d <strong>Mitsubishi<\/strong> Automotive Cybersecurity Senior Manager Kristie Pfosi told CyberSat last week.<\/p>\n<p>And that means that system access and software tools required to modify onboard IT systems have to be public, she said. \u201cIt\u2019s basically like giving anyone who wants it administrator access to any vehicle.\u201d<\/p>\n<p>She added that market imperatives would likely drive auto manufacturers to monetize driver data to offset the costs of cybersecurity and other investments required to maintain connected cars.<\/p>\n<p>Market imperatives were also driving connectivity in the cruise industry, said Greg Sullivan, CIO of <strong>Carnival<\/strong> cruise line. Passengers were generating or accessing 10 to 12 GB data per second across the company\u2019s 105 vessels, he said.<\/p>\n<p>The successful hack of onboard driving controls on a Jeep Cherokee in 2015, when a <strong>Wired<\/strong> reporter was driven off the road by security researchers \u2014 and the subsequent federally ordered recall \u2014 really got the attention of the auto industry, explained Pfosi.<\/p>\n<p>Last year the industry spent $1.3 billion on cybersecurity and that is projected to rise to $6 billion over the next couple of years, she said. Cyberattacks were also on the rise, and the auto sector was seeing a quadrupling in the number of online attacks so far this year, compared to the whole of 2018.<\/p>\n<p>\u201cWe\u2019ve certainly got the attention of the hacker community. Yay!\u201d she joked.<\/p>\n<p>For the automobile industry, Pfosi said, cybersecurity defense in depth meant thinking about the much greater attack surface represented by long range connectivity like Wi-Fi, cellular or satellite, as opposed to short range like Bluetooth or direct access like USB ports. Long range attacks could reach thousands of vehicles, she said, whereas a direct physical access attacker might be able to reach only dozens.<\/p>\n<p>But right to repair laws \u2014 and the aggressive lobbying by their \u201cafter market\u201d supporters \u2014 seriously limited the security controls manufacturers could employ to limit direct physical access, she said.<\/p>\n<p>By law, every car has to have an On-Board Diagnostics (OBD) port. Once plugged into that port \u201cYou can do anything, you can read and write, you can flash the software \u2026 anything you want,\u201d Pfosi said.<\/p>\n<p>Efforts to introduce authentication requirements, or to require software updates to be cryptographically signed by the manufacturer \u2014 to prevent the introduction of malicious software to onboard systems \u2014 might fall foul of right to repair laws, Pfosi said.<\/p>\n<p>\u201cWe\u2019re seeing a lot of pushback,\u201d she said.<\/p>\n<p>An even bigger problem was the CANbus, a chip that connects the car\u2019s systems. Currently, the chip doesn\u2019t require any authentication: It\u2019s designed to implement any command it receives, without checking where it comes from.<\/p>\n<p>In the next generation of connected cars, \u201cWe have to make an architectural change \u2026 to introduce encryption and authentication,\u201d she said.<\/p>\n<p>\u201cWe need to have a way to know that a command to apply the brakes is a genuine command (from the driver), not coming from off board the vehicle,\u201d she said.<\/p>\n<p>A connected car generated as much as 4,000 GB of data per day, she said, and auto manufacturers were looking to monetize that, to pay for the networks and the software development required to keep connected cars updated.<\/p>\n<p>\u201cIn order to be able to support the cost of the infrastructure and even the cybersecurity (investments) \u2026&nbsp; there needs to be an offset revenue stream,\u201d Pfosi said.<\/p>\n<p>She said that cybersecurity vendors had priced the cost of regular updates to vehicle software at about $4 per vehicle per month. \u201cThat\u2019s not acceptable,\u201d as a cost that has to be eaten to an industry that makes design changes based on fractions of a penny change in the price of materials, she said.<\/p>\n<p>\u201cThere\u2019s no subscription plan that is palatable to the consumer today. There\u2019s no consumer demand (for cybersecurity), there\u2019s no regulation. We\u2019re doing this because it\u2019s the right thing to do and \u2026 also perhaps to avoid the risk and cost\u201d associated with a cyberattack.<\/p>\n<p>If for the consumer, the car purchase remained a one off capital expenditure, \u201cThere needs to be some backend revenue that\u2019s generated off that car, and that\u2019s a focus\u201d for the industry.<\/p>\n<p>Another focus of the industry was trying to create a cybersecurity aware workforce for the future, she said. \u201cWe are working with universities to build up a pipeline that doesn\u2019t exist today.\u201d<\/p>\n<p>In the meantime, the sector was seeking to \u201ceducate our current workforce so that they\u2019re not reliant on cybersecurity professionals to tell them how to design their products but can rely on the engineers who write the code, who interact with our products every day to take security into account from the very beginning,\u201d Pfosi said.<\/p>\n<p>Sullivan agreed that workforce training was key. Carnival was using training to \u201cdramatically raise cybersecurity awareness for all shipboard crew,\u201d he said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A major cybersecurity challenge for satellite manufacturers is that their products have to be designed to be beyond the reach of human hands for decades. Automobile companies face the opposite problem \u2014 their products have to spend 15 years or more being touched by human hands every day. Right to repair laws mean that \u201cEveryone [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61104,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-61102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/61102"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=61102"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/61102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/61104"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=61102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=61102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=61102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}