News: 1666076294

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Japanese giants to offer security-as-a-service for connected cars

(2022/10/18)


Japanese industrial giants NTT Communications Corporation and Denso Corporation have decided to start a business “to respond to the threat of increasingly sophisticated cyber-attacks against vehicles.”

NTT Communications is a global IT services company that is a member of the NTT Group (which confusingly also operates NTT Data, another global IT services company). Denso is an auto parts maker that’s part of the Toyota empire.

The two companies have collaborated on vehicle security for a few years now, with NTT Communications bringing its consulting expertise around technologies such as networking, cloud computing, and managed infosec services such as building security operations centres for clients. Denso has shared its knowledge of just what goes on inside a car.

[1]

Now the pair have decided the time is right to productise those efforts by creating a “Security Operation Centre for Vehicles” that will offer at least the following four services:

Vehicle monitoring and cyber-attack detection by automating the acquisition of log output from communications, connected servers, and security devices installed within vehicles

Detection of cyber-attack trends along with the details of actual attacks against vehicles on an individual or fleet-wide basis

Analysis of cyber-attacks and threats by expert security analysts, reporting of results and forensic information that facilitates recovery and response efforts, and real-time visualization and alerting for customers through a client portal site

Vehicle security monitoring on a global scale

The two companies haven’t offered details of who they expect will become customers of the above services. The Register has asked if the VSOC will target individuals, fleet owners, manufacturers, or some other market, and will update this story if we receive a substantive reply.

Whatever the target market, we do know that the two companies believe the time is ripe for a VSCO service because “the number of vehicles facing threats from sophisticated cyber-attacks continues to grow.”

[2]

[3]

The pair therefore believe it has become “necessary to monitor connected cars, detect and analyze attacks at an early stage, and take appropriate measures.”

If they get it right, the two orgs believe they’ll “contribute to the realization of a safe and secure mobility society.”

[4]Oil company Castrol slips and slides into immersion cooling

[5]Sony, Honda collaborate on 'premium' electric vehicles that are born in the USA

[6]City isn't keen on 5,000 erratic, traffic-jam-causing GM robo-cars on its streets

[7]Update your Tesla now before the windows put your fingers in a pinch

The need for third party security services for cars is hard to dispute, as in these pages we have recently reported [8]a Bluetooth hack that makes it easy to steal a Tesla , a [9]horrid Hyundai hack , and a [10]hopelessly insecure Honda . our archives contain myriad other reports of crackable cars.

In the years since many of those stories were published, vehicles have become more connected, and more computerised, increasing attack surfaces and the likelihood of attack. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y055OKw-CtkjJrrap7b3yAAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y055OKw-CtkjJrrap7b3yAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y055OKw-CtkjJrrap7b3yAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2022/10/17/castrol_to_open_immersion_cooling/

[5] https://www.theregister.com/2022/10/13/sony_honda_to_collaborate_on/

[6] https://www.theregister.com/2022/09/27/gm_cruise_robocar_safety_waiver/

[7] https://www.theregister.com/2022/09/22/tesla_update_nhtsa_fingers/

[8] https://www.theregister.com/2022/05/17/ble_vulnerability_lets_attackers_steal/

[9] https://www.theregister.com/2022/08/17/software_developer_cracks_hyundai_encryption/

[10] https://www.theregister.com/2022/03/25/honda_civic_hack/

[11] https://whitepapers.theregister.com/



Kevin McMurtrie

The need for such a service makes me sad. I suppose it's followed by tech support saying, "We're very sorry your car was stolen. This issue will be fixed in the next model of your car. Would you like to purchase one now?"

Cybersecurity

The Man Who Fell To Earth

Security should be an ongoing obligation of automakers for at least 15 years after the unit was manufacrured. Legislation should be put in place with stiff penalties to back it up. Or is it the owners problem when a few years after purchase, the car can be opened and driven without a key?

Old timer doubleplus good...

NATTtrash

And again even more arguments to (keep) driving an old timer. Not only do they not look like your average hoover or fridge, they actually do as the driver instructs them to do unequivocally, while replacing a broken light bulb is possible without removing and replacing the complete front end of the car. They are even so dangerous that they will rely on your ability to make decisions, since they do not annoy nag distract warn? inform you all the time that they "need service in X days". So no need for all these "extra services" "preventing me to hurt myself" in my Karmann 14, thank you very much.

Up to the point when "autonomous, unassisted driving" will be prohibited by law that is...

Re: Old timer doubleplus good...

Mike 137

" So no need for all these "extra services" "

The need is not yours -- it's the need of pointless but opportunist vendors to generate a revenue stream. I'm waiting until some business starts offering a "guaranteed air supply" on subscription, but I'm not holding my breath.

Re: Old timer doubleplus good...

AnotherName

How about the manufacturers make the cars secure in the first place? Sort of like how they have to make them roadworthy, protect their occupants and other road users.

Re: Old timer doubleplus good...

Ball boy

What, like making a key fob that doesn't respond to a challenge/response call unless an accelerometer within it detects the fob is moving (that'd cut out midnight car theft at a stroke and should have been a standard feature from the outset) or the manufacturers realising that a car has to last many, many years, probably going without critical updates every few weeks (as we know we have to do with almost all other software-based devices) and still maintain rock-solid security?

Wishful thinking, I'm afraid: they rely on the insurance market picking up the pieces - and a cynic could argue that the industry as a whole benefits from car thefts because the missing vehicles have to be replaced. Not me: I'd never be caught uttering such a blasphemous and emotive statement.

sitta_europea

I can remember when they had contact breakers.

Wellyboot

And rendering the vehicle motionless took all of 30 seconds by removing the rotor arm.

"But I don't like Spam!!!!"