UPSTREAM-2021年全球汽车网络安全报告(英文)-2021.1-76页_7mb
报告摘要
Summary of the Upstream Security 2021 Report: Cyber Attack Trends in the Automotive Industry
Core Content
This report provides an in-depth analysis of the evolving cybersecurity landscape in the automotive industry, focusing on the rise of connected vehicles, the increasing number of cyber threats, and the role of the deep and dark web in facilitating these attacks. It also outlines the impact of cybersecurity standards and regulations, the effect of the pandemic on the industry, and the major attack vectors used by cybercriminals.
Main Points
Connected Vehicles: A Growing Reality
- By 2023, connected vehicles are expected to account for 25% of all passenger cars globally.
- By 2025, they will make up nearly 86% of the global automotive market, far more sophisticated than the first connected car models from the 1990s.
- Connectivity enhances vehicle functionality, user experience, and autonomous driving, but also introduces new vulnerabilities and attack surfaces.
- Data sharing is a core feature of connected vehicles, enabling telematics, smart mobility, and other services, but also making them attractive targets for cybercriminals.
Cyber Threat Landscape
- The number of malware has increased from 65 million in 2011 to 1.1 billion in 2020.
- Over 11,000 CVEs were registered in the first 10 months of 2020.
- Cybercrime is more profitable than the global illegal drug trade, generating $600 billion annually.
- Connected vehicles are a high-value target for nation-states and financially-motivated actors, with the potential to cause life-threatening consequences due to their integration with critical infrastructure.
Key Cyber Threat Trends in 2020
Top 2020 Cyber Incidents
- 4,118 vehicles were stolen in India using cheap electronic devices to bypass the engine control module.
- A Mobileye 630 PRO and Tesla Model X were hacked to manipulate ADAS and autopilot systems.
- 19 vulnerabilities were found in a Mercedes-Benz E-Class car, allowing remote control of the vehicle.
- A hacker took full control of an OEM's corporate network by exploiting the TCU and using the telematics connection.
- Passwords and API tokens for Daimler's internal systems were exposed after a component's source code was leaked.
- 3.5 million Zoomcar users' data was offered for sale on the dark web.
- Toll Group suffered a ransomware attack affecting 1,000 servers and 40,000 employees.
- Honda halted production after a Snake ransomware attack on its networks.
- Over 300 vulnerabilities were found in 40 ECUs from 10 Tier-1 companies and OEMs.
- A hacker gained control of Tesla's entire connected vehicle fleet by exploiting a server-side vulnerability.
Attackers and Motives
Types of Hackers
- White Hat Hackers: Actively discover and report vulnerabilities, often for security validation or bug bounties.
- Black Hat Hackers: Motivated by personal gain or malicious intent, often targeting connected vehicles for data theft, remote control, or ransomware.
- Gray Hat Hackers: Use vulnerabilities for personal benefit, sometimes exposing them to third parties or exploiting them for unauthorized access.
Black Hat Dominance
- 49.3% of incidents from 2010 to 2020 involved black-hat hackers.
- In 2020, 54.6% of incidents were attributed to black-hat attacks.
- These attacks can lead to life-threatening outcomes, such as remote vehicle control and data breaches.
Attack Vectors
Most Common Attack Vectors
- Server Attacks: 73% of 2020 incidents involved server-based attacks.
- Keyless Entry Systems: 25.3% of 2020 incidents used keyless entry fobs as an attack vector.
- Mobile Apps: 9.9% of incidents from 2010 to 2020 involved mobile apps.
Remote vs. Physical Attacks
- Remote attacks outnumbered physical attacks by a 79.6% margin from 2010 to 2020.
- 20.7% of all attacks in 2020 were physical.
- Remote attacks are more scalable and less detectable, often using network connectivity (e.g., Wi-Fi, Bluetooth, 5G).
Impact of Cyber Attacks
- Cyber attacks on connected vehicles can lead to data breaches, vehicle theft, remote control, and physical harm to users.
- Ransomware attacks, such as those on Toll Group and Volkswagen, disrupted operations and data security.
- The FBI reported over 4,000 daily complaints of cyber attacks in 2020.
- Interpol noted an "alarming rate" of cyber attacks across all industries, including automotive.
Standards and Regulations
Key Regulations
- UNECE WP.29 cybersecurity regulations were adopted in 2020, requiring OEMs to demonstrate cyber-risk management across the vehicle lifecycle.
- ISO/SAE 21434 is a draft standard aiming to establish automotive cybersecurity practices.
- These regulations are a paradigm shift in the automotive industry, emphasizing security by design and OTA updates for post-production fixes.
Role of the Deep and Dark Web
- The deep and dark web serves as a communication hub for automotive cybercriminals, enabling anonymous collaboration and data trading.
- Private forums and Telegram accounts are used to share hacking techniques, toolkits, and sensitive data.
- Automotive data is frequently traded on the dark web, including user information, vehicle credentials, and API tokens.
- OEMs are advised to monitor and understand the deep and dark web to prevent cyber attacks and protect their ecosystems.
Conclusion
- Connected vehicles are here to stay and will dominate the market by 2025.
- The automotive industry is increasingly vulnerable to cyber attacks due to data proliferation, software complexity, and network connectivity.
- Black-hat hackers pose the greatest threat, with server attacks being the most common.
- The deep and dark web plays a critical role in cybercrime and data exploitation.
- Cybersecurity standards like WP.29 and ISO/SAE 21434 are essential in shaping the future of automotive security and ensuring safe operations.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载