Giving up control of our automobiles to a potentially fallible computer is a foreign concept to many of us. And yet, that’s what we do each time we climb behind the wheel of a car or truck. The trouble is, the computer between our ears is a lot slower and less consistent than the ones we build from silicon.
Autonomous cars will take some getting used to, even as they help us bring down the number of crashes and fatalities on our roads. But cybersecurity is a big part of the learning curve here ” maybe even more so than convincing people to give up the wheel. Here’s a look at where cybersecurity for autonomous vehicles is headed.
When Autonomous Cars Become Tools for Cyber Criminals
Researchers representing the U.S. Department of Transportation estimate that fully driverless cars could reduce fatalities on the road by as much as 94%. This is an unprecedented opportunity to save millions of lives over the coming years.
Driverless cars rely on software and hardware to engage in safe pathfinding. As more of these cars make their way onto our roads, we greatly increase our cybersecurity threat surface. Like any mobile computer, autonomous cars need to exchange data with other devices, servers and services in order to function.
From ride dispatch services to a family punching in directions for grandma’s house, driverless cars represent a huge amount of in-transit information. Since that information concerns details about our addresses and trip itineraries, the security software deployed to keep this data under wraps must be at least as robust as the security we use to protect our general online information.
How Hackers Can Turn Driverless Cars Against Their Drivers
Smartphones and ubiquitous computing are both incredibly useful. But as we now know, it takes technological savviness to use smartphones and mobile services with your personal privacy intact. We’re about to repeat this whole learning process with smart, internet-connected, driverless cars.
A case study from 2017 demonstrated some of the very real growing pains we’re set to experience as driverless cars take to the streets. Charlie Miller and Chris Valasek showed the world that it was possible to hijack the internet connections aboard Jeep, Ford, Toyota and other popular vehicles. They weren’t even working with a fully autonomous vehicle, yet the pair still managed to use the internet connection in a Jeep Cherokee to bring the vehicle to a stop on the highway.
And the real-world implications of this type of vulnerability are even worse than that. A truly unscrupulous outside party could also instruct the vehicle to turn or brake suddenly, causing untold havoc and tragedy if they wanted to. In the case of Toyota’s vehicles, Miller and Valasek turned a Prius’ collision avoidance tools against itself to brake the car without driver intervention.
Driverless cars contain safety-focused instrumentation and computer systems that could be made to deliver harm instead. But as we can see here, even standard cars with computer control systems demonstrate serious vulnerabilities.
Solving the Driverless Car Security Problem
We’ve gone past the tipping point for driverless cars, with billions of dollars of investments pouring into these projects from companies large and small. But before Uber or Tesla achieve their dreams of fleets of roaming robotic cars for hire, we need to know that the whole of the automotive industry is pulling in the same direction, cybersecurity-wise.
For instance: even a car’s ODB-II port ” where mechanics use tools to read and interpret vehicle error codes ” is vulnerable to physical and cyber-based attacks. This port could be used by criminals to introduce malware into the vehicle’s control systems.
We’re slowly learning what tools we need to keep ourselves safe, however. Machine learning provides one potential solution for this and other intrusion methods. If a car is equipped with machine learning-based security systems, it could use that system to keep and study logs of all connections in order to detect and isolate malicious activity or code automatically.
The Promise and the Threat of Driverless Cars
Charlie Miller, one of the researchers who hacked into that Jeep Cherokee in 2017, says that Autonomous vehicles are at the apex of all the terrible things that can go wrong with technology.
And he’s right. After the honeymoon phase of every major innovation, we have to reckon with the tradeoffs. For example, the internet can apparently break democracy if we let it. And maintaining a constant digital connection to everything and everybody on earth seems to foster a kind of dependence.
Autonomous cars stand a good chance of rescuing us from some of our worst habits. But before they can, private and public groups need to develop robust, industrywide standards for automotive cybersecurity. These efforts are already underway in the U.S., thanks in part to NHTSA-backed research at the Vehicle Research and Test Center in Ohio and other facilities.
Researchers are working to better understand the frameworks required to, among other things:
- Deliver timely over-the-air firmware updates for driverless vehicles to respond to emerging threats.
- Determine the different cybersecurity considerations for passenger and heavy vehicles.
- Deploy secure and reliable wireless vehicle-to-vehicle and vehicle-to-infrastructure communication protocols.
- More proactively share information between public and private entities for more successful collaborations against up-and-coming cyberthreats.
It seems we have the right voices and talent working to call attention to these matters and come up with solutions. Scepticism of new technologies is only right. But in the case of driverless cars, so long as we build a strong and secure foundation first, the reality is already beginning to live up to the promise.