Showing posts with label embedded systems. Show all posts
Showing posts with label embedded systems. Show all posts

Sunday, May 16, 2021

Yes, embedded systems are important

 


Do you drive a car? have you in the last five years flown on an airplane? Have you purchased any goods that were shipped to your location? If you have answered Yes to any of these, then embedded systems have played a role in your life. 


Generally, you can separate the cybersecurity area of operations into enterprise and embedded systems. The enterprise is the system we learn so much about in school and for certifications. These are the efforts to secure servers, data located on these, communication, etc. Embedded systems are a bit different. These are the modules in your vehicle controlling and monitoring steering, tire pressure, GPS, and other functions required for the machinery to operate. 


While the functions are distinct, there is a complication. Each of these systems interacts with others. The data collected and commands are used by the other systems. This is especially the case as transportation systems become more connected and autonomous systems are used more. This includes vehicles, airplanes, farm equipment, and other equipment being engineered to operate without human interaction and direction. These systems need to communicate quickly and clearly. Imagine a vehicle of your choice, receiving incorrect or malicious information and data from a "trusted" source. With someone else in control, there could be immediate and serious consequences for anything in or near the equipment. 


All is not lost though. There are steps to assist with securing these systems. The first step is to conduct a threat assessment for the device or module. This has to be done end-to-end and includes all aspects, including hardware, software, data, communications, and anything else involved with the equipment. The analysis itself is static for that point in time. The analysis should be part of the product's lifecycle. When there is a change or update, this needs to be addressed again. The update may affect other parts of the system, and create other issues. 


The next step is to review the current advanced security designs and use these to the fullest extent possible. There are a number of these including virtualization and hypervisors. 


There are further steps to follow based on the individual environment. The important aspect to acknowledge is the embedded systems are very different and need to be tested and secured in a specific manner. 


Saturday, September 22, 2018

Vehicle Cybersecurity Positions are Difficult to Fill


Vehicle Cybersecurity Professionals-Still a Difficult Position to Fill
Charles Parker, II
>_

In the metro-Detroit area, the primary industry and revenue force is the auto industry. This is clearly due to the number and concentration of the vehicle manufacturer headquarters, assembly plants, and admin offices. As these vehicles are designed and engineered, they require cybersecurity testing. This ensures as much as possible the vehicles are safe and secure for being successfully attacks. Cybersecurity for the presently connected vehicles and future autonomous vehicles is paramount. Without this in place and the vehicles being active, directly tested, any vehicle on the road would not be safe itself or from other vehicles which could be hijacked.

To accomplish this vast task, the vehicle manufacturers require qualified people to complete the testing. This does not appear to be a significant issue. There are jobs to fill in a technology area creating a demand for years, and there should be people to fill the open positions. Unfortunately, this is not remotely the case. This is occurring presently in the field for many reasons. The primary reason for this is the available persons with this skill are limited. The persons with the skill and experience to test the cybersecurity of embedded, equipment is rather narrow. Of this narrow field, the applicants need to be vetted not only for their technological prowess but also for their ethics, as there are bad apples present who would not morally do the right thing 100% of the time. Based on this need/demand is far outpacing the demand. This is further exacerbated due to this need being across several industries, not only auto manufacturers.

As an option, the manufacturer may reach out to third parties to complete a portion of the testing. The manufacturer may also incorporate a bug bounty program into their process. Programs like this would pay the cybersecurity persons when they would find a bug in their product. By using a program as such there are a great number of persons reviewing the product and are paid for their time if a bug is found. GM and FCA’s Bug Bounty programs are well known.

There are a limited number of universities and colleges attempting to train persons for this vast need. There are also contests in which high school and college students may apply to be in to learn the basics. This will assist with increasing the pipeline for the cybersecurity talent.



Saturday, July 21, 2018

California Consumer Privacy Act of 2018 Applicability

California recently passed an aggressive data privacy law. The California legislature passed AB375 (The California Consumer Privacy Act of 2018), which by most accounts, is a strong push for consumer privacy. The law, in summary, requires companies collecting consumer data to disclose to the consumer the types of data collected and allowing the consumer the option of opting out from allowing the companies to sell the consumer’s data.

The new California law is a step towards the GDPR. This has much of the same intent, however, does not have the like exact goals, parameters, or negative reinforcement for not complying. Interestingly, the law requires the company to disclose the “category” of the third party receiving the consumer’s data, versus the name of the third party.

Consumers in California will, beginning on January 1, 2020 (the point at which the law takes effect), have the right to know all the data that has been collected for the individual consumer, to not allow their data to be sold, know what type of companies are receive the data, have their data deleted, the sources of the consumer data being sold, and other pertinent, germane facets of their data.

The headlines do indeed portray this as a far-reaching and direct victory for consumer rights. The general consumer thought is of this bringing the Google, Yahoo, and other internet-oriented companies to comply and be more transparent with their wishes. One should actually read the statute to garner a better understanding of the statute’s parameters. The California Consumer Privacy Act of 2018 does indeed affect businesses. As an example, section 1798.105 references a consumer’s right to request a business to delete any of the consumer’s personal information. On the initial reading, this would appear to affect all businesses collecting the personal information of a California citizen.

With this law, in general as it pertains to consumer’s data privacy, a business “...collects consumer’s personal information” (1798.140(c)(1)), has annual gross revenues greater than $25M (1798.140(c)(1)(A)), buys or receives the personal data of at least 50K consumers, households, or devices (1798.140(c)(1)(B), or derives 50% or more of the annual revenue from selling consumer’s personal information (1798.140(c)(1)(C)). As the statute is presently written, the “or” is important. Although this does narrow the potential field of companies having to comply to the statute, this would include the massive companies that comprise most of the work done in this endeavor. This statute also covers any device, which is any equipment that may connect to the internet or another device.

Embedded Devices
Embedded devices are throughout many industries and utilized with many devices consumers are in contact with daily, including vehicles. The connected vehicles have many opportunities to collect a consumer’s private information. If the person were to connect their cell phone to the vehicle with an app, the person’s contact list, smartphone call history, locations visited previously, credit card numbers, and other relevant data could be collected or in the least pass through the modules. With IoT devices, there may be present a portion of this data and other data points deemed confidential. These are only two examples of the many possible scenarios. In the present capacity, there is no legal advice and this is my opinion only, however, seemingly this new statute would apply to the embedded systems in vehicles, IoT devices, and other like devices collecting, processing, or managing a consumer’s private information and data in California. At this junction, this point is more of conjecture and to begin the thought process.

Is this were to be applicable to these systems, there would need to be completed much updating to the code for the present and future hardware, the affected policies, and noticing functions for the consumers.


Resources
California Legislative Information. (2018). Bill text - AB-375 Privacy: personal information: business. Retrieved from https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375

California Privacy. (n.d.). Californians for consumer privacy applauds successful passage of groundbreaking legislation. Retrieved from https://www.caprivacy.org/

Lecher, C. (2018, June 28). California just passed one of the toughest data privacy laws in the country. Retrieved from https://www.theverge.com/2018/6/28/17509720/california-consumer-privacy-act-legislation-law-vote