{"id":18847,"date":"2024-06-04T07:58:36","date_gmt":"2024-06-04T06:58:36","guid":{"rendered":"https:\/\/staging2022.42crunch.com\/?p=18847"},"modified":"2024-06-04T08:08:26","modified_gmt":"2024-06-04T07:08:26","slug":"buckle-up-and-protect-your-ride-the-importance-of-api-security-for-the-connected-vehicle","status":"publish","type":"post","link":"https:\/\/staging2022.42crunch.com\/buckle-up-and-protect-your-ride-the-importance-of-api-security-for-the-connected-vehicle\/","title":{"rendered":"Buckle Up and Protect your Ride. The Importance of API Security for the Connected Vehicle"},"content":{"rendered":"

Last week 42Crunch and VicOne, a Trend Micro subsidiary, announced a unique and vitally important partnership for the automotive industry. Our partnership is the first of its kind to address the mission critical role API security plays for automotive manufacturers as the software driven vehicle becomes an increasingly vulnerable attack surface for rogue actors.<\/p>\n

Automotive: Another Attack Surface<\/strong><\/p>\n

In today’s interconnected world, the automotive industry is experiencing a rapid transformation, with vehicles becoming increasingly connected and reliant on digital technologies. From advanced infotainment systems to autonomous driving features, modern vehicles are equipped with a myriad of sensors, processors, and communication interfaces that enable seamless interaction with the external environment and backend systems.
\nVehicles are now more interconnected than ever before, with numerous electronic control units (ECUs) and communication interfaces. This interconnectedness delivers many benefits from improved vehicle performance, enhanced infotainment experiences, and ultimately greater convenience, but also increases the potential attack surface for cyber threats, as malicious actors seek to exploit vulnerabilities to gain unauthorized access or control over vehicle systems. Witness for example the vulnerabilities identified by researcher Sam Curry last year in automotive APIs and software from several automotive suppliers<\/a>.<\/p>\n

VicOne\u2019s own research also indicates that between the second half of 2022 and the first half of 2023 API related attacks accounted for 12% of all cyber attacks on automotive players.1<\/sup><\/p>\n

\"\"<\/p>\n

In 2023 these attacks tended to be concentrated in North America and Europe, continuing the same trend seen in 2022. In terms of general security incidents, however, Asia\u2013Pacific had a notable share of reports, especially in the first half of 2023. 2<\/sup><\/p>\n

\"\"<\/p>\n

\u201cWhereas automotive cybersecurity not long ago focused almost exclusively on in-vehicle APIs, it must today account for API attacks within and among vehicles, the cloud and mobile. This partnership brings together 42Crunch\u2019s proven expertise in API security and ours in automotive cybersecurity to enable a solution engineered for the new, more complex reality in this industry.\u201d<\/p>\n

Max Cheng
\n<\/span>CEO
\n<\/span>VicOne<\/span><\/p><\/blockquote>\n

Regulations & Standards Mandate API Protection<\/strong><\/p>\n

Thankfully, unlike some other industries,\u00a0 the leading global standard institutions have launched initiatives to address these challenges being faced by the auto industry. They have created a common set of cybersecurity procedures and practices specific to the manufacturing and development of the connected vehicle for all manufacturers to adhere to.<\/p>\n

ISO 21434
\nThe International Standardization Organization (ISO) and the Society of Automotive Engineers (SAE) published the \u201cRoad vehicles\u2014Cybersecurity Engineering\u201d standard 21434 as a framework for engineering cybersecurity into a vehicle.<\/p>\n

UN R155
\nIn parallel, the United Nations Economic Commission for Europe (UNECE) published the WP.29 R155 regulation that requires original equipment manufacturers (OEMs) to prove that their vehicle software and connected ecosystem have gone through rigorous cybersecurity measures during development and after production. Failure to do so means an OEM would not be able to sell their vehicles in UNECE-regulated markets until they remediate cybersecurity gaps.<\/p>\n

These standards and regulations are very rigorous and relate to protection of not only the in-vehicle software but anything that can remotely change or query the state of a vehicle. Cyber relevant off-vehicle areas of reference include manufacturing provisioning, service tools, OTA software updates, backend-end services and APIs.<\/p>\n

Achieving compliance with this ISO standard and UN regulation points towards the need for OEMs and automotive industry suppliers to implement robust API security measures to mitigate cyber threats and protect consumer safety not just at the time of manufacturing the vehicle, but throughout the vehicle\u2019s lifecycle.<\/p>\n

API Security – Under the Hood<\/strong><\/p>\n

The reasons why international bodies are regulating for OEMs\u00a0 to implement API security strategies are manifold, let\u2019s take a look.<\/p>\n

    \n
  1. Data Protection<\/strong>: Connected cars generate and exchange vast amounts of data, including sensitive information such as location data, vehicle diagnostics, and driver behavior. Secure APIs are essential for protecting this data from unauthorized access, interception, or tampering, ensuring the privacy and safety of vehicle occupants.<\/li>\n
  2. Remote Access<\/strong>: Many connected car features, such as remote start, lock\/unlock, and vehicle diagnostics, rely on APIs to communicate with backend systems and mobile applications. Secure APIs are necessary to prevent unauthorized parties from exploiting these functionalities to gain control over the vehicle, potentially leading to theft, sabotage, or safety hazards.<\/li>\n
  3. Integration with Third-party Services<\/strong>: Connected cars often integrate with various third-party services, such as navigation apps, music streaming platforms, and smart home systems, via APIs. Securing these APIs is essential to prevent malicious actors from compromising the vehicle’s functionality or accessing sensitive data through unauthorized integrations.<\/li>\n
  4. Safety and Reliability<\/strong>: In addition to protecting data and preventing unauthorized access, API security is crucial for ensuring the safety and reliability of connected car systems. Vulnerabilities in APIs can be exploited to manipulate vehicle operations, disrupt critical functions, or cause accidents, posing significant risks to vehicle occupants and other road users.<\/li>\n<\/ol>\n

    Comprehensive\u00a0 API Security Across the SDV and Connected-Vehicle Ecosystem\u00a0<\/strong><\/p>\n

    The partnership announced last week builds on the success both 42Crunch and VicOne have already had in the automotive sector. Now, by combining 42Crunch’s expertise in the field of automotive API security with VicOne\u2019s dedicated xNexus Vehicle Security Operations Center into a joint offering, OEMs will benefit from broad protection across their vehicle, cloud and mobile ecosystems. \"\"<\/p>\n

    Not only will the software driven vehicle be a more secure experience, the OEMs will also be able to demonstrate their compliance with industry standards and regulations. Cybersecurity testing such as functional testing, interface testing, penetration testing, fuzz testing, and vulnerability scanning are used to provide evidence of a product\u2019s compliance. The xNexus VSOC and 42Crunch platform can provide real-time visibility and insights into anomalous vehicles and connected ecosystem behaviors, security incidents, events and conditions, and responses to mitigate any threats that are detected.<\/p>\n

    May the road rise before you<\/strong>
    \nMy Irish colleagues sometimes quote an old saying that is appropriate for this initiative by our two companies:\u00a0 \u201cMay the road rise before you, and the wind be always at your back\u201d.\u00a0 The harmonizing of cybersecurity standards and practices across the automotive industry promoting trust, transparency, and resilience augurs well for the connected and automated vehicles.<\/p>\n

    Leveraging our respective capabilities, OEMs are now better placed to address their API security and broader cybersecurity concerns, ensuring the safety and integrity of their software-driven vehicles in this connected world and delivering greater consumer confidence in their marques.<\/p>\n

     <\/p>\n

    1<\/sup> https:\/\/documents.vicone.com\/reports\/automotive-cyberthreat-landscape-report-2023.pdf
    \n2<\/sup> https:\/\/documents.vicone.com\/reports\/automotive-cyberthreat-landscape-report-2023.pdf<\/p>\n","protected":false},"excerpt":{"rendered":"

    Last week 42Crunch and VicOne, a Trend Micro subsidiary, announced a unique and vitally important partnership for the automotive industry. Our partnership is the first of its kind to address the mission critical role API security plays for automotive manufacturers as the software driven vehicle becomes an increasingly vulnerable attack surface for rogue actors. Automotive: […]<\/p>\n","protected":false},"author":16,"featured_media":18857,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"none","_seopress_titles_title":"Addressing the mission critical role API security plays for automotive manufacturers","_seopress_titles_desc":"","_seopress_robots_index":"","site-sidebar-layout":"default","site-content-layout":"disabled","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"disabled","ast-hfb-above-header-display":"disabled","ast-hfb-below-header-display":"disabled","ast-hfb-mobile-header-display":"disabled","site-post-title":"disabled","ast-breadcrumbs-content":"disabled","ast-featured-img":"disabled","footer-sml-layout":"disabled","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[6],"tags":[],"class_list":["post-18847","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts\/18847"}],"collection":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/comments?post=18847"}],"version-history":[{"count":2,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts\/18847\/revisions"}],"predecessor-version":[{"id":18854,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/posts\/18847\/revisions\/18854"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/media\/18857"}],"wp:attachment":[{"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/media?parent=18847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/categories?post=18847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging2022.42crunch.com\/wp-json\/wp\/v2\/tags?post=18847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}