Week 8 - Security of IoT Flashcards
What happened with the Mirai Botnet example?
Mirai is IoT malware that tracks IoT devices such as webcams and turns them into bots for DDOS
What happened with the Jeep IoT Attack?
Exploited the WiFi connection through brute force (password generated using default system time plus a few seconds during boot)
Took over the head unit’s system
They used a femtocell to get into Sprint’s internal network and scan the IP addresses that were listening to calls from these head-units (information they knew after gaining access via WIFI)
Access the controller Area Network bus by pivoting through a V850 controller
Name the automotive industry standards for IoT security
SAE J3061, J3061-1, J3061-2
– Cybersecurity Guidebook for Cyber-Physical Vehicle Systems
– Automotive Cybersecurity Integrity levels (now rolled into AWI ISO/SAE
21434)
– Security Testing Methods
• SAE J3101
– Requirements for hardware-protected security for ground vehicle
applications
• ISO/SAE AWI 21434
– Road vehicles: cybersecurity engineering