Korea rehearsed a vehicle attack arriving through a supplier's OTA pipeline
MOLIT, KATRI, KISA, the National Police Agency and Hyundai Motor ran a joint incident-response exercise built around malware distributed to vehicles from a compromised parts supplier's server.
South Korea’s Ministry of Land, Infrastructure and Transport said it held a public-private joint incident-response exercise for automotive cybersecurity at Hyundai Motor’s Pangyo headquarters on September 15. The ministry’s announcement was released at 11:00 Korean time and marked for September 16 morning editions.
Five organizations took part: the ministry’s autonomous driving policy division, the Korea Transportation Safety Authority’s automobile safety research institute KATRI, the Korea Internet and Security Agency, the National Police Agency and Hyundai Motor. The exercise was run as a tabletop drill, and no vehicle or system was actually attacked.
The scenario began with an automotive parts supplier’s server being compromised, software carrying concealed malware being distributed to vehicles over the air, and vehicles then behaving abnormally. The ministry said that in a software-defined vehicle the effect of an attack extends from the individual car into the manufacturer and supplier chain.
Participants worked through five phases: detection, reporting and containment; cause analysis and coordination between agencies; short-term measures to restore vehicles; final measures closing the vulnerability and hardening supply-chain security; and an adequacy check before closing the incident. In sequence, Hyundai detected the anomaly and filed the report, KATRI conducted a technical review and reported to the ministry, KISA analyzed the intrusion, and the National Police Agency traced the attacker. Software distribution was halted, a corrected build shipped, and unremediated vehicles traced.
The ministry presented the exercise as a readiness check on Korea’s cybersecurity management system regime now that it is in force. Park Jun-hyung, director general of the ministry’s mobility and automobile bureau, was quoted on the rising sophistication of attacks against carmaker supply chains.
Source: MOLIT (Ministry of Land, Infrastructure and Transport)