Showing posts with label Automotive Cybersecurity. Show all posts
Showing posts with label Automotive Cybersecurity. Show all posts

Friday, June 26, 2026

Review - HR 8560 Introduced – Advanced Automotive Tech

Back in April, Rep Stevens (D,MI) introduced HR 8560, the Shifting Forward Vehicle Technologies Research and Development Act. The bill would require DOE to conduct a research, development, and demonstration program of advanced vehicle technologies on more efficient, sustainable, and domestically available materials and manufacturing processes. It provides a five-year spending authorization for the program, starting at $530 million for FY 2027, increasing slightly in each of the following years. 

HR 8560 is similar to HR 5090, the Shifting Forward Vehicle Technologies Research and Development Act, that was introduced by Stevens in July 2023. No action was taken on that bill in the 118th Congress. That earlier bill did include one section dealing with cybersecurity assessments for on-road vehicles. This bill includes a virtually identical cybersecurity section. 

Moving Forward  

Stevens is a member of the House Science and Technology Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered by the Committee. Unfortunately, there are two issues related to this bill that would make support from the Republican leadership problematic at best. First is the large amount of new spending that would be authorized, over ½ billion dollars annually; the second is the focus on electric vehicles and alternative fuel vehicles. Either issue would be likely to block consideration of the bill. 


For more information on the cybersecurity provisions of this legislation, including a brief commentary on the pace of change to be expected, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-8560-introduced-advanced-automotive - subscription required. 

Tuesday, June 29, 2021

Review - HR 3262 Introduced – GUARD Act

Last month Rep Upton (R,MI) introduced HR 3262, the Guarding against Unauthorized Attacks Related to Driving (GUARD) Act. The bill would require DOT to submit to Congress a report on cybersecurity risks to motor vehicle safety.

Study and Report Required

Section 2 of the bill requires DOT to “conduct a study on the state of cybersecurity regarding motor vehicles”. In the process of conducting the study, DOT is required to address eight wide-ranging vehicle cybersecurity tasks, including:

• Identify each regulation, guideline, mandatory standard, voluntary standard, and other policy implemented by each Federal agency identified under this subsection and each guideline, mandatory standard, voluntary standard, and other policy implemented by industry-based and recognized international bodies,

• Review the technology, measures, guidelines, or practices used across the motor vehicle industry as of the date of the enactment of this Act to identify, protect, detect, respond to, or recover from cyber security incidents affecting the safety of a motor vehicle, focusing on the most advanced vehicle security solutions such as AI-driven vehicle security software,

• Identify existing cybersecurity resources to assist individuals in maintaining awareness of cybersecurity risks associated with motor vehicle safety and mechanisms for alerting a human driver or operator regarding cybersecurity vulnerabilities; and

• Identify means to protect vehicle occupants from cybersecurity incidents affecting safety that may arise while the motor vehicle is operating.

Moving Forward

Upton is a member of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that he likely has sufficient influence to see the bill considered in Committee.

I see nothing in the language of this bill that would engender any specific opposition. Given the importance that Congress is increasingly putting on cybersecurity issues, I suspect that this bill will receive significant bipartisan support, both in Committee and on the Floor of the House.

For a more detailed analysis of the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-3262-introduced - subscription required.

Thursday, May 25, 2017

Bills Introduced – 05-25-17

Yesterday with both the House and Senate in session there were 61 bills introduced. Of those one may be of specific interest to readers of this blog:

S 1225 A bill to support research, development, and other activities to develop innovative vehicle technologies, and for other purposes. Sen. Peters, Gary C. [D-MI]


This bill will only be covered here if it contains specific cybersecurity coverage for the innovative vehicle technologies described in the bill.

Monday, April 3, 2017

S 680 Introduced – Automotive Cybersecurity

Last month Sen. Markey (D,MA) introduced S 680, the Security and Privacy in Your Car (SPY Car) Act of 2017. The bill is essentially identical to S 1806 that was introduced in the 114th Congress. That earlier bill saw no action.

Moving Forward


Markey is a member of the Senate Commerce, Science, and Transportation Committee to which this bill was assigned for consideration. This means that it is possible that may have the political influence necessary to have the Committee consider the bill.

The multiple requirements for new regulations included in the bill, however, make it almost certain that neither the Committee nor the Senate as a whole will consider the bill. The anti-regulatory movement in the current Congress ensures that bills requiring major new regulations will have a difficult time being considered.

Commentary


As I noted in my earlier post on S 1806, this bill is a good first attempt at writing a comprehensive automotive cybersecurity bill. It is evident, however, that Markey and his staff (while being the closest thing to being cybersecurity policy wonks in the current congress) have some serious short comings in their knowledge of cybersecurity issues, particularly when it comes to control system security issues.

The other thing about this bill is that it points out a basic cybersecurity legislative problem, the need for sharing responsibility for cybersecurity between different agencies in the Federal government. In this case there are various requirements for the DOT’s National Highway Transportation Safety Administration (NHTSA) and the Federal Trade Commission work together on issuing the required regulations; with each taking the lead on different regulatory requirements.

While getting the two agencies to work together will prove to be difficult (bureaucratic silos have thick walls), ensuring that congressional committees with oversight over those agencies work well together may be even more difficult. For instance, with this bill, if Markey had included requirements that addressed the actions of the ICS-CERT (arguably the control system security experts within the Federal government) then the bill would have also been referred to the Homeland Security and Governmental Affairs Committee.


Curiously missing from this bill is any reference to Commerce Department’s National Institute of Standards and Technology (NIST). Surely in establishing any cybersecurity regulatory requirements one would expect the use of any of a number of areas NIST expertise in establishing technical standards would be helpful, particularly when many of those standards already exist.

Wednesday, March 22, 2017

Bills Introduced – 03-21-17

Yesterday with both the House and Senate in session there were 54 bills introduced. Of these four may be of specific interest to readers of this blog:

HR 1647 To establish a Water Infrastructure Trust Fund, and for other purposes. Rep. Blumenauer, Earl [D-OR-3]

HR 1653 To amend certain provisions of the Safe Drinking Water Act, and for other purposes. Rep. Latta, Robert E. [R-OH-5]

S 679 A bill to require the disclosure of information relating to cyberattacks on aircraft systems and maintenance and ground support systems for aircraft, to identify and address cybersecurity vulnerabilities to the United States commercial aviation system, and for other purposes. Sen. Markey, Edward J. [D-MA]

S 680 A bill to protect consumers from security and privacy threats to their motor vehicles, and for other purposes. Sen. Markey, Edward J. [D-MA]

The two water system bills will only receive further mention in this blog if they specifically address facility security or cybersecurity issues.


These two bills from Markey are almost certainly based upon bills that he introduced in the 114th Congress (S 2764 and S 1806 respectively). Neither bill saw any action in the previous session; perhaps it will be different this time.

Saturday, February 4, 2017

HR 701 Introduced – NHTSA Cybersecurity

Last month Rep. Wilson (R,SC) introduced HR 701, the Security and Privacy in Your (SPY) Car Study Act of 2017. The bill would require DOT’s National Highway Transportation Safety Administration (NHTSA) to conduct a study to determine appropriate standards for the regulation of the cybersecurity of motor vehicles.

The Study


The study would be required to address {§2(a)}:

• The isolation measures that are necessary to separate critical software systems from other software systems;
• The measures that are necessary to detect and prevent or minimize in the software systems of motor vehicles anomalous codes associated with malicious behavior;
• The techniques that are necessary to detect and prevent, discourage, or mitigate intrusions into the software systems of motor vehicles and other cybersecurity risks in motor vehicles, such as continuous penetration testing and on-demand risk assessments;
• Best practices to secure driving data collected by the electronic systems of motor vehicles;
• A timeline for implementing systems and software that reflect the measures, techniques, and best practices identified.

The bill requires a report to Congress within one year of passage of this bill. Presumably, then Congress would take necessary actions to pass legislation requiring implementation of the suggested program.

Moving Forward


Neither Wilson nor his co-sponsor {Rep. Lieu (D,CA)} are members of the House Energy and Commerce Committee, the committee to which this bill was referred for consideration. This means that the bill is unlikely to be considered by that Committee.

There is nothing in the bill that would draw substantial ire of any group. Since only a study is being required (with no spending to support the study) that could only serve to pass the buck to a future Congress, this bill would be adopted in committee if it was considered and subsequently passed if it made it to the floor of the House.

Commentary


The first major problem with this bill is that it fails to include the DHS ICS-CERT in the list of organizations with which NHTSA is required to consult in the conduct of the study. In fact, there is no mention of DHS, the agency designated by Congress to be responsible for cybersecurity matters, in the bill. This was almost certainly done to avoid the inevitable inter-committee conflicts that affect most homeland security legislation.

The major technical issue with this bill (other than the complete misuse/misunderstanding of technical terminology – ‘continuous penetration testing’???) is that it completely fails to address the communications issues that are an integral part of most any cyber threat. The current existence of in-car Wi-Fi nodes and the imminent future impact of vehicle-to-vehicle and vehicle-to-infrastructure communications systems cannot be overlooked in any study of automotive cybersecurity issues.


Finally, the bill overlooks the role of the independent security researcher in identification of cybersecurity vulnerabilities. Any cybersecurity study that fails to look at the relationships between such researchers, vendors and regulators is missing an important component of identifying and fixing cybersecurity vulnerabilities.

Monday, November 16, 2015

Congressional Hearings – Week of 11-15-15

This week the House and Senate return to Washington after their extended Veterans Day holiday. Currently there is only one hearing scheduled this week that may be of specific interest to readers of this blog; looking at automotive cybersecurity.

Auto Cybersecurity

The Transportation and Public Assets Subcommittee of the House Oversight and Government Committee will hold a hearing on Wednesday on “The Internet of Cars”. There is no witness list currently available.

On the Floor

There are two bills that will be considered under suspension of the rules in the House this week that may be of specific interest to readers of this blog:

HR 1073 - Critical Infrastructure Protection Act; and
HR 3996 – The Surface Transportation Extension Act of 2015, part II (introduced today)


HR 1073 is an electromagnetic pulse protection bill with no funding or regulatory authority. HR 3996 is another short term extension of the Surface Transportation Extension Act while the House and Senate Conferees work out the differences in the two versions of HR 22. The draft of the bill from the House Transportation Committee looks to be a relatively clean bill this time. Both bills will pass without significant opposition.

Wednesday, August 5, 2015

Amendments to S 754 – 08-04-15

While the Senate is trying to get S 754, the Cybersecurity Information Sharing Act  (CISA) of 2015, to a floor vote before leaving on their summer recess at the end of the week, a number of amendments are being submitted that may or may not be considered before the final floor vote. Yesterday, for instance there were 65 such amendments submitted. Of those amendments only four may be of specific interest to readers of this blog:

SA 2573. Mr. Flake (R,AZ), pgs S6306-07;
SA 2576. Mr. Markey (D,MA), pgs S6309-10;
SA 2608. Ms. Warren (D,MA), pg S6321; and
SA 2609. Ms. Warren, pg S6321

The Flake amendment deals with electric grid cybersecurity issues and is a virtual copy of HR 2271 which has yet to be acted upon in the House. Similarly the Markey amendment is a copy of S 1806; his bill on automotive cybersecurity issues.

The two amendments by Warren both deal with liability issues. The first ensures that the provisions of §6 (Protection from Liability) of the bill are not misconstrued to apply to organizations that do not take actions to “action to address a cybersecurity threat or a security vulnerability”. Similarly SA 2609 adds a new paragraph to §6 that specifically requires an entity that receives information “regarding a cybersecurity threat or a security vulnerability under this Act” to take actions to “to address the threat or vulnerability” or be liable.


As of this morning’s publication of yesterday’s Congressional Record there was no agreement in place as to what amendments would or would not be taken up prior to the final vote on S 754.

Friday, July 24, 2015

S 1806 Introduced – Auto Cybersecurity

Earlier this week Sen. Markey (D,MA) introduced S 1806, Security and Privacy in Your Car Act of 2015, or SPY Car Act of 2015. While this bill was introduced on the same day as the notorious Wired article about the Jeep Cherokee hack was published, this bill marks the culmination of an ongoing interest by Markey on this topic.

Definitions

The bill starts out by adding some new cybersecurity related definitions to 49 USC 30102. The following terms were added:

Critical software systems;
Driving data;
Entry points; and
Hacking.

Of the four the first and last two are most critical from a control system cybersecurity perspective.

The term ‘critical software systems’ was specifically limited to “software systems that can affect the driver’s control of the vehicle movement” {new §30102(a)(3)}. This means that other control systems related to signals, lights, locks and windshield wipers for example are excluded from the definition.

‘Entry points’ are those means by which someone can access driving data or through which control signals can be sent into the system. The term is specifically defined to include wired or wireless connections.

The term ‘hacking’ is given pretty broad definition as “the unauthorized access to electronic controls or driving data, either wirelessly or through wired connections”. There is no discussion of who (the auto manufacturer or vehicle owner) can provide authorized access.

Cybersecurity Standards

The bill then goes on to add a new section to 49 USC, §30129 addressing cybersecurity standards that would apply to vehicles manufactured two years after regulations implementing this new statute take effect. Three areas are covered in these standards:

Protection against hacking;
Security of collected information;
Detection, reporting, and responding to hacking.

The protection against hacking provisions require that the covered vehicles are {new §30129(a)(2)}:

Equipped with reasonable measures to protect against hacking attacks;
Incorporating isolation measures to separate critical software systems from noncritical software systems;
Evaluated for security vulnerabilities following best security practices, including appropriate applications of techniques such as penetration testing; and
Adjusted and updated based on the results of the evaluation.

The information security provisions of the new section deal with protecting the data collected by onboard ‘electronic systems’. The provisions include protecting data stored in the vehicle, in transit to undefined other locations, and in storage in those off-vehicle locations. The protected data is not limited to that obtained from ‘critical software systems’.

The final standard pertaining to hacking is the most broadly written. It states {§30129(a)(4)}:

“Any motor vehicle that presents an entry point shall be equipped with capabilities to immediately detect, report, and stop attempts to intercept driving data or control the vehicle.”

Once the regulations are written implementing these standards, violations of the standards could result in a civil penalty “of not more than $5,000 for each violation” {§30129(b)}. This paragraph references 49 USC 30165 for the application of this penalty so it is clear that the penalty could be assessed on each vehicle or part of a vehicle covered under the violation for up to a total of $5 million.

Privacy Protections

Section 4 of the bill relies on the Federal Trade Commission to provide additional privacy protections. The FTC is required to develop regulations addressing the following automotive information protection requirements {new 15 USC 57d}:

Notice of the collection, transmission, retention, and use of driving data collected from such motor vehicle;
The option of terminating the collection and retention of driving data;
Continued access to navigation tools or other features or capabilities; and
Prohibition of the use any information collected by a motor vehicle for advertising or marketing purposes without affirmative express consent by the owner or lessee.

Moving Forward

I think that thanks to Charlie Miller and Chris Valasek there is an increased understanding of the potential severity of the problem. This will be reinforced when they give their talk about the Jeep Cherokee hack at Black Hat next month. There will be some more hearings; probably including a command performance by Miller and Valasek with an FCA executive sitting at the table next to them. But some sort of legislation like this will almost certainly move forward during the 114th Congress.

Markey is a member of the Senate Commerce, Science and Transportation Committee which is tasked with considering this bill and the Subcommittee which will take the lead on this legislation. So he is in a good position to move this bill through the Committee side of the equation. It remains to be seen if he can convince Chairman Thune to work to move the bill to the floor.

With the surface transportation bill starting to move forward in the Senate, it would not be unusual for Markey to try to get this added to that bill as a floor amendment. It is a bit early in the process for this to be effective, but it would provide an interesting gauge of how well this type of bill would do on the floor of the Senate.

Commentary

The first problem that I see with this bill is that it relies on the DOT in consultation with the FTC to establish control system security regulations for automobiles. While I understand that DOT is responsible for automotive safety (and this is clearly a safety issue) I don’t believe that they have the necessary in-house expertise to establish and enforce workable automotive control system cybersecurity regulations.

While DHS has generally been given responsibility for cybersecurity regulations, I don’t think that anyone there has given any serious thought to control system cybersecurity regulatory issues. TSA, which has the transportation security mandate, certainly has not and their surface transportation security folks have over the last five years or so demonstrated a marked inability to get around to writing mandated security regulations.

What probably needs to happen here is that the bill needs to include ICS-CERT as a consultive partner on this regulatory scheme and that organization needs to be beefed up with some regulatory expertise to actually be of help in this type of situation. While we are talking about ICS-CERT we need to consider that they are going to have to add some expertise in automotive control systems as they are obviously going to have to be dealing with automotive control system issues going forward.

The next problem is the unnecessarily limited definition of ‘critical software systems’. In fact, limiting the problem to ‘software systems’ could be construed to eliminate large portions of the cyber-physical systems used to control modern motor vehicles. Given the recent work by Corey Thuen at Digital Bond Labs on can bus issues (see for example here) it seems to me that the definition of ‘critical software systems’ needs to be much more expansive. Even if we limit that definition to other cyber-physical systems like lights and windshield wipers, the definition needs to include all of the safety systems for the vehicle.

The bill needs to include specific provisions for the discovery, reporting and mitigating of new vulnerabilities once the vehicles are on the road. This will almost certainly be a function for the National Highway Transportation Safety Administration, but is needs to be specifically spelled out in the bill. This would have to include specific authority for NHTSA to order (if necessary) an automotive manufacturer to fix a cyber defect reported to NHTSA by a security researcher.

Finally, and perhaps most importantly, we are going to need to have a serious discussion about who can authorize access to the various electronic systems in vehicles. The automotive industry has long maintained that they own those systems and only license their use to the vehicle owner. This potentially means that a bill like this would make it a federal criminal offense for a non-manufacturer authorized auto shop to access information in the vehicle control system for diagnostic testing, much less make changes to the tuning specifications for the engine to improve engine performance or increase fuel efficiency. Because of the wide definition of hacking provided here, even changing out a vehicle sensor with a factory replacement by the owner could be considered hacking under the bill if the manufacturer is the only one who can authorize access.

As a serious first pass at automotive cybersecurity legislation this looks like a pretty good bill. It still needs a lot of significant work and some serious input from the control system security community.

Tuesday, June 23, 2015

Vehicle-to-Vehicle Communications Hearing

This afternoon the House Energy and Commerce Committee updated their web site for Thursday’s hearing on vehicle-to-vehicle (V2V) communications. The site now has a witness list, copies of the witnesses’ written testimony (NHTSA testimony is not yet available) and a Committee Staff document discussing the issues to be covered at the hearing.

The witness list includes:

Nat Beuse, National Highway Transportation Safety Administration (NHTSA);
Barry Einsig, Cisco;
Harry Lightsey, General Motors;
David St. Amant, Econolite Group, Inc; and
Peter Sweatman, University of Michigan Transportation Research Institute

There are a number of issues that will be discussed during this hearing. According to the staff document those issues will include answering the following questions (pgs 6-7):

How will a rulemaking requiring V2V communications in new vehicles impact used cars on the road today?
What driver education is necessary to prepare drivers to operate vehicles equipped with V2V capability?
How does the implementation of V2V technology foster the development of vehicle automation technologies?
How is the auto industry preparing a rollout that will allow this technology to evolve? Will any technological evolution require ongoing government oversight?
What is a realistic timeframe by which drivers will see the benefits of this technology?

Readers of this blog will quickly note that there is no specific mention of cybersecurity issues in the list above. The staff background document does note that NHTSA has made attempts to address the cybersecurity and personal information protection issues potentially associated with the V2V program. Following the comment period on their advance notice of proposed rulemaking (ANPRM) last year NHTSA issued a request for information (RFI) about the development and governance of a “Security Credential Management System” (SCMS) for the system.

There is at least a mention of these SCMS issues in the written testimony:

Einsig – “This network needs interoperability, standards-based technology, as well as a tested architecture for delivering a highly secure, mobile, and high availability solution.” (pg 3)

Lightsey – “National and international standards must be adopted to insure interoperability of V2V systems deployed by all auto makers and those deploying related V2I systems. A scaleable and operational security credential management system must be developed.” (pg 3)

St. Amant – “Efforts underway to create a Security Credential Management System (SCMS) for connected vehicles are critically important.” (pg 5)

Sweatman – “Current gaps requiring federal support include: Cyber-security solutions that suit both the vehicle and the infrastructure.” (pg 8)


In point of fact, these are the only significant mentions of cybersecurity issues in the four written testimonies submitted to the Committee. Of more concern is the fact that according to Sweatman Michigan has already constructed its first V2V/V2I enabled stretch of public road and Mr. Lightsey is announcing that GM will begin to sell its first V2V equipped vehicle, the 2017 Cadillac CTS, next year. Both of these have taken place before there is an established and accepted SCMS.

Wednesday, March 18, 2015

Bills Introduced – 03-17-15


Yesterday there were 54 bills introduced in the House and Senate. Four of these bills may be of specific interest to readers of this blog:


· HR 1385 - To provide for a legal framework for the operation of public unmanned aircraft systems, and for other purposes. Rep. Poe, Ted [R-TX-2]

· HR 1405 - To amend title 49, United States Code, to ensure railroad safety. Rep. Lipinski, Daniel [D-IL-3]

· S 754 - An original bill to improve cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes. Sen. Burr, Richard [R-NC]

· S 766 - A bill to limit the retrieval of data from vehicle event data recorders, and for other purposes. Sen. Hoeven, John [R-ND]


HR 1385 will probably address more than small unmanned aerial vehicles, but we will have to wait to see the details.


Lipinski's HR 1405 will almost certainly address crude oil train issues among other items.


S 754 is the much publicized bill from the Senate Intelligence Committee. The formal copy of the bill has not been published by the GPO yet, but earlier draft versions did specifically include industrial control systems in the definition of information systems covered by the bill. The bill was reported without a written report when it was introduced yesterday meaning that it can be brought to the floor at anytime the leadership desires. It will be interesting to see if and when this bill gets to the floor.
S 766 may have implications for cybersecurity of automobiles, but I won't be certain of that until we see the actual language.
 
/* Use this with templates/template-twocol.html */