Experiencing a Security Incident? → 24/7 Response: +91 73059 79248
Briskinfosec
COMPANY
About Briskinfosec Scope My Security Program Our Clients Testimonials Careers Partnership
INDUSTRIES
Banking & Financial Services Healthcare Manufacturing Government Energy & Utilities Telecom Technology Retail & E-Commerce All Industries →
CONNECT
Contact Us Request Assessment Responsible Disclosure Client Certificate Verification Training Certificate Verification
SECURITY TESTING (VAPT)
Web Application VAPT Mobile App Security API Security Testing Cloud Security Assessment Network Security Audit IoT Penetration Testing OT/SCADA Security Database Penetration Wireless Security CREST VAPT
ADVANCED ASSESSMENT
Red Team Operations AI/LLM Security Audit Digital Forensics Cyber Intelligence Secure Code Review DevSecOps Hardware Security Thick Client Security Host Level Security Automotive VAPT Telecom VAPT
DATA & PRIVACY
Data Security Audit Data Privacy Audit Data Masking & Privacy DSPM Data Breach Simulation SBOM & SCA Website Security All Assurance Services →
COMPLIANCE FRAMEWORKS
ISO 27001:2022 SOC 2 PCI-DSS HIPAA GDPR DPDPA NIST CSF IRDAI ISO 22301 (BCP) ISO 42001 (AI) IEC 62443 (OT) ISO 21434 (Automotive) PDPL (Saudi)
GRC SERVICES
GRC Framework Cyber Risk Assessment Third-Party Risk (TPRM) Data Privacy Compliance Data Retention Policy National Security Compliance Cybersecurity Insurance All Compliance →
GOVERNANCE LAYER
Data Governance Security Posture Management Cybersecurity Maturity AI Maturity Assessment Cyber Resilience BCP/DR Planning vIT Compliance Business Impact Analysis
MANAGED SECURITY
Managed Security (MSSP) SOC as a Service V-CISO Incident Response Virtual Security Team Third Eye (Surveillance)
CONTINUOUS MONITORING
SOAR Integration Security Monitoring Threat Intelligence Platform Cyber Threat Intelligence Lateral Movement Detection Penetration Test as Service
DEFENSIVE OPS
Perimeter Security Access Control Review Cloud Config Review CDN Security Network Architecture Cloud Security Management Virtualization Security All MSSP Services →
ELITE ASSESSMENTS
Threat Modeling Ransomware Readiness Threat & Vulnerability Mgmt Military Grade Review Hacker's POV Assessment
HUMAN LAYER
Security Awareness Training Phishing Simulation Tabletop Exercise Secure Code Training Cybersecurity Culture Cybersec Leadership Incident Response Training Data Privacy Training
STRATEGIC SERVICES
Application Security Governance Quarterly AppSec Review Minimum Security Baseline Secure SDLC Cyber Sense Plan Integration Threat Analysis Infra Risk Assessment Web Extensions Security bSAFE Security Score Layered Security Philosophy All Maturity Services →
PLATFORMS
LURA Portal LuraInsight (SAST) bSAFE Score BriskBox All Products →
Staffing
LEARN
Blog Videos Case Studies Press Room
INTELLIGENCE
Threatsploit Reports Security Essentials Carousel Flyers & Downloads All Resources →
Briskinfosec is a CREST accredited cybersecurity firm, globally recognized for penetration testing and VAPT services Briskinfosec is a CERT-In empanelled cybersecurity company based in Chennai with global operations in Dubai
Get Your bSafe Score →
Briskinfosec
COMPANY
About Briskinfosec Scope My Security Program Our Clients Testimonials Careers Partnership
INDUSTRIES
Banking & Financial Services Healthcare Manufacturing Government Energy & Utilities Telecom Technology Retail & E-Commerce All Industries →
CONNECT
Contact Us Request Assessment Responsible Disclosure Client Certificate Verification Training Certificate Verification
SECURITY TESTING (VAPT)
Web Application VAPT Mobile App Security API Security Testing Cloud Security Assessment Network Security Audit IoT Penetration Testing OT/SCADA Security Database Penetration Wireless Security CREST VAPT
ADVANCED ASSESSMENT
Red Team Operations AI/LLM Security Audit Digital Forensics Cyber Intelligence Secure Code Review DevSecOps Hardware Security Thick Client Security Host Level Security Automotive VAPT Telecom VAPT
DATA & PRIVACY
Data Security Audit Data Privacy Audit Data Masking & Privacy DSPM Data Breach Simulation SBOM & SCA Website Security All Assurance Services →
COMPLIANCE FRAMEWORKS
ISO 27001:2022 SOC 2 PCI-DSS HIPAA GDPR DPDPA NIST CSF IRDAI ISO 22301 (BCP) ISO 42001 (AI) IEC 62443 (OT) ISO 21434 (Automotive) PDPL (Saudi)
GRC SERVICES
GRC Framework Cyber Risk Assessment Third-Party Risk (TPRM) Data Privacy Compliance Data Retention Policy National Security Compliance Cybersecurity Insurance All Compliance Services →
GOVERNANCE LAYER
Data Governance Security Posture Management Cybersecurity Maturity AI Maturity Assessment Cyber Resilience BCP/DR Planning vIT Compliance Business Impact Analysis
MANAGED SECURITY
Managed Security (MSSP) SOC as a Service V-CISO Incident Response Virtual Security Team Third Eye (Surveillance)
CONTINUOUS MONITORING
SOAR Integration Security Monitoring Threat Intelligence Platform Cyber Threat Intelligence Lateral Movement Detection Penetration Test as Service
DEFENSIVE OPS
Perimeter Security Access Control Review Cloud Config Review CDN Security Network Architecture Cloud Security Management Virtualization Security
ELITE ASSESSMENTS
Threat Modeling Ransomware Readiness Threat & Vulnerability Mgmt Military Grade Review Hacker's POV Assessment
HUMAN LAYER
Security Awareness Training Phishing Simulation Tabletop Exercise Secure Code Training Cybersecurity Culture Cybersec Leadership Incident Response Training Data Privacy Training
STRATEGIC SERVICES
Application Security Governance Quarterly AppSec Review Minimum Security Baseline Secure SDLC Cyber Sense Plan Integration Threat Analysis Infra Risk Assessment Web Extensions Security bSAFE Security Score → Layered Security Philosophy →
PLATFORMS
LURA Portal LuraInsight (SAST) bSAFE Score BriskBox All Products →
Staffing
LEARN
Blog Videos Case Studies Press Room
INTELLIGENCE
Threatsploit Reports Security Essentials Carousel Flyers & Downloads All Resources →
Home → Blog → Have You Known About Such Things In Conn...
Wireless Security

Have You Known About Such Things In Connected Cars?

August 20, 2019
9 min read
4,663 Views
Contents
Have You Known About Such Things In Connected Cars?

Contents:

  • Introduction
  • Currently Available Cars In The Market
  • High Level Moving Parts
    • Embedded Hardware And Software
    • In-Vehicle Networking
    • External Interference And Protocols
    • End – End Security
  • Possible Loopholes
  • Prevention
  • How Briskinfosec Can Help You?
  • Curious To Read Our Case Studies?
  • Last But Not The Least
  • You May Be Interested In

Introduction:

Connected cars is the next stage of automotive development fuelling to IoV (Internet of Vehicles). They’re equipped with internet access and WLAN (wireless local area network). They follow safe and legitimate standards which makes them to communicate properly, thereby driving the human safely. They use Dedicated Short-Range Communication (DSRC), with FCC granted 5.9GHz band of very low latency. They’re are internally composed of mechatronics, telemetry and AI to interact with the environment.

image

Currently Available Cars In The Market:

Almost all the giant and mid-sized car companies have connected cars with a mobile app interface. Below is the list of companies that have connected cars and their indigenous apps to interact with their own cars.

image

As per the business insider report, there’ll be about 380 million cars connected to the internet by 2021. These above car interfaces are upgraded in SOTA (Software Over The Air) update and FOTA (Firmware Over The Air) update manner.

SOTA – It refers to the downloads that pertain to the software components.

FOTA – It refers to the downloads that pertain to the firmware components.

Cars available in the middle end segment are

  • Hector from Morris garage
  • Venue from Hyundai
  • Kicks from Nissan.
  • Cars from BMW and Mercedes as well with tier 1 level too.

These devices have various features like start/stop, voice assistant, current status of the vehicle and regulating A/C’s functions which provides an earthly heaven for humans. These features intake the cyberattacks to the car via smartphones. Below shown is a Blue link app from Hyundai.

image

These cars come with the stock embedded sim that supports 5g and ipv6. They also have the facility of ‘Geotagging’. Geotagging refers to the adding of the latitude and longitude details by the user for identification (anti-theft) purposes i.e it immediately shuts down if a non-user drives the car.

High Level Moving Parts

The below parts work behind each and every function which the user uses for interacting with the car. They are classified as

  • Embedded hardware and software
  • In-vehicle networking
  • External interfaces
  • End-to-End security

Embedded hardware and software

This section contains two major sections. They are

  • High Level Networking
  • Low Level Networking

To start with the classification of High-Level Networking, the hardware parts consist of four major components. They are

  • Firmware
  • Embedded security
  • Electrical device security
  • ECU testing.

Here, every part has its own unique functions where the data can be shared to the next device, once it completes its part. Even the music system of the car plays a prominent role in the embedded security feature. The prime reason is, if the music system gets compromised, then the entire security of the car is not built from the hardware design level. Hence, it can be easily compromised. A solid proof for this is the Jeep Cherokee, which was exploited through the entertainment system (music) that’s present in the car. This occurred due to the flaws that were present in the hardware design. Through this, hackers seized the control of the steering and braking systems access. Similar type of breaches occurred in general motors like Chevy Impala, BMW Connect Drive, Tesla and Nissan Leaf. Since the breaches had occurred in almost all the cars, security concerns inevitably arise. Apropos to it, the breaches could’ve also occurred due to software flaws.

In-vehicle networking (Low Level Networking):

This is about Low-Level Networking. Here, majority of the automobile manufacturers use only CAN and LIN. Few of them use ETHERNET and FLEXRAY. CAN protocol was invented by Bosch, and LIN by Lexus. These two are the major game changers for the networking protocol. Most importantly, even a single car can use all of these protocols in a synthesized manner.

CAN (Controller Area Network)

CAN is a protocol that’s developed initially for Automotive. But today, they’re used widely, ranging from medical field to fighter jets.

CAN (Controlled Area Network) is divided into two parts namely. They are:

  • High Speed CAN
  • Low Speed CAN

These are prioritized based on the importance i.e., their level of importance. Systems when switched on, shed priority to high speed CAN which comprises of systems like engine, transmission, ABS (Anti-Braking Suspension) and suspension. The remaining systems like light control, power seats, AC, airbags and power locks come under low speed CAN. The reason is, they aren’t turned at the instance, when the car turns on

image

LIN (Local Interconnect Network)

LIN is almost similar to CAN protocol but differs in the testing phase. CAN protocol consists of 3 wires in which two are data lines and the other remains ground. LIN uses half duplex type with CSMA/CD and when it comes to LIN category, it consists of 2 lines. One is used for data transfer while the other acts as the ground. Since LIN is devoid of arbitration and prioritisation, the master controls all the information; each master can control up to 16 slave nodes.

image

 

Ethernet

Ethernet is a third type of communication protocol. It’s used by one of the highly reputed brands, BMW. The main use of this protocol is to transfer the data faster than CAN and LIN. Moreover, this protocol is familiar in the world of networking. It’s also worthy to remember that the traditional security vulnerabilities in CAN doesn’t affect ethernet.

External Interfaces:

External interfaces/communication has two different parts, V2V (Vehicle-to-Vehicle) and V2X (Vehicle-to-Everything). Both of these, use proprietary RF and 802.11 as the communicating protocols.

Vehicle-Vehicle Communication

This is the communication that occurs between vehicles through which information like speed, distance and location are shared. By using these key parameters, they can drive carefully without needing human hands on steering.

image

Vehicle-X Communication:

This phase involves communication with various interfaces. For example, it communicates with the pedestrians, traffic lights, other cars for entering and exiting the lane, cloud server and with the base stations. By gathering such information, the car calculates these details internally with the help of CPU (ECU). But the major drawback here is the network connectivity problem. The network speed varies from urban to rural. Henceforth, the ISP (Internet Service Providers) should take of these connectivity issues.

image

If the hackers have knowledge about the transmission protocols on the connected cars, then they can take over the entire control of it. Hence, security plays a major role in securing and maintaining the data of the connected cars.

End To End Security

Security concerns should start form the preliminary stage of hardware and software development. Today, we have these security guidelines which the manufactures must follow. First is the EVITA (E-Safety Vehicle Intrusion Protected Applications) which was released on 2011. This was later followed by the SAE (Society for Automotive Engineers) in 2016. Regarding security, Briskinfosec provides security standards for connected cars, as per the SAE and EVITA standards.

Possible Loopholes:

  • Attacks on V2V system.
  • Attacks on OTA firmware upgrades.
  • Attacks on ISP.
  • Attacks on sensors and system interfaces.
  • Exploitation of embedded firmware and partial code re-writes.

Prevention:

  • Provide End-to-End encryption.
  • Hardening the encryption standards.
  • Providing authentication to access all the device information.
  • Radio layer hardening.           
  • Frequent upgradation on software and firmware.
  • Providing encryption standards to physical layer.

How Briskinfosec Can Help You?

BriskInfosec has subject matter experts to test and provide security solutions for client tailored Automotive Cybersecurity needs. In the case of connected cars, our subject matter experts who can create a very detailed attack surface, map and test the device’s both internal and external security thereby providing client specific solutions. Our team tests both internal and external communications that can arise in the domain of automotive cybersecurity. They’re also specialized in the area of asymmetric attack vectors and can provide solutions for automotive needs. To know more about this, kindly reach us out.

Curious To Read Our Case Studies?

Our case studies reveal you the honest security assessment strategies used by us to fix all the classified vulnerabilities of our client’s systems/applications. Well, if you are in a notion to find and read something beneficial and intriguing, then our case studies are something that surely shouldn’t be missed.

Last But Not The Least:

Just imagine, you’re on a herculean task to accomplish something and the only way you knew to do it is by taking the route of hard work. One day, a saviour knocks your door and offers you a blessing by

providing you the route of smart work in order to achieve it without strain. Won’t you accept it? I’d assume you would!

Similarly, with regards to the significant cyberattacks that’d happened globally on every month, the impacts they’d caused to organizations and individuals, the losses faced by them and much more, and to know about all these, you have two options. First, you can take the route of hard and time-consuming work by searching in search engines and websites, day and night, in order to know them.

Well, the other one to know about them is through Briskinfosec’s Threatsploit Adversary reports, the route of smart work. It’s our report which we prepare on a monthly basis exclusively to create cybersecurity awareness to people. Even the best mitigation measures are given by us, just for you in order to stay secured against such threats. Just check it out. You’ll feel it as a blessing in disguise!

You May Be Interested In:

  • Layer Wise Analysis of Security in IOT
  • How your RF layer is exposed to serious cyberattacks?
Wireless Security Automotive Cybersecurity
Share this article
A
Written by
Arulselvar Thomas Founder & Director
Cybersecurity expert at Briskinfosec Technology and Consulting, specializing in security assessments, compliance, and helping organizations build resilient security postures.
Recent Blogs
How to Create a Secure AWS IAM Audit User for Cloud Security Assessments
The Cyber Capability Gap Between Mythos, GPT-5.5 and Open-Weight Models Explained
Inside Claude Mythos and What the Indian Defender Actually Needs to Know
Related Services
VAPT Cloud Security Red Team Network Security API Security Mobile App Security
Latest Videos
Navigating Compliance in Cybersecurity Laws, Privacy laws and Your Business
Navigating Compliance in Cybersecurity Laws,...
Apr 26, 2024
Beyond Size: How to Elevate your SOC Cybersecurity Monitoring
Beyond Size: How to Elevate your SOC Cybersec...
Mar 20, 2024
Red Team Assessment
Red Team Assessment
Mar 13, 2024
Get Protected

Discuss your security posture with our certified experts. Get a free initial assessment.

Schedule Free Consultation WhatsApp Us

Related Articles

Cyber-Security in Automotive Industry
Cyber-Security in Automotive Industry
Dec 21, 2021 · 5,331
Evolution of Ransomware and the trends in 2020
Evolution of Ransomware and the trends in 2020
Apr 29, 2020 · 7,773
Dumpster Diving-Your Unused Modem Hardware can Leak Your Critical Data
Dumpster Diving-Your Unused Modem Hardware can Leak Your Critical Data
Apr 07, 2020 · 4,817
Read Next (Top Blog)
Getting Started with Frida

Ready to Strengthen Your Security?

Talk to our CREST-certified security experts today

WhatsApp Us
Chat instantly with our security team
AI Presales Bot
Get instant answers from LURA AI
Schedule Consultation
Book a free security consultation
Email Us
contact@briskinfosec.com
Link copied to clipboard!
About Us
About Briskinfosec Certin Our Clients Testimonials Press Room
Services
Application Security Mobile App Security Cloud Security Red Team Operations SOC as a Service MSSP All Services →
Compliance
ISO 27001 SOC 2 PCI-DSS GDPR HIPAA All Compliance →
Resources
Blog Videos Case Studies Threatsploit Reports All Resources →
Connect
Careers Partnership Contact Us Responsible Disclosure Terms and Conditions Privacy Policy
India (HQ) Bascon Futura Sv It Park, 12th Floor, 10/2,
Venkatanarayana Rd, T. Nagar, Chennai, Tamil Nadu 600017
+91 73059 79248 · contact@briskinfosec.com
UAE (Dubai) IFZA Business Park, Building A1, Dubai Digital Park,
Dubai Silicon Oasis, Post Box 342001, UAE
contact@briskinfosec.com
Briskinfosec CREST accredited cybersecurity company and globally recognized provider of penetration testing and VAPT services CERT-In empanelled cybersecurity company with headquarters in Chennai and operations in Dubai offering VAPT services Briskinfosec ISO 27001 certified company ensuring robust information security management system Briskinfosec ISO 9001:2015 certified cybersecurity company committed to quality management in India Briskinfosec is a DUNS registered cybersecurity company with a verified global business identity offering VAPT services
© 2026 Briskinfosec Technology & Consulting Pvt Ltd. All rights reserved.
Scope Your Security Program
Chat on WhatsApp Ask LURA AI AI