-
Notifications
You must be signed in to change notification settings - Fork 4.4k
Update: Automotive Security #1984
Copy link
Copy link
Open
Labels
ACK_OBTAINEDIssue acknowledged from core team so work can be done to fix it.Issue acknowledged from core team so work can be done to fix it.UPDATE_CSIssue about the update/refactoring of a existing cheat sheet.Issue about the update/refactoring of a existing cheat sheet.
Metadata
Metadata
Assignees
Labels
ACK_OBTAINEDIssue acknowledged from core team so work can be done to fix it.Issue acknowledged from core team so work can be done to fix it.UPDATE_CSIssue about the update/refactoring of a existing cheat sheet.Issue about the update/refactoring of a existing cheat sheet.
What is missing or needs to be updated?
I can propose an updated description for the Top 10 Automotive Security Vulnerabilities. Based on my knowledge, I believe I can add more value to this cheat sheet.
How should this be resolved?
I propose adding the following vulnerabilities:
I also propose replacing:
“Weak Vehicle Communication Protocols” with “Lack of secure communication.”
The CAN protocol itself is not weak, but it does not provide any built-in security mechanisms. However, an OEM may require SecOC, which adds integrity checking for each CAN frame.
I also propose extending the description of the existing cheat sheet and adding a MITIGATION proposal.