The Cyber Threat From Within

The Cyber Threat From Within

You’re the operations manager of a major truckload carrier. It’s Tuesday, a little after 2 p.m. The morning rush is over, the drivers and customers are all reasonably happy, and you’re gearing up for the onslaught of late-afternoon messages from customers wondering where their trucks are and drivers alerting you that they can’t load until tomorrow. It’s a typical day — until you get a call from a driver with something out of the ordinary.

“My engine has just shut down and I’m sitting dead in the center lane of the Cross-Bronx expressway,” he says. “There were no warnings, no red or yellow lights. It just quit. Traffic was too heavy for me to get over to the shoulder, so I’m sitting here blocking traffic. What a mess.”

Then your phone chirps with a text message: “Send 25,000 in Bitcoin and you can have your truck back.”

If you’re chuckling, saying, “No, that could never happen,” wipe the smile off your face. It has already happened — so far only in a lab, but it’s likely to happen in real life if truck makers, regulators and fleets don’t take steps to protect certain vulnerabilities in the basic electronic architecture of nearly every truck built in the past 25 years or so.

A large part of the potential threat comes from the J1939 data bus. As the Society of Automotive Engineers defines it, “J1939 is a common communication architecture that offers an open interconnect system allowing ECUs associated with different component manufacturers to communicate with each other.”

But while J1939’s open design provides a great deal of efficiency to the industry, it also makes it vulnerable.

“We worked, as an industry, to develop that open architecture of J1939 so that we could have this great flexibility, as fleets and as OEMs to work collaboratively,” says Gary …Read the rest of this story

Source:: http://www.truckinginfo.com/channel/fleet-management/article/story/2017/10/the-cyber-threat-from-within.aspx