Modern Automotive Vulnerabilities: Causes, Disclosures, and Outcomes

Monday, January 25, 2016 - 1:30pm2:00pm

Stefan Savage, Professor, Department of Computer Science and Engineering, University of California, San Diego


Over the last six years, a range of research has transformed our understanding of automobiles. What we traditionally envisioned as mere mechanical conveyances are now more widely appreciated as complex distributed systems "with wheels." A car purchased today has virtually all aspects of its physical behavior mediated through dozens of microprocessors, themselves networked internally, and connected to a range of external digital channels. As a result, software vulnerabilities in automotive firmware potentially allow an adversary to obtain arbitrary control over the vehicle. Indeed, multiple research groups have been able to demonstrate such remote control of unmodified automobiles from a variety of manufacturers. In this talk, I'll highlight how our understanding of automotive security vulnerabilities has changed over time, how unique challenges in the automotive sector give rise to these problems, and how different approaches to disclosure have played a role in driving industry and government response.

Stefan Savage is part of the Systems & Networking and Security research groups at the University of California, San Diego. His interests are all over the map, ranging from the economics of e-crime, to characterizing availability, to automotive systems to routing protocols, data center virtualization and back again. He has very broad interests (i.e. "try me if you have a crazy idea").

Stefan got his undergrad degree in Applied History from CMU and his Ph.D. from the University of Washington (courtesy Brian Bershad and Tom Anderson). He was Co-founder and Chief Scientist at Asta Networks (now kaput), served on the Strategy Advisory Council of Rendition Networks (since acquired by OpsWare) and helped develop some of the technology used by Netsift (since acquired by Cisco). He does other consulting here and there.

