SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.

Korea rehearsed a vehicle attack arriving through a supplier's OTA pipeline

MOLIT, KATRI, KISA, the National Police Agency and Hyundai Motor ran a joint incident-response exercise built around malware distributed to vehicles from a compromised parts supplier's server.

South Korea’s Ministry of Land, Infrastructure and Transport said it held a public-private joint incident-response exercise for automotive cybersecurity at Hyundai Motor’s Pangyo headquarters on September 15. The ministry’s announcement was released at 11:00 Korean time and marked for September 16 morning editions.

Five organizations took part: the ministry’s autonomous driving policy division, the Korea Transportation Safety Authority’s automobile safety research institute KATRI, the Korea Internet and Security Agency, the National Police Agency and Hyundai Motor. The exercise was run as a tabletop drill, and no vehicle or system was actually attacked.

The scenario began with an automotive parts supplier’s server being compromised, software carrying concealed malware being distributed to vehicles over the air, and vehicles then behaving abnormally. The ministry said that in a software-defined vehicle the effect of an attack extends from the individual car into the manufacturer and supplier chain.

Participants worked through five phases: detection, reporting and containment; cause analysis and coordination between agencies; short-term measures to restore vehicles; final measures closing the vulnerability and hardening supply-chain security; and an adequacy check before closing the incident. In sequence, Hyundai detected the anomaly and filed the report, KATRI conducted a technical review and reported to the ministry, KISA analyzed the intrusion, and the National Police Agency traced the attacker. Software distribution was halted, a corrected build shipped, and unremediated vehicles traced.

The ministry presented the exercise as a readiness check on Korea’s cybersecurity management system regime now that it is in force. Park Jun-hyung, director general of the ministry’s mobility and automobile bureau, was quoted on the rising sophistication of attacks against carmaker supply chains.

Why it mattersMost cybersecurity coverage stops when a rule takes effect, and this is a regulator testing whether the procedure it wrote actually executes across five organizations.

Source: MOLIT (Ministry of Land, Infrastructure and Transport)

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.