Security

KISA Conducts Public-Private Drill on Responding to Automotive Cyber Incidents

IT DAILY ·

Officials pose for a commemorative photo during the 'Public-Private Joint Simulation Training for Automobile Cyber Incident Response' held on September 15 at Hyundai Motor and Kia's Pangyo Advanced Vehicle Platform (AVP) headquarters. [Photo: Korea Internet & Security Agency]

✦ AI Summary

The Korea Internet & Security Agency (KISA) announced on the 15th that it had conducted a simulated drill on responding to automotive cyber incidents. The public-private joint drill was held on September 15 at the Hyundai Motor and Kia Pangyo Advanced Vehicle Platform (AVP) headquarters in Seongnam, Gyeonggi Province. The drill involved the Ministry of Science and ICT, the Ministry of Land, Infrastructure and Transport, the National Police Agency, the Korea Transportation Safety Authority, Hyundai Motor, Kia, and their partners.

The Korea Internet & Security Agency (KISA) announced on the 15th that it had conducted a simulated drill on responding to automotive cyber incidents. The public-private joint drill was held on September 15 at the Hyundai Motor and Kia Pangyo Advanced Vehicle Platform (AVP) headquarters in Seongnam, Gyeonggi Province.

KISA disclosed that it carried out the joint public-private drill at the Hyundai Motor and Kia Pangyo Advanced Vehicle Platform (AVP) headquarters. The photo showed officials at the drill site posing for a commemorative group photo.

Automobiles are evolving into platforms that provide a wide range of software- and communications-based functions and services. As a result, external system connectivity is increasing, and with that expansion, the likelihood that vehicles will be exposed to cyber threats is also rising.

The automotive industry has a supply-chain structure involving numerous partners. These partners take part in parts, software development, and production processes, and a security vulnerability at an individual partner can affect vehicle production, services, and even vehicle safety.

The Korea Internet & Security Agency (KISA) signed a business agreement with Hyundai Motor and Kia on April 30 to strengthen cooperation on preventing cyber threats in the automotive industry and on information security, and the simulated drill was carried out in accordance with that agreement.

The drill involved the Ministry of Science and ICT, the Ministry of Land, Infrastructure and Transport, the National Police Agency, the Korea Transportation Safety Authority, Hyundai Motor, Kia, and their partners. It was conducted on the assumption that an attacker infiltrates a car partner's information system using AI-based attack tools, tampers with a vehicle software update file, and exploits the update route to deliver the altered file to vehicles, causing signs of abnormal function in some features.

Accordingly, Hyundai Motor and Kia detected the vehicle abnormalities, activated their incident response teams, and handled recovery. Hyundai Motor and Kia partners isolated the compromised systems and were responsible for reporting the incident and cooperating with recovery efforts. The Ministry of Land, Infrastructure and Transport and the Korea Transportation Safety Authority received the incident report and managed the situation, while the Ministry of Science and ICT and the Korea Internet & Security Agency analyzed the cause of the breach and attack route and shared threat intelligence. The National Police Agency tracked down the attacker and handled the investigation and arrest, and each agency checked the entire response process according to the drill scenario.

Lee Yong-pil, head of KISA's Digital Threat Prevention Headquarters, noted that the impact of automotive cyber incidents can extend not only to the safety of vehicle users but also to the broader industrial supply chain, stressing the importance of a public-private cooperative response system. He added that, based on this recognition, KISA will seek to strengthen cyber threat response capabilities in key industrial sectors going forward and build a digital safety foundation that the public can trust.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241607

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.