Business Wire
Welcome
  • Log In
  • Sign Up
Search News:
Help
http://www.adacore.com/
August 23, 2010 08:00 AM Eastern Time 

Security Given Short Shrift in Automotive Software Development, Says AdaCore

NEW YORK & PARIS--(BUSINESS WIRE)--With each new model year, cars are becoming more dependent on microprocessors and complex software, challenging the auto industry to ensure that these systems are secure, safe, and reliable. According to AdaCore, this challenge is not being met: security and safety issues are not being properly considered at the start of the automotive system design cycle, but are instead being addressed as an afterthought. A recent paper from Rutgers University and the University of South Carolina, detailing preventable security flaws of in-car wireless networks, confirms AdaCore's thesis.

“While the potential for misuse may be minimal, this vulnerability points to a troubling lack of rigor with secure software development for new automobiles”

“It is totally unacceptable for safety and security to be treated as add-on features for any safety-critical system, much less an automobile,” said Robert Dewar, President and CEO of AdaCore. “Car makers simply must consider these issues from the very start of a new vehicle design, because trying to add them in later, sometimes even after cars are on the road, is dangerous for drivers and expensive for manufacturers.”

AdaCore is a leading provider of tools and services that help software developers meet stringent safety and security standards.

Hacked Tire Sensors a Possibility

Researchers from Rutgers University and University of South Carolina found, for example, that wireless communications between new cars and their tires can be “hacked” – intercepted or even forged – just like vulnerable computers on a data network. The report also shows that digital eavesdropping is possible at a distance of roughly 40 meters from a passing vehicle, and safety-critical messages from sensors in the car can be triggered and spoofed remotely.

“While the potential for misuse may be minimal, this vulnerability points to a troubling lack of rigor with secure software development for new automobiles,” said Wenyuan Xu, in a recent Business Week interview with Joab Jackson of IDG News Service. Prof. Xu, from the Computer Science department at the University of South Carolina, was a co-lead on the study.

This specific security flaw is a symptom of a larger problem: electronic systems are being developed and deployed in automobiles without considering security requirements. AdaCore says this is a particularly surprising omission for software systems where development costs will ultimately be distributed across a very large volume of vehicles, since the added effort needed to integrate security is negligible on a per-vehicle basis.

Existing Techniques for Ensuring Safety and Security

The software discipline has come up with a wide range of technologies that have proven over the years to increase both safety and security. For example, the avionics industry has adopted the DO-178B safety standard to make sure that software in commercial aircraft systems is safe. Similar standards are used in many other safety-critical industries, including high-speed rail, nuclear reactors, and medical devices. Analogous standards, most notably the Common Criteria, address security issues. There are established communication encryption mechanisms, and also computer architectures that allow multiple programs to operate securely on a single computer system. Both of these technologies make sense for the computer systems on board an automobile, where typically various sensors communicate data to remote processors that, in turn, are managed and coordinated by a central computer.

This central computer will be running multiple programs at different security or criticality levels. The entertainment system, although nice to have, is not essential to the safe operation of the car. In contrast, the cruise control system is safety critical; a bug that, for example, prevented the driver from overriding the set speed could cause an accident. The Bluetooth wireless interface and, in the case of the tire pressure system considered in the Rutgers / Univ. of South Carolina study, sensor communication channels can allow outside access, and that’s the source of the security problem. These systems, along with the many other systems operating on a modern automobile, need to be protected from one another (and from outsiders) so that one system cannot adversely affect another.

The Multiple Independent Levels of Security (MILS) architecture was specifically designed to support this sort of multi-program computer system. It isolates separate programs into their own partitions where each can operate safely and securely without interfering with others. It also supports secure communication between these various programs in a policy-defined manner. This architecture is available commercially (GNAT Pro High-Integrity Edition for MILS), and can solve many of the security issues presented by a modern automobile with its many computer systems.

About AdaCore

Founded in 1994, AdaCore is the leading provider of commercial software solutions for Ada, a state-of-the-art programming language designed for large, long-lived applications where safety, security, and reliability are critical. AdaCore's flagship product is the GNAT Pro development environment, which comes with expert on-line support and is available on more platforms than any other Ada technology. AdaCore has an extensive world-wide customer base; see http://www.adacore.com/home/company/customers/ for further information.

Ada and GNAT Pro continue to see a growing usage in high-integrity and safety-certified applications, including commercial aircraft avionics, military systems, air traffic management/control, railroad systems, and medical devices, and in security-sensitive domains such as financial services.

AdaCore has North American headquarters in New York and European headquarters in Paris. www.adacore.com

Contacts

AdaCore
Jamie Ayre
press@adacore.com
or
Rainier Communications (for AdaCore)
Jessie Glockner, 508-475-0025 x140
adacore@rainierco.com

Recent Stories from AdaCore

  • View Press Release
    AdaCore Launches GNATtest
    February 01, 2012
    TOULOUSE, France & PARIS & NEW YORK--(BUSINESS WIRE)--AdaCore announces availability of the GNATtest unit test harness generator for Ada. The tool helps automate the processes for developing and ma... more »
  • View Press Release
    “Project P” and “Hi-MoCo” Research Projects Launched
    February 01, 2012
    TOULOUSE, France, PARIS & NEW YORK--(BUSINESS WIRE)--AdaCore announces its participation in ‘Project P’ and ‘Hi-MoCo’, two open-source research projects that combine model-based integration and qua... more »
  • View Press Release
    AdaCore and SofCheck Merge
    January 10, 2012
    NEW YORK & PARIS & LEXINGTON, Mass.--(BUSINESS WIRE)--AdaCore, a leading supplier of Ada development tools and support services, today announced a merger with SofCheck, Inc., a Lexington, Massachus... more »
More Stories
RSS feed for AdaCore
http://www.adacore.com/

Release Versions

  • EON: Enhanced Online News

Company Information Center

AdaCore RSS feed for AdaCore

Share

  • Facebook
  • Twitter
  • LinkedIn
  • Delicious
  • Reddit
  • StumbleUpon
  • Digg
  • MySpace
  • Newsvine
  • Google Bookmark
  • Yahoo! Bookmark
  • EmailEmail
Tweet
  • EmailEmail
All News
Business Wire
  • Home
    • Home
    • Membership Benefits
    • Submit a Press Release
  • News
    • All News
    • News with Multimedia
    • News by Industry
    • News by Subject
    • News by Language
    • RSS Feeds
    • Business Wire Mobile
    • Features
    • Company NewsCenters
    • Smart Marketing Pages
    • Company Profiles
    • Annual Reports
  • Events
    • Trade Shows & Events
    • Earnings & Conference Calls
    • Business Wire Events
  • PR Services
    • Press Release Distribution
    • Distribution Lists
    • Industry Targeting
    • LatinoWire & Ethnic Media
    • Public Policy Wire
    • Trade Show Services
    • Photos & Multimedia Marketing
    • GloMoSoMe
    • Press Release Measurement
    • Mobile Alerts
    • Clips & Research
    • Fax & Email Services
    • Online Newsrooms
    • News Feeds
  • IR Services
    • Material News Disclosure
    • XBRL
    • EDGAR (US)
    • IPO Services
    • SEDAR (Canada)
    • European Disclosure
    • Corporate Social Responsibility (CSR)
    • Investor Targeting
    • Fax & Email Services
    • Online Investor Centers
    • IR Resource Center
  • SEO Services
    • Press Release Optimization
    • EON: Enhanced Online News
    • Webinars & Resources
  • Journalist Tools
    • PressPass: Your News
    • Conduct Surveys
    • Business Wire News Feeds
    • Business Wire News On Your Website
    • Journalism Associations
  • Support & Education
    • FAQ
    • How to Write a Press Release
    • How To Optimize a Press Release for Search
    • How to Distribute a Press Release
    • Find Your News Online
    • Sample Press Release
    • Features News Tips
    • International Media Tips
    • SEC Regulations
    • Exchange Guidelines
    • White Papers
    • Webinars & Podcasts
    • Get WiredIn!
  • About Us
    • Business Wire Newsroom
    • Contact Us
    • History
    • Jobs
  • About Us
  • Contact Us
  • Site Map
  • Privacy Statement
  • Terms of Use
  • ©2012 Business Wire

More Business Wire sites

  • Canada
  • UK/Ireland
  • Deutschland
  • France
  • Italy
  • Japan
  • EON: Enhanced Online News
  • Tradeshownews.com
  • PYMNTS.com

About Us

  • Business Wire Newsroom
  • Contact Us
  • Business Wired blog

News on BusinessWire.com

  • All News
  • RSS Feeds
  • Business Wire Mobile Apps

Follow Us on Twitter

  • @BusinessWire
  • @BWSportsWire
  • @BWPolitics
  • @BWCSRNews
  • @EONpr
  • @TradeshowNews
  • @BW_Canada
  • @BWIntlMedia
  • @BWInfoDiva
  • @BusinessWireFR

Like Us on Facebook

  • Business Wire
  • Tradeshow News