Something to keep an eye on: legislation being introduced in the United States that would restrict the use of connected vehicle hardware and software components tied to covered countries.
This could be the beginning of tighter vehicle cybersecurity regulations in North America. Europe already has UNECE WP.29 R155 and ISO/SAE 21434, but there is currently no equivalent regulatory framework in the United States.
It is also interesting to note that we at TrustThink already work with AUVSI and others to evaluate supply chain provenance for uncrewed aerial system (#UAS) hardware and software. There will likely be lessons learned from those efforts that can be applied to connected vehicles if this legislation moves forward.
https://t.co/N8YrtYNUTA
Really happy to note that Elijah Pichler is TrustThink's new Director of Transportation Cybersecurity. In this role, he will help lead and grow our efforts across intelligent transportation systems (ITS), connected vehicle security, and our uncrewed system security test and evaluation program. He will also work closely with our Lead AI Engineer, Allison Lane, to leverage #AI tools into our test and evaluation processes. Looking forward to seeing what Elijah builds over the next few years.
Test and evaluation (T&E) processes are really good at validating whether a system was built according to specified requirements.
They are much less effective at validating system behavior once you add:
- learned models
- API-driven architectures
- dynamic runtime conditions
- external data and service dependencies
A lot of the things we will soon need to evaluate come from:
- interaction effects between components
- edge conditions
- model and data drift over time
- unanticipated or adversarial inputs
Something to think about as we test the security and robustness of intelligent systems.
Check out Reilly Fastring's presentation at AUVSI on Tuesday, May 12 at 2:30pm in Detroit for more thoughts on this.
https://t.co/wsZDncLeev
Open sourced a small library for ISO/IEC 13888-3 non-repudiation tokens.
https://t.co/7sBVPxhh2X
There aren’t many reference implementations out there... this focuses on token construction so it can be used for testing and integration with existing security frameworks.
Open sourced a project called TokenFool.
https://t.co/OUcC0zOgd5
Most adversarial tooling is built around CNNs and pixel-space attacks.
This is a research tool for experimenting with attacks on vision transformers at the token and patch level.
As transportation goes autonomous and connected, cybersecurity isn’t just a checkbox—it’s the backbone of safe, reliable systems. Vehicle and ITS equipment manufacturers should align with ISO/SAE 21434:
TARA: Identifying risks to build defenses that align with ISO/SAE 21434 & NIST CSF.
CSMS: A framework for proactive security management and monitoring across the supply chain
...and integrate secure communications by designing equipment to meet enrollment standards for the Security Credential Management System (SCMS), enabling trusted and authenticated V2X messaging.
Looking to hire a strong junior / mid security engineer that has an interest in encryption to work with myself and a great team on modernizing cryptographic solutions / helping plan transition to quantum resistant algorithms. #infosecjobs San Diego preferred, remote an option