IPA 独立行政法人 情報処理推進機構:プレス発表 「2011年度 自動車の情報セキュリティ動向に関する調査」報告書を公開

 近年、スマートフォンの普及に伴う自動車のインターネットへの接続や、車載機器?システムのメーカー共通化(オープン化)の検討?実施によって、車載システムの高機能化が進んでいます。これにより、車載機器,642-975?システムの脆弱(ぜいじゃく)性を狙って、ネットワーク経由で外部から自動車が攻撃を受ける可能性が高まっています。そのため、自動車においても、パソコン同様にネットワーク経由の情報セキュリティ上の脅威に備える必要があります。

 この状況を踏まえIPAでは、「2011年度 自動車の情報セキュリティ動向に関する調査」を実施し、2011年度に発生した自動車の情報セキュリティに関する事案4件と、車載システムの脆弱性を突いた攻撃に関する研究等1件の調査結果5件について、脅威と影響、その対策を報告書にまとめました。

 2011年度に発表された自動車の情報セキュリティに関する研究では、車載システムの脆弱性を狙った攻撃を行うことで、自動車の解錠やエンジンスタート、車内音声の盗聴が可能になるとの報告がありました。このような攻撃は車載システム内の新旧の機能を繋ぐ部分に見つかった脆弱性が狙われており、今後も新しい機能の搭載が進むと考えられる自動車において、自動車全体に対して一貫した情報セキュリティ対策が必要であることが明らかになりました,HP0-J73

 また近年の、自動車を安全で快適に走行させるための「安全快適機能」には車載システムによる制御が必須となってきており、悪路や事故などから車や搭乗者を守る「セーフティ」確保に向けて、悪意のある者から車や搭乗者、情報を守る「セキュリティ」がより一層重要となっていることを確認しました。

 本調査では、安全な自動車社会の実現に向けて3つの提言をまとめました。
 (1) ユーザーへの適切な情報提供
 (2) 悪意ある攻撃への備え
 (3) 今すぐ始める情報セキュリティ対策

 IPAとしては、本レポートが自動車の情報セキュリティの普及の一助となり、安心,70-662?安全なIT社会の実現に寄与することを期待します。

IPA Information-technology Promotion Agency, Japan IPAISEC:Vulnerabilities:“MyJVN Security Configuration Checker” released

Disable USB autorun to protect personal and confidential information from viruses

Dec 21, 2009
>>

Lately, viruses that spread infection by exploiting the USB autorun feature are becoming highly noticeable. The autorun feature is a Windows functionality that enables to automatically open a file stored in a USB memory stick when it is inserted into a computer.

According to the Study on Information Security Incidents in Japan 2008, the percentage of virus infection among all the incidents was 15.8% in 2008, increase from 12.4% in 2007, and a USB autorun virus W32/Autorun seems to account for the increase. W32/Autorun is the most infected virus in Japan in 2008, making up 39.5% of the total.

One of the solutions to protect computers from USB autorun viruses is to disable the USB autorun feature. Nevertheless, the measure has not been widely implemented. According to the Attitude Study on Information Security Threats 2009,BCABA, the percentage of responders who answered yes to “Disabled the USB autorun feature to prevent viruses from automatically being executed” was 15.1%, whereas “No measures taken” gained 38.4%.

IPA recommends PC users disable the USB autorun feature but IPA is also aware that the measures, such as how to disable the feature or see if it is disabled or not,1Y0-300J, may look a little confusing to general users.

In response, IPA developed MyJVN Security Configuration Checker, a free, easy-to-use tool to assess Windows security settings, including the USB autorun feature, available at (in Japanese).

The tool checks the security settings listed in Table1 and users can easily check (1) whether the USB autorun feature is being disabled or not and (2) whether the security patch that disables the USB autorun feature has been applied or not,642-975.

Table 1. MyJVN Security Configuration Checker

Check Items

whether the USB autorun feature is being disabled or not

whether the security patch that disables the USB autorun feature has been applied or not

Figure 1 is a screenshot of MyJVN Security Configuration Checker. With just a few clicks, it enables users to check the current settings and access the web page that shows how to change the settings.

Figure 1. MyJVN Security Configuration Checker

Figure 1. MyJVN Security Configuration Checker

In addition to the USB autorun feature, more check items, such as the minimum password length, password expiration period and automatic turn-on of screensaver, are to be added to MyJVN Security Configuration Checker in the future.

IPA encourages PC users to utilize this tool to protect themselves and their company/organization. Just as the use of OVAL in MyJVN Security Configuration Checker, IPA will keep working on developing and promoting an infrastructure supportive of automatic implementation of vulnerability countermeasures to improve computer users’ convenience.

Table 2 shows the operational requirements of MyJVN Security Configuration Checker.

Table 2. MyJVN Security Configuration Checker Operational Requirements

OS
(32bit only)

Microsoft Windows XP SP2, SP3 or
Microsoft Windows Vista

Browser

Internet Explorer 6, 7
Firefox 3

JRE

Sun Java Runtime Environment 5.0, 6.0

Footnote

(*1)The Study on Information Security Incidents in Japan 2008
(in Japanese)

(*2)The Attitude Study on Information Security Threats 2009, 4-5-3-1, Security on USB Memory Sticks
(in Japanese)

(*3)New Year Holidays Security Alert
(in Japanese)

(*4)A collective term of tools and services that support the better use of JVN iPedia ( http://jvndb.jvn.jp/en ), a vulnerability countermeasure information data base hosted by IPA. MyJVN Version Checker has been also offered since November 30, 2009.

(*5)The security patch that disables the USB autorun feature comes as KB971029. By applying KB971029, other autorun features besides USB autorun are also disabled. For more information, refer to the AutoPlay functionality in Windows.

(*6)Scheduled for 2010 spring or later.

(*7)Open Vulnerability and Assessment Language. OVAL is one of the elements that constitute SCAP (Security Content Automation Protocol), which allows the automation and standardization of technical approaches in the field of information security promoted by the U.S. government.

(*8)As of December 21, 2009, the check items for Windows Vista is “(1) whether the USB autorun feature is being disabled or not” only.

Reference

Contact