Hacking Connected Cars: Tactics, Techniques, and Procedures
暫譯: 駭客攻擊連網汽車:戰術、技術與程序

Alissa Knight

  • 出版商: Wiley
  • 出版日期: 2020-03-17
  • 定價: $1,730
  • 售價: 9.0$1,557
  • 語言: 英文
  • 頁數: 250
  • 裝訂: Paperback
  • ISBN: 1119491800
  • ISBN-13: 9781119491804
  • 相關分類: 駭客 Hack
  • 相關翻譯: 車聯網滲透測試 (簡中版)
  • 立即出貨

買這商品的人也買了...

相關主題

商品描述

A field manual on contextualizing cyber threats, vulnerabilities, and risks to connected cars through penetration testing and risk assessment

Hacking Connected Cars deconstructs the tactics, techniques, and procedures (TTPs) used to hack into connected cars and autonomous vehicles to help you identify and mitigate vulnerabilities affecting cyber-physical vehicles. Written by a veteran of risk management and penetration testing of IoT devices and connected cars, this book provides a detailed account of how to perform penetration testing, threat modeling, and risk assessments of telematics control units and infotainment systems. This book demonstrates how vulnerabilities in wireless networking, Bluetooth, and GSM can be exploited to affect confidentiality, integrity, and availability of connected cars.

Passenger vehicles have experienced a massive increase in connectivity over the past five years, and the trend will only continue to grow with the expansion of The Internet of Things and increasing consumer demand for always-on connectivity. Manufacturers and OEMs need the ability to push updates without requiring service visits, but this leaves the vehicle’s systems open to attack. This book examines the issues in depth, providing cutting-edge preventative tactics that security practitioners, researchers, and vendors can use to keep connected cars safe without sacrificing connectivity.

  • Perform penetration testing of infotainment systems and telematics control units through a step-by-step methodical guide
  • Analyze risk levels surrounding vulnerabilities and threats that impact confidentiality, integrity, and availability
  • Conduct penetration testing using the same tactics, techniques, and procedures used by hackers

From relatively small features such as automatic parallel parking, to completely autonomous self-driving cars—all connected systems are vulnerable to attack. As connectivity becomes a way of life, the need for security expertise for in-vehicle systems is becoming increasingly urgent. Hacking Connected Cars provides practical, comprehensive guidance for keeping these vehicles secure.

商品描述(中文翻譯)

關於透過滲透測試和風險評估來將網路威脅、漏洞和風險情境化的實地手冊

駭客攻擊連網汽車 解構了駭客入侵連網汽車和自駕車所使用的戰術、技術和程序(TTPs),幫助您識別和減輕影響網路物理車輛的漏洞。本書由一位在物聯網設備和連網汽車的風險管理及滲透測試方面的資深專家撰寫,詳細說明了如何對遠端信息控制單元和娛樂系統進行滲透測試、威脅建模和風險評估。本書展示了無線網路、藍牙和GSM中的漏洞如何被利用,影響連網汽車的機密性、完整性和可用性。

在過去五年中,乘用車的連接性大幅增加,隨著物聯網的擴展和消費者對持續連接的需求增加,這一趨勢只會繼續增長。製造商和原始設備製造商(OEM)需要能夠在不需要服務訪問的情況下推送更新,但這使得車輛系統面臨攻擊的風險。本書深入探討了這些問題,提供了前沿的預防性戰術,供安全從業人員、研究人員和供應商使用,以在不犧牲連接性的情況下保持連網汽車的安全。


  • 透過逐步的方法指南對娛樂系統和遠端信息控制單元進行滲透測試

  • 分析影響機密性、完整性和可用性的漏洞和威脅的風險水平

  • 使用駭客所用的相同戰術、技術和程序進行滲透測試

從自動平行停車等相對小的功能,到完全自動駕駛的汽車——所有連接系統都容易受到攻擊。隨著連接性成為生活的一部分,對於車輛系統的安全專業知識的需求變得越來越迫切。駭客攻擊連網汽車 提供了實用且全面的指導,以保持這些車輛的安全。

作者簡介

Alissa Knight has worked in cybersecurity for more than 20 years. For the past ten years, she has focused her vulnerability research into hacking connected cars, embedded systems, and IoT devices for clients in the United States, Middle East, Europe, and Asia. She continues to work with some of the world's largest automobile manufacturers and OEMs on building more secure connected cars.

Alissa is the Group CEO of Brier & Thorn and is also the managing partner at Knight Ink, where she blends hacking with content creation of written and visual content for challenger brands and market leaders in cybersecurity. As a serial entrepreneur, Alissa was the CEO of Applied Watch and Netstream, companies she sold in M&A transactions to publicly traded companies in international markets.

Her passion professionally is meeting and learning from extraordinary leaders around the world and sharing her views on the disruptive forces reshaping global markets. Alissa's long-term goal is to help as many organizations as possible develop and execute on their strategic plans and focus on their areas of increased risk, bridging silos to effectively manage risk across organizational boundaries, and enable them to pursue intelligent risk taking as a means to long-term value creation. You can learn more about Alissa on her homepage at http: //www.alissaknight.com, connect with her on LinkedIn, or follow her on Twitter @alissaknight.

作者簡介(中文翻譯)

阿莉莎·奈特(Alissa Knight)在網路安全領域工作超過20年。在過去的十年中,她專注於為美國、中東、歐洲和亞洲的客戶進行連接汽車、嵌入式系統和物聯網設備的漏洞研究。她持續與全球最大的汽車製造商和原始設備製造商(OEM)合作,致力於打造更安全的連接汽車。

阿莉莎是Brier & Thorn的集團首席執行官,同時也是Knight Ink的管理合夥人,在這裡她將駭客技術與為挑戰品牌和網路安全市場領導者創作書面和視覺內容相結合。作為一位連續創業家,阿莉莎曾擔任Applied Watch和Netstream的首席執行官,這兩家公司後來以併購交易的方式出售給國際市場上的上市公司。

她的職業熱情在於與全球卓越領導者會面並學習,並分享她對重塑全球市場的顛覆性力量的看法。阿莉莎的長期目標是幫助盡可能多的組織制定和執行其戰略計劃,專注於其風險增加的領域,打破孤島,有效管理跨組織邊界的風險,並使他們能夠追求智能風險承擔,以實現長期價值創造。您可以在她的個人網站 http://www.alissaknight.com 獲得更多有關阿莉莎的信息,或在LinkedIn上與她聯繫,或在Twitter上關注她 @alissaknight。