Systems and methods for increasing security of connected vehicles
Examples are disclosed for systems and methods for monitoring and filtering data transmitted to a vehicle connected to a wireless network. In one embodiment, a method for an edge node of a wireless network comprises routing traffic of the wireless network to a vehicle connected to the wireless network through the edge node; examining the traffic for potentially malicious content at the edge node; transmitting data packets of the traffic without potentially malicious content to the vehicle; and not transmitting data packets of the traffic with potentially malicious content to the vehicle.
1 . A method for an edge node of a wireless network, comprising:
routing traffic of the wireless network to a vehicle connected to the wireless network through the edge node, wherein from the wireless network destined for the vehicle is intercepted by the edge node prior to reaching the vehicle and data from the vehicle destined for the wireless network is intercepted by the edge node prior to reaching the wireless network;
examining the traffic for potentially malicious content at the edge node as the traffic is routed through the edge node;
transmitting data packets of the traffic without potentially malicious content to the vehicle; and
not transmitting data packets of the traffic with potentially malicious content to the vehicle.
2 . The method of claim 1 , further comprising:
routing traffic of the wireless network from the vehicle to a destination over the Internet through the edge node;
examining the traffic for potentially malicious content at the edge node;
transmitting data packets of the traffic without potentially malicious content to the destination; and
not transmitting data packets of the traffic with potentially malicious content to the destination.
3 . The method of claim 2 , wherein the edge node is selected from a plurality of edge nodes of the wireless network based on a proximity of the edge node to the vehicle.
4 . The method of claim 2 , further comprising:
in response to detecting potentially malicious content in the traffic, performing at least one of:
updating a log with information of the potentially malicious content; and
sending a notification of the potentially malicious content to an original equipment manufacturer (OEM) of a component of the vehicle.
5 . The method of claim 2 , wherein examining the traffic for potentially malicious content further comprises receiving, from the vehicle, a security posture of the vehicle.
6 . The method of claim 5 , wherein examining the traffic for potentially malicious content further comprises using a rule-based filtering/access control algorithm to perform at least one of:
blocking data packets of the traffic;
redirecting data packets of the traffic; and
filtering data packets of the traffic.
7 . The method of claim 6 , wherein one or more rules retrieved from a rules database hosted at the edge node by the rule based filtering/access control algorithm are added or updated based on inputs from at least one of:
the security posture of the vehicle;
a malware signature database;
a common vulnerability and exposures (CVE) database;
an output of an artificial intelligence (AI) or machine learning (ML) anomaly detection algorithm.
8 . The method of claim 5 , wherein the security posture is transmitted to the edge node as a set of key-value pairs.
9 . The method of claim 2 , wherein examining the traffic for potentially malicious content at the edge node relies on functions of network security components of the edge node, the network security components including at least:
a firewall;
a secure domain name system (DNS);
a secure web gateway; and
an access broker.
10 . The method of claim 1 , wherein:
in a first condition, where potentially malicious content is detected in a plurality of data packets of the traffic at the edge node, the plurality of data packets are not transmitted to the vehicle; and
in a second condition, where no malicious content is detected in the plurality of data packets of the traffic at the edge node, the plurality of data packets are transmitted to the vehicle.
11 . A method for a vehicle connected to a wireless network, comprising:
connecting to an edge node of the wireless network, wherein the edge node is a server running at a cellular tower of the wireless network;
changing a network configuration of the vehicle to route network traffic to and/or from the vehicle through the edge node, wherein all network traffic outgoing from the vehicle to the wireless network passes through the edge node before reaching the wireless network and all network traffic incoming to the vehicle from the wireless network passes through the edge node before reaching the vehicle;
sending a security posture of the vehicle to a threat detection service of the edge node; and
receiving filtered network traffic from the edge node, the filtered network traffic filtered based on the security posture.
12 . The method of claim 11 , wherein connecting to the edge node of the wireless network further comprises:
determining a current location of the vehicle;
scanning the network to detect a closest edge node of the wireless network to the current location; and
connecting to the closest edge node.
13 . The method of claim 11 , wherein the security posture of the vehicle is based on log information of the vehicle and sensor data of the vehicle.
14 . The method of claim 11 , wherein sending the security posture of the vehicle to the threat detection service further comprises sending an updated security posture of the vehicle to the threat detection service at periodic intervals.
15 . A system, comprising:
an edge node of a cellular network, the cellular network including a plurality of connected vehicles, the edge node including one or more processors having executable instructions stored in a non-transitory memory that, when executed, cause the one or more processors to:
accept a request from a vehicle of the plurality of connected vehicles;
in response to accepting the request from the vehicle, route all incoming traffic to the vehicle from the cellular network through the edge node and route all outgoing traffic from the vehicle to other entities on the cellular network through the edge node, wherein the edge node is selected from a plurality of edge nodes of the cellular network based on signal strength;
filter the incoming and outgoing traffic based on one or more rule-based filtering/access control algorithms; and
transmit the filtered incoming traffic to the vehicle and the filtered outgoing traffic to the other entities.
16 . The system of claim 15 , wherein one or more rules used by the one or more rule-based filtering/access control algorithms are based on or updated based on inputs from one or more of:
a malware signature database;
a common vulnerability and exposures (CVE) database;
an output of an artificial intelligence (AI) or machine learning (ML) anomaly detection algorithm; and
a security posture of the vehicle transmitted to the edge node from the vehicle.
17 . The system of claim 16 , where additional instructions are stored in the non-transitory memory that, when executed, cause the one or more processors to:
in response to detecting potentially malicious content in the incoming traffic or outgoing traffic when filtering the incoming or outgoing traffic, perform at least one of:
update a log with information of the potentially malicious content; and
send a notification of the potentially malicious content to an original equipment manufacturer (OEM) of a component of the vehicle.
18 . The system of claim 15 , wherein filtering the incoming and outgoing traffic based on one or more rule-based filtering/access control algorithms includes filtering the incoming and outgoing traffic using one or more of:
a secure domain name system (DNS) of the edge node;
a secure web gateway of the edge node;
a firewall of the edge node; and
an access broker of the edge node.
19 . The method of claim 15 , wherein the edge node is not the closest edge node in proximity to the vehicle.
20 . The system of claim 15 , wherein the vehicle comprises an intrusion detection/prevention system (IDPS) that is configured to share resources with the edge node for detection of potentially malicious content in the incoming traffic or outgoing traffic.