Research highlights vulnerabilities in ELD cybersecurity
Summary
The paper shares vulnerabilities in commonly used ELDs that could allow hackers to take control of, steal data from and disrupt entire fleets by spreading malware unnoticed between vehicles. “This could involve modifying logbook data to incorrectly display hours of use that are beyond the daily limit, which may put the operator of a compromised vehicle at risk for a DOT sanction.” So, there are many implications for trucking companies in the event of such an attack. “In our evaluation of ELD units procured from various resellers, we discovered that they are distributed with factory default firmware settings that present considerable security risks,” the paper reads. Jeremy Daily, associate professor at the Walter Scott, Jr. College of Engineering at CSU, who led the research, said these findings are important for the trucking industry, but they also inform some of the broader potential vulnerabilities as different assets and infrastructure elements become interlinked. “Our group will continue to develop adaptable security measures, assessments and models that can easily be integrated into existing operations,” said Jeremy Daily, associate professor at the Walter Scott, Jr. College of Engineering at CSU, who led the research.