PlaxidityX teams up with Riscure to develop automotive-focused challenges for this year’s Riscure Hack Me competition

PlaxidityX teams up with Riscure to develop automotive-focused challenges for this year’s Riscure Hack Me competition

This year’s RHme Capture The Flag (CTF) competition will feature several automotive-themed challenges developed by the PlaxidityX (formerly Argus Cyber Security) research team in addition to the hardware and software challenges the RHme CTF has become known for over the last two years. These challenges will run on a custom printed circuit board developed by Riscure specifically for the competition.

Last year’s competition consisted of five different sections: some of the challenges required primarily software reverse engineering skills, where you had to recover the secret flag through binary analysis techniques. Other challenges had the researchers attempt to exploit vulnerabilities in software, often with difficult constraints such as a very limited ability to observe (let alone debug) the vulnerable code. Still others required an understanding of cryptography and its mathematical underpinnings in order to find and exploit the weaknesses intentionally left behind in the challenges.

The last two sets of challenges RHme is known for, side channel analysis and fault injection, are two families of hardware exploitation techniques that require an understanding of the connection between the lowest layer of hardware and high-level concepts like code flow and cryptographic operations. Since these techniques require challenge participants to operate directly on hardware, last year Riscure provided a competition board, an Arduino with a unique bootloader, to each participant in the competition. This year, to support the automotive focus of some of the challenges, Riscure developed a custom board that they will send to every registered participant.

This year’s automotive challenges will feature hardware and software challenges that simulate the (better parts of) systems and protocols prominent in the automotive industry. We’ve put a lot of effort into designing challenges that are both interesting and similar to real-life systems and scenarios, drawing from our experience and imagination. Although automotive cyber security has been a trending topic lately, with few notable exceptions, information on the subject is still scarce and involves technologies that are not widely known . We hope these challenges will serve as a fun way for engineers to develop knowledge and interest in the industry.

We’ve known and respected Riscure for a long while: we took part in last year’s RHme competition and some of us even flew to The Netherlands to receive specialized hardware training at Riscure headquarters. As Riscure is a global leader in the field of hardware security, this joint project is very exciting for us.

Participating in the planning and development of the challenges for the CTF alongside Riscure has allowed PlaxidityX to reach a large target audience and increase awareness of cyber-security issues as they relate to the automotive industry. We hope our collaboration will succeed just as previous iterations of RHme served to educate researchers about hardware security.

A prototype competition board

For the last few months we’ve been hard at work devising and testing the challenges on the custom boards developed by Riscure. The competition itself will start on November 1st, but registration opened on August 7 so don’t miss your chance to learn about automotive cyber security and hone your hacking skills!

Published: August 9th, 2017

Ready to See Plaxidityx in Action?

“We see cybersecurity as a differentiator of our market offering and believe our partnership with PlaxidityX complements our “Digital Shield” cybersecurity service offering, helping us to achieve our goal of becoming a leader in secure software and electronics.”

Oliver Huppenbauer

“The partnership with PlaxidityX enables our OEM and Tier 1 customers to benefit from our new, high-performance Ajunic®️ platform without the security worries. By leveraging PlaxidityX’s automotive cyber security expertise and innovative IDPS product line, we will be able to deliver market-leading in-vehicle protection capabilities as an integral part of our software development stack.”

Georg Schwab

“We chose PlaxidityX based on its proven experience, knowledge, methodology, and expertise..PlaxidityX’s ability to complete and submit in an extremely short time with top quality results, was critical for meeting our business goals”

PlaxidityX (Formerly Argus) Automotive Cyber Security
Emrah Duman

“PlaxidityXs’ comprehensive suite of cyber security solutions and its outstanding array of strategic technological partnerships have contributed to the company’s leadership position”

PlaxidityX (Formerly Argus) Automotive Cyber Security
Dorothy Amy

“The partnership with PlaxidityX enables our customers to perform cybersecurity testing on our established test platforms ..We are excited to partner with a strong and experienced cybersecurity service provider such as PlaxidityX”

Dr. Herbert Schütte

“By combining PlaxidityX’s expertise in securing connected vehicles with Microsoft’s Azure AI capabilities, we have a unique opportunity to accelerate ‘shift left’ security innovations across the entire automotive sector..”

PlaxidityX (Formerly Argus) Automotive Cyber Security
Dominik Wee

“PlaxidityX is a key pillar of Continental’s SDV strategy, enabling Continental to implement a security-by-design approach. As automotive cyber security moves to the cloud, PlaxidityX’ cutting-edge technologies and proven VSOC capabilities position us advantageously to meet our customers’ future needs”

Gilles Mabire

Learn how we bring peace of mind for millions of drivers