A simulation framework for automotive cybersecurity risk assessment

被引:1
作者
Jayaratne, Don Nalin Dharshana [1 ,3 ]
Kamtam, Suraj Harsha [1 ]
Shaikh, Siraj Ahmed [2 ,3 ]
Ramli, Muhamad Azfar [3 ]
Lu, Qian [1 ]
Mepparambath, Rakhi Manohar
Nguyen, Hoang Nga [2 ]
Rakib, Abdur [1 ,2 ]
机构
[1] Coventry Univ, Ctr Future Transport & Cities CFTC, Coventry, England
[2] Swansea Univ, Dept Comp Sci, Syst Secur Grp SSG, Swansea, Wales
[3] ASTAR, Inst High Performance Comp IHPC, Singapore, Singapore
关键词
Connected vehicles; Automotive cybersecurity; Risk assessment; Simulation; VULNERABILITIES;
D O I
10.1016/j.simpat.2024.103005
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Human-initiated disruptions such as cyberattacks on connected vehicles have the potential to cause cascading failures in transport systems, leading to systemic risks. 'ISO/SAE 21434:2021 Road vehicles- Cybersecurity engineering' is the current standard for risk management of road vehicles. However, the threat analysis and risk assessment framework given in the standard focuses on asset-level analysis and assessment. Hence, this study develops a novel simulation- based framework to perform threat analysis and risk assessment on connected vehicles from a transport network perspective. The proposed framework is developed based on the ISO/SAE 21434 threat analysis and risk assessment methodology. We demonstrate the applicability and usefulness of the framework through a remote attack via the cellular network on the in-vehicle communication bus system of a connected vehicle to show the potential impacts on the transport network. Based on the findings of our case studies, we exemplify how cyberattacks on individual system components of a connected vehicle have the potential to cause systemic failures.
引用
收藏
页数:16
相关论文
共 62 条
[1]   Security Vulnerabilities of Connected Vehicle Streams and Their Impact on Cooperative Driving [J].
Amoozadeh, Mani ;
Raghuramu, Arun ;
Chuah, Chen-Nee ;
Ghosal, Dipak ;
Zhang, H. Michael ;
Rowe, Jeff ;
Levitt, Karl .
IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (06) :126-132
[2]  
Andy G, 2015, Hackers cut a corvette's brakes via a common car gadget
[3]  
[Anonymous], 2016, HIGHWAY CAPACITY MAN
[4]  
[Anonymous], 2015, CPSS 2015, DOI DOI 10.1145/2732198.2732204
[5]  
[Anonymous], 2021, Cybersecurity challenges in the uptake of artificial intelligence in autonomous driving
[6]  
[Anonymous], Risk definition meaning
[7]  
[Anonymous], 2020, Systemic Cyber Risk
[8]  
Barceló J, 2005, OPER RES COMPUT SCI, V31, P57
[9]  
Berdica K, 2002, Transp Policy, V9, P117, DOI [10.1016/S0967-070X(02)00011-2, DOI 10.1016/S0967-070X(02)00011-2, 10.1016/S0967-070X, DOI 10.1016/S0967-070X]
[10]  
Bouissou M., 2015, P 22 COMP EL SEC APP, P55