A Systematic Approach to Automotive Security

被引:4
|
作者
Ebrahimi, Masoud [1 ]
Marksteiner, Stefan [2 ,4 ]
Nickovic, Dejan [3 ]
Bloem, Roderick [1 ]
Schoegler, David [2 ]
Eisner, Philipp [2 ]
Sprung, Samuel [2 ]
Schober, Thomas [2 ]
Chlup, Sebastian [3 ]
Schmittner, Christoph [3 ]
Koenig, Sandra [2 ,3 ]
机构
[1] Graz Univ Technol, Graz, Austria
[2] AVL List GmbH, Graz, Austria
[3] AIT Austrian Inst Technol, Vienna, Austria
[4] Malardalen Univ, Vasteras, Sweden
来源
FORMAL METHODS, FM 2023 | 2023年 / 14000卷
关键词
Cybersecurity; Testing; Automotive; Threats;
D O I
10.1007/978-3-031-27481-7_34
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
We propose a holistic methodology for designing automotive systems that consider security a central concern at every design stage. During the concept design, we model the system architecture and define the security attributes of its components. We perform threat analysis on the system model to identify structural security issues. From that analysis, we derive attack trees that define recipes describing steps to successfully attack the system's assets and propose threat prevention measures. The attack tree allows us to derive a verification and validation (V&V) plan, which prioritizes the testing effort. In particular, we advocate using learning for testing approaches for the black-box components. It consists of inferring a finite state model of the black-box component from its execution traces. This model can then be used to generate new relevant tests, model check it against requirements, and compare two different implementations of the same protocol. We illustrate the methodology with an automotive infotainment system example. Using the advocated approach, we could also document unexpected and potentially critical behavior in our example systems.
引用
收藏
页码:598 / 609
页数:12
相关论文
共 50 条
  • [31] Cybersecurity Engineering: Bridging the Security Gaps in Advanced Automotive Systems and ISO/SAE 21434
    Siddiqui, Fahad
    Khan, Rafiullah
    Tasdemir, Sena Yengec
    Hui, Henry
    Sonigara, Balmukund
    Sezer, Sakir
    McLaughlin, Kieran
    2023 IEEE 97TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-SPRING, 2023,
  • [32] MACsec-Based Security for Automotive Ethernet Backbones
    Carnevale, Berardino
    Fanucci, Luca
    Bisase, Samson
    Hunjan, Harman
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2018, 27 (05)
  • [33] Evaluation of Security Access Service in Automotive Diagnostic Communication
    Kurachi, Ryo
    Takada, Hiroaki
    Takei, Kentaro
    Iinuma, Takaaki
    Satoh, Yuki
    Nakano, Manabu
    Matsushima, Hideki
    Anzai, Jun
    Nakano, Toshihisa
    2019 IEEE 89TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2019-SPRING), 2019,
  • [34] A Preliminary View on Automotive Cyber Security Management Systems
    Schmittner, Christoph
    Dobaj, Jrgen
    Macher, Georg
    Brenner, Eugen
    PROCEEDINGS OF THE 2020 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2020), 2020, : 1634 - 1639
  • [35] Cyber Security Threats and Vulnerabilities: A Systematic Mapping Study
    Mamoona Humayun
    Mahmood Niazi
    NZ Jhanjhi
    Mohammad Alshayeb
    Sajjad Mahmood
    Arabian Journal for Science and Engineering, 2020, 45 : 3171 - 3189
  • [36] Cyber Security Threats and Vulnerabilities: A Systematic Mapping Study
    Humayun, Mamoona
    Niazi, Mahmood
    Jhanjhi, N. Z.
    Alshayeb, Mohammad
    Mahmood, Sajjad
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2020, 45 (04) : 3171 - 3189
  • [37] Poster: Scenario Creation for Immersive Automotive Security Exploration
    Kwok, Aidan
    Owoputi, Richard
    Ray, Sandip
    PROCEEDINGS OF THE 2023 INTERNATIONAL SYMPOSIUM ON THEORY, ALGORITHMIC FOUNDATIONS, AND PROTOCOL DESIGN FOR MOBILE NETWORKS AND MOBILE COMPUTING, MOBIHOC 2023, 2023, : 565 - 567
  • [38] Towards a security-driven automotive development lifecycle
    Dobaj, Juergen
    Macher, Georg
    Ekert, Damjan
    Riel, Andreas
    Messnarz, Richard
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2023, 35 (08)
  • [39] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [40] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261