Threat and Risk Assessment Methodologies in the Automotive Domain

被引:37
作者
Macher, Georg [1 ]
Armengaud, Eric [1 ]
Brenner, Eugen [2 ]
Kreiner, Christian [2 ]
机构
[1] AVL List GmbH, Hans List Pl 1, A-8010 Graz, Austria
[2] Graz Univ Technol, Inffeldgasse 16, A-8010 Graz, Austria
来源
7TH INTERNATIONAL CONFERENCE ON AMBIENT SYSTEMS, NETWORKS AND TECHNOLOGIES (ANT 2016) / THE 6TH INTERNATIONAL CONFERENCE ON SUSTAINABLE ENERGY INFORMATION TECHNOLOGY (SEIT-2016) / AFFILIATED WORKSHOPS | 2016年 / 83卷
关键词
ISO; 26262; HARA; STRIDE; automotive systems; safety / security co-engineering;
D O I
10.1016/j.procs.2016.04.268
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Safety and security are both qualities that concern the overall system. However, these disciplines are traditionally treated independently in the automotive domain. Replacement of classical mechanical systems with safety-critical embedded systems raised the awareness of the safety attribute and caused the introduction of the ISO 26262 standard. In contrast to this, security topics are traditionally seen as attacks of a mechanical nature and as only affecting single vehicles (e.g. door lock and immobilizer related). Due to the increasing interlacing of automotive systems with networks (such as Car2X), new features like autonomous driving, and online software updates, it is no longer acceptable to assume that car fleets are immune to security risks and automated remote attacks. Consequently, future automotive systems development requires appropriate systematic approaches to support cyber security and safety aware development. Therefore, this paper examines threat and risk assessment techniques that are available for the automotive domain and presents an approach to classify cyber-security threats, which can be used to determine the appropriate number of countermeasures that need to be considered. Furthermore, we present a combined approach for safety and security analysis to be applied in early development phases, which is a pre-requisite for consistent engineering throughout the development lifecycle. (C) 2016 The Authors. Published by Elsevier B.V.
引用
收藏
页码:1288 / 1294
页数:7
相关论文
共 28 条
[1]  
[Anonymous], 2012, AUTOMOTIVE IND INNOV
[2]  
[Anonymous], 2006, 60812 ISO IEC
[3]  
[Anonymous], GUID MEHT COND SAF A
[4]  
[Anonymous], 2006, 61025 ISO IEC
[5]  
[Anonymous], INT C DEP SYST NETW
[6]  
[Anonymous], 61508 IEC 1
[7]  
[Anonymous], 2011, DO178C RTCA SPEC COM
[8]  
[Anonymous], 2005, The STRIDE Threat Model'
[9]  
Bloomfield R, 2013, LECT NOTES COMPUT SC, V8166, P17, DOI 10.1007/978-3-642-40894-6_2
[10]  
European Organization for Civil Aviation Equipment, 2010, ED202 EUROCAE WG 72