ISO/SAE 21434-Based Risk Assessment of Security Incidents in Automated Road Vehicles

被引:2
作者
Puellen, Dominik [1 ]
Liske, Jonas [1 ]
Katzenbeisser, Stefan [1 ]
机构
[1] Univ Passau, Passau, Germany
来源
COMPUTER SAFETY, RELIABILITY, AND SECURITY (SAFECOMP 2021) | 2021年 / 12852卷
关键词
ISO/SAE; 21434; Risk assessment; Context awareness;
D O I
10.1007/978-3-030-83903-1_6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Although numerous automotive security solutions have been presented in the last years, the question of how to properly react to security incidents during vehicle operation has not yet received much attention. In this work, we describe a context-aware scheme for automated road vehicles that assesses the risk of security incidents intending to automatically identify adequate countermeasures. We specifically focus on attack propagation, as related works proved how seemingly uncritical, but compromised vehicle components can cause dangerous situations. Our scheme is inspired by the risk assessment process of the novel ISO/SAE 21434 cybersecurity standard, which uses attack paths to model static threat scenarios. In contrast, our scheme dynamically queries an asset dependency graph once a security incident is reported, in order to identify attack paths leading to pre-assessed damage scenarios. Since the expected damage of a security incident also depends on the vehicle context, we include information such as speed, time, and traffic density into the risk computation. Based on the resulting risk value, the vehicle selects and realizes a compensating (safety) action. Finally, we discuss our scheme and conduct a case study on an automated prototype vehicle.
引用
收藏
页码:82 / 97
页数:16
相关论文
共 24 条
[1]  
[Anonymous], 2020, 18045 ISOIEC
[2]  
[Anonymous], 2020, 214342022E ISOSAE DI
[3]  
[Anonymous], 2018, 26262 ISO
[4]  
[Anonymous], 2018, 27005 ISOIEC, V3rd
[5]  
[Anonymous], 2017, COMMON CRITERIA COMM
[6]  
[Anonymous], 2017, ISA62443
[7]  
[Anonymous], 2016, SAE J3061
[8]  
Dibaei, 2019, ARXIV190707455
[9]  
Helmholz P, 2013, LECT NOTES COMPUT SC, V7939, P412
[10]   Securing SOME/IP for In-Vehicle Service Protection [J].
Iorio, Marco ;
Reineri, Massimo ;
Risso, Fulvio ;
Sisto, Riccardo ;
Valenza, Fulvio .
IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2020, 69 (11) :13450-13466