Security risk assessment framework for smart car using the attack tree analysis

被引:47
作者
Kong, Hee-Kyung [1 ]
Hong, Myoung Ki [2 ]
Kim, Tae-Sung [3 ]
机构
[1] Chungbuk Natl Univ, Dept Informat & Commun Engn, 1 Chungdae Ro, Cheongju 362763, Chungbuk, South Korea
[2] Chungbuk Natl Univ, Dept Informat Secur Management, 1 Chungdae Ro, Cheongju 362763, Chungbuk, South Korea
[3] Chungbuk Natl Univ, Dept Management Informat Syst, 1 Chungdae Ro, Cheongju 362763, Chungbuk, South Korea
基金
新加坡国家研究基金会;
关键词
Security risk; Assessment framework; Vulnerability; Smart car; Attack tree analysis; ARCHITECTURE;
D O I
10.1007/s12652-016-0442-8
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As the automobile industry has recently adopted information technologies, the latter are being used to replace mechanical systems with electronically-controlled systems. Moreover, automobiles are evolving into smart cars or connected cars as they are connected to various IT devices and networks such as VANET (Vehicular Ad hoc NETwork). Although there were no concerns about the hacking of automobiles in the past, various security threats are now emerging as electronic systems are gradually filling up the interiors of many automobiles, which are in turn being connected to external networks. As such, researchers have begun studying smart car security, leading to the disclosure of security threats through the testing or development of various automobile security technologies. However, the security threats facing smart cars do not occur frequently and, practically speaking, it is unrealistic to attempt to cope with every possible security threat when considering such factors as performance, compatibility, and so forth. Moreover, the excessive application of security technology will increase the overall vehicle cost and lower the effectiveness of investment. Therefore, smart car security risks should be assessed and prioritized to establish efficient security measures. To that end, this study constructed a security risk assessment framework in a bid to establish efficient measures for smart car security. The proposed security risk assessment framework configured the assessment procedure based on the conventional security risk analysis model GMITS (ISO13335) and utilized 'attack tree analysis' to assess the threats and vulnerabilities. The security risk assessment framework used the results of an asset analysis, threat/vulnerability analysis, and risk analysis to finally assess the risk and identify the risk rating. Moreover, it actually applied the proposed framework to assess security risks concerning targeted increases in vehicle velocity and leakages of personal information, which are the leading threats faced by smart cars. Here, the framework was applied to vehicle velocity increase and personal information leakage, which are the leading threats.
引用
收藏
页码:531 / 551
页数:21
相关论文
共 48 条
[1]  
[Anonymous], 2012, AUTOMOTIVE SAFETY SE
[2]  
[Anonymous], 2011, P 20 USENIX SEC S
[3]  
[Anonymous], USENIX SEC S
[4]  
[Anonymous], 2007, C VULNERABILITY ASSE
[5]  
[Anonymous], 2011, NETW DISTR SYST SEC
[6]   Multi-layer security analysis and experimentation of high speed protocol data transfer for GRID [J].
Bernardo, Danilo Valeros ;
Hoang, Doan B. .
INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2012, 3 (2-3) :81-88
[7]   An authentication protocol for vehicular ad hoc networks with heterogeneous anonymity requirements [J].
Bhavesh, N. Bharadiya ;
Maity, Soumyadev ;
Hansdah, R. C. .
INTERNATIONAL JOURNAL OF SPACE-BASED AND SITUATED COMPUTING, 2014, 4 (01) :1-14
[8]   AUTOMOBILE SECURITY CONCERNS [J].
Brooks, R. R. ;
Sander, S. ;
Deng, Juan ;
Taiber, Joachim .
IEEE VEHICULAR TECHNOLOGY MAGAZINE, 2009, 4 (02) :53-64
[9]  
Cha B, 2013, INT J GRID UTIL COMP, V4, P1
[10]  
EVITA, 2009, SEC REQ AUT ON BOARD