How Trustworthy are Over-The-Air (OTA) Updates for Autonomous Vehicles (AV) to Ensure Public Safety?: A Threat Model-based Security Analysis

被引:0
|
作者
Chowdhury, N. M. Istiak [1 ]
Hasan, Ragib [1 ]
机构
[1] Univ Alabama Birmingham, Dept Comp Sci, Birmingham, AL 35294 USA
关键词
OTA Update; threat model; attacker; security; public safety;
D O I
10.1109/WFPST58552.2024.00025
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The rise of autonomous vehicles (AV) has transformed our transportation sectors in recent years. The evolution of technology has made AVs more popular among users. The Over-The-Air (OTA) updates for AVs are widely adopted by the AV industry. These updates are used to deliver improved functionality and security patches to ensure public safety. However, this system is susceptible to security threats since the wireless communication link between the car, the manufacturer, and the cloud-based web server is inherently insecure. While there are studies that explored multiple cybersecurity frameworks and tools for OTA updates, many challenges remain unaddressed. To build a robust trustworthy system, we need to perform a thorough security analysis by creating a threat model. In this study, we use the CIAA and STRIDE threat modeling process to analyze the OTA updates security. Our analysis demonstrates numerous dangers and vulnerabilities. To increase the security of OTA updates, we also suggest several corrective mitigation steps.
引用
收藏
页码:87 / 92
页数:6
相关论文
共 4 条
  • [1] Systematic threat assessment and security testing of automotive over-the-air (OTA) updates
    Mahmood, Shahid
    Nguyen, Hoang Nga
    Shaikh, Siraj Ahmed
    [J]. VEHICULAR COMMUNICATIONS, 2022, 35
  • [2] A Model-Based Security Testing Approach for Automotive Over-The-Air Updates
    Mahmood, Shahid
    Fouillade, Alexy
    Hoang Nga Nguyen
    Shaikh, Siraj A.
    [J]. 2020 IEEE 13TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW), 2020, : 6 - 13
  • [3] An Approach of Scenario-Based Threat Analysis and Risk Assessment Over-the-Air updates for an Autonomous Vehicle
    Khatun, Marzana
    Glass, Michael
    Jung, Rolf
    [J]. 2021 7TH INTERNATIONAL CONFERENCE ON AUTOMATION, ROBOTICS AND APPLICATIONS (ICARA 2021), 2021, : 122 - 127
  • [4] Practical Security and Privacy Threat Analysis in the Automotive Domain: Long Term Support Scenario for Over-the-Air Updates
    Vasenev, Alexandr
    Stahl, Florian
    Hamazaryan, Hayk
    Ma, Zhendong
    Shan, Lijun
    Kemmerich, Joerg
    Loiseaux, Claire
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON VEHICLE TECHNOLOGY AND INTELLIGENT TRANSPORT SYSTEMS (VEHITS 2019), 2019, : 550 - 555