Integrated Automation for Threat Analysis and Risk Assessment in Automotive Cybersecurity Through Attack Graphs

被引:0
|
作者
Saulaiman, Mera Nizam-Edden [1 ]
Csilling, Akos [2 ]
Kozlovszky, Miklos [3 ,4 ]
机构
[1] Obuda Univ, Doctoral Sch Appl Informat & Appl Math, Becsi Ut 96-B, H-1034 Budapest, Hungary
[2] Robert Bosch Kft, Gyomroi Ut 104, H-1103 Budapest, Hungary
[3] Obuda Univ, John von Neumann Fac Informat, Becsi Ut 96-b, H-1034 Budapest, Hungary
[4] Hungarian Res Network HUN REN, Inst Comp Sci & Control SZTAKI, LPDS, Med Device Res Grp, Kende U 13-17, H-1111 Budapest, Hungary
关键词
Automotive security; 5G; Threat analysis and risk assessment; Attack graph; ISO/SAE; 21434; SECURITY;
D O I
暂无
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Attack graphs contribute to the evaluation of network security vulnerabilities, offering a visualization of possible attack paths. Despite their common use in IT security for analyzing system vulnerabilities, attack graphs are not commonly used in the automotive sector. As smart vehicles increasingly rely on 5G networks for high-bandwidth, low-latency communication - necessary for advanced vehicle-to-everything (V2X) services and sensor data processing - security concerns escalate. The complexity of 5G-enabled vehicles significantly expands a vehicle's attack surface. The ISO/SAE 21434 standard establishes a framework for securing road vehicle systems. The Threat Analysis and Risk Assessment (TARA) process, a vital part of this standard, helps identify and mitigate security risks. However, the current TARA process relies heavily on manual effort to identify potential attack vectors and assess risks. This can be time consuming, resource- intensive, and prone to human error. This paper discusses the concept of an automated attack graph generation tool specifically designed for automotive threat analysis. We propose a new Graph-based Attack Path Prioritization tool (GAPP), tailored for automotive networks. GAPP focuses on generating attack paths, assessing their feasibility, and identifying the most likely attack scenarios. This aims to enhance the efficiency, comprehensiveness, and accuracy of the TARA process in evaluating network security.
引用
收藏
页码:149 / 168
页数:20
相关论文
共 50 条
  • [1] Cybersecurity Threat Analysis, Risk Assessment and Design Patterns for Automotive Networked Embedded Systems: A Case Study
    Dobaj, Juergen
    Ekert, Damjan
    Stolfa, Jakub
    Stolfa, Svatopluk
    Macher, Georg
    Messnarz, Richard
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2021, 27 (08) : 830 - 849
  • [2] Valet attack on privacy: a cybersecurity threat in automotive Bluetooth infotainment systems
    Renganathan, Vishnu
    Yurtsever, Ekim
    Ahmed, Qadeer
    Yener, Aylin
    CYBERSECURITY, 2022, 5 (01)
  • [3] Valet attack on privacy: a cybersecurity threat in automotive Bluetooth infotainment systems
    Vishnu Renganathan
    Ekim Yurtsever
    Qadeer Ahmed
    Aylin Yener
    Cybersecurity, 5
  • [4] Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
    Plappert, Christian
    Zelle, Daniel
    Gadacz, Henry
    Rieke, Roland
    Scheuermann, Dirk
    Kraus, Christoph
    2021 29TH EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING (PDP 2021), 2021, : 266 - 275
  • [5] Cybersecurity: A Survey of Vulnerability Analysis and Attack Graphs
    Lahcen, Rachid Ait Maalem
    Mohapatra, Ram
    Kumar, Manish
    MATHEMATICS AND COMPUTING (ICMC 2018), 2018, 253 : 97 - 111
  • [6] Threat Analysis and Risk Assessment in Automotive Cyber Security
    Ward, David
    Ibarra, Ireri
    Ruddle, Alastair
    SAE INTERNATIONAL JOURNAL OF PASSENGER CARS-ELECTRONIC AND ELECTRICAL SYSTEMS, 2013, 6 (02): : 507 - 513
  • [7] Software and Attack Centric Integrated Threat Modeling for Quantitative Risk Assessment
    Potteiger, Bradley
    Martins, Goncalo
    Koutsoukos, Xenofon
    SYMPOSIUM AND BOOTCAMP ON THE SCIENCE OF SECURITY, 2016, : 99 - 108
  • [8] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [9] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [10] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261