Integrated Attack Tree in Residual Risk Management Framework

被引:0
|
作者
Khan, Ahmed Nawaz [1 ]
Bryans, Jeremy [1 ]
Sabaliauskaite, Giedre [2 ]
Jadidbonab, Hesamaldin [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Coventry CV1 5FB, England
[2] Swansea Univ, Dept Comp Sci, Swansea SA1 8EN, Wales
关键词
automotive cybersecurity; risk management framework; risk assessment; attack tree; ISO/SAE; 21434; SECURITY;
D O I
10.3390/info14120639
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Safety-critical cyber-physical systems (CPSs), such as high-tech cars having cyber capabilities, are highly interconnected. Automotive manufacturers are concerned about cyber attacks on vehicles that can lead to catastrophic consequences. There is a need for a new risk management approach to address and investigate cybersecurity risks. Risk management in the automotive domain is challenging due to technological improvements and advances every year. The current standard for automotive security is ISO/SAE 21434, which discusses a framework that includes threats, associated risks, and risk treatment options such as risk reduction by applying appropriate defences. This paper presents a residual cybersecurity risk management framework aligned with the framework presented in ISO/SAE 21434. A methodology is proposed to develop an integrated attack tree that considers multiple sub-systems within the CPS. Integrating attack trees in this way will help the analyst to take a broad perspective of system security. Our previous approach utilises a flow graph to calculate the residual risk to a system before and after applying defences. This paper is an extension of our initial work. It defines the steps for applying the proposed framework and using adaptive cruise control (ACC) and adaptive light control (ALC) to illustrate the applicability of our work. This work is evaluated by comparing it with the requirements of the risk management framework discussed in the literature. Currently, our methodology satisfies more than 75% of their requirements.
引用
收藏
页数:27
相关论文
共 50 条
  • [1] An integrated framework for outsourcing risk management
    Lee, C. K. M.
    Yeung, Yu Ching
    Hong, Zhen
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2012, 112 (3-4) : 541 - 558
  • [2] An integrated framework for risk management and population health
    Krewski, Daniel
    Hogan, Victoria
    Turner, Michelle C.
    Zeman, Patricia L.
    McDowell, Ian
    Edwards, Nancy
    Losos, Joseph
    [J]. HUMAN AND ECOLOGICAL RISK ASSESSMENT, 2007, 13 (06): : 1288 - 1312
  • [3] Security risk assessment framework for smart car using the attack tree analysis
    Kong, Hee-Kyung
    Hong, Myoung Ki
    Kim, Tae-Sung
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2018, 9 (03) : 531 - 551
  • [4] Security risk assessment framework for smart car using the attack tree analysis
    Hee-Kyung Kong
    Myoung Ki Hong
    Tae-Sung Kim
    [J]. Journal of Ambient Intelligence and Humanized Computing, 2018, 9 : 531 - 551
  • [5] BPRIM: An integrated framework for business process management and risk management
    Lamine E.
    Thabet R.
    Sienou A.
    Bork D.
    Fontanili F.
    Pingaud H.
    [J]. Computers in Industry, 2019, 113
  • [6] BPRIM: An integrated framework for business process management and risk management
    Lamine, Elyes
    Thabet, Rafika
    Sienou, Amadou
    Bork, Dominik
    Fontanili, Franck
    Pingaud, Herve
    [J]. COMPUTERS IN INDUSTRY, 2020, 117 (117)
  • [7] A Survey of Fault and Attack Tree Modeling and Analysis for Cyber Risk Management
    Nagaraju, Vidhyashree
    Fiondella, Lance
    Wandji, Thierry
    [J]. 2017 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2017,
  • [8] Implementation of Risk Management in Manufacturing of Wellhead and Christmas Tree Equipment (Risk management framework)
    Hamid, Abdul
    Bin Baba, Ishak
    Hasan, Sulaiman Bin Haji
    Darmawan, Agung Setyo
    Nushatisah
    [J]. 4TH ENGINEERING SCIENCE AND TECHNOLOGY INTERNATIONAL CONFERENCE (ESTIC 2018), 2018, 248
  • [9] Integrated fuzzy framework to incorporate uncertainty in risk management
    Kumar, Vikas
    Schuhmacher, Marta
    [J]. INTERNATIONAL JOURNAL OF ENVIRONMENT AND POLLUTION, 2010, 42 (1-3) : 270 - 288
  • [10] Social Technology: An Integrated Strategy and Risk Management Framework
    Lenk, Margarita M.
    Krahel, John Peter
    Janvrin, Diane J.
    Considine, Brett
    [J]. JOURNAL OF INFORMATION SYSTEMS, 2019, 33 (02) : 129 - 153