Integrated Attack Tree in Residual Risk Management Framework

被引:0
|
作者
Khan, Ahmed Nawaz [1 ]
Bryans, Jeremy [1 ]
Sabaliauskaite, Giedre [2 ]
Jadidbonab, Hesamaldin [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Coventry CV1 5FB, England
[2] Swansea Univ, Dept Comp Sci, Swansea SA1 8EN, Wales
关键词
automotive cybersecurity; risk management framework; risk assessment; attack tree; ISO/SAE; 21434; SECURITY;
D O I
10.3390/info14120639
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Safety-critical cyber-physical systems (CPSs), such as high-tech cars having cyber capabilities, are highly interconnected. Automotive manufacturers are concerned about cyber attacks on vehicles that can lead to catastrophic consequences. There is a need for a new risk management approach to address and investigate cybersecurity risks. Risk management in the automotive domain is challenging due to technological improvements and advances every year. The current standard for automotive security is ISO/SAE 21434, which discusses a framework that includes threats, associated risks, and risk treatment options such as risk reduction by applying appropriate defences. This paper presents a residual cybersecurity risk management framework aligned with the framework presented in ISO/SAE 21434. A methodology is proposed to develop an integrated attack tree that considers multiple sub-systems within the CPS. Integrating attack trees in this way will help the analyst to take a broad perspective of system security. Our previous approach utilises a flow graph to calculate the residual risk to a system before and after applying defences. This paper is an extension of our initial work. It defines the steps for applying the proposed framework and using adaptive cruise control (ACC) and adaptive light control (ALC) to illustrate the applicability of our work. This work is evaluated by comparing it with the requirements of the risk management framework discussed in the literature. Currently, our methodology satisfies more than 75% of their requirements.
引用
收藏
页数:27
相关论文
共 50 条
  • [21] An Integrated Risk Management Framework: Measuring the Success of Organizational Knowledge Protection
    Thalmann, Stefan
    Manhart, Markus
    Ceravolo, Paolo
    Azzini, Antonia
    INTERNATIONAL JOURNAL OF KNOWLEDGE MANAGEMENT, 2014, 10 (02) : 28 - 42
  • [22] COSO Enterprise Risk Management: Understanding the New Integrated ERM Framework
    Cannon, David
    Godwin, Joseph H.
    Goldberg, Stephen R.
    JOURNAL OF CORPORATE ACCOUNTING AND FINANCE, 2008, 19 (02): : 83 - 85
  • [23] Research on Flood Integrated Risk Dynamic Management Framework for Coastal Cities
    Liu, Mingqiong
    Gao, Huiying
    Zhao, Chunyan
    ADVANCES IN CIVIL AND STRUCTURAL ENGINEERING III, PTS 1-4, 2014, 501-504 : 2138 - 2141
  • [24] A Framework for Web Integrated Information System for Risk Management of Natural Disasters
    Velev, Dimiter
    Zlateva, Plamena
    Velev, Vladimir
    EDUCATION AND MANAGEMENT TECHNOLOGY, ICEMT 2011, 2011, 13 : 114 - 118
  • [25] A Risk Management Framework and A Generalized Attack Automata for IoT based Smart Home Environment
    James, Fathima
    2019 3RD CYBER SECURITY IN NETWORKING CONFERENCE (CSNET), 2019,
  • [26] INTEGRATED RISK ASSESSMENT OR INTEGRATED RISK MANAGEMENT
    HART, JW
    JENSEN, NJ
    REGULATORY TOXICOLOGY AND PHARMACOLOGY, 1992, 15 (01) : 32 - 40
  • [27] Cyberattack Analysis Utilising Attack Tree with Weighted Mean Probability and Risk of Attack
    Naik, Nitin
    Jenkins, Paul
    Grace, Paul
    Prajapat, Shaligram
    Naik, Dishita
    Song, Jingping
    Xu, Jian
    Czekster, Ricardo M.
    ADVANCES IN COMPUTATIONAL INTELLIGENCE SYSTEMS, UKCI 2023, 2024, 1453 : 351 - 363
  • [28] Cyberattack Analysis Based on Attack Tree withWeighted Average Probability and Risk of Attack
    Naik, Nitin
    Jenkins, Paul
    Grace, Paul
    ADVANCES IN COMPUTATIONAL INTELLIGENCE SYSTEMS, UKCI 2022, 2024, 1454 : 324 - 333
  • [29] A FRAMEWORK FOR INTEGRATED EMERGENCY MANAGEMENT
    MCLOUGHLIN, D
    PUBLIC ADMINISTRATION REVIEW, 1985, 45 : 165 - 172
  • [30] The integrated relationship management framework
    Deszczynski, Bartosz
    EKONOMIA I PRAWO-ECONOMICS AND LAW, 2018, 17 (01): : 17 - 31