Integrated Attack Tree in Residual Risk Management Framework

被引:0
|
作者
Khan, Ahmed Nawaz [1 ]
Bryans, Jeremy [1 ]
Sabaliauskaite, Giedre [2 ]
Jadidbonab, Hesamaldin [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Coventry CV1 5FB, England
[2] Swansea Univ, Dept Comp Sci, Swansea SA1 8EN, Wales
关键词
automotive cybersecurity; risk management framework; risk assessment; attack tree; ISO/SAE; 21434; SECURITY;
D O I
10.3390/info14120639
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Safety-critical cyber-physical systems (CPSs), such as high-tech cars having cyber capabilities, are highly interconnected. Automotive manufacturers are concerned about cyber attacks on vehicles that can lead to catastrophic consequences. There is a need for a new risk management approach to address and investigate cybersecurity risks. Risk management in the automotive domain is challenging due to technological improvements and advances every year. The current standard for automotive security is ISO/SAE 21434, which discusses a framework that includes threats, associated risks, and risk treatment options such as risk reduction by applying appropriate defences. This paper presents a residual cybersecurity risk management framework aligned with the framework presented in ISO/SAE 21434. A methodology is proposed to develop an integrated attack tree that considers multiple sub-systems within the CPS. Integrating attack trees in this way will help the analyst to take a broad perspective of system security. Our previous approach utilises a flow graph to calculate the residual risk to a system before and after applying defences. This paper is an extension of our initial work. It defines the steps for applying the proposed framework and using adaptive cruise control (ACC) and adaptive light control (ALC) to illustrate the applicability of our work. This work is evaluated by comparing it with the requirements of the risk management framework discussed in the literature. Currently, our methodology satisfies more than 75% of their requirements.
引用
收藏
页数:27
相关论文
共 50 条
  • [31] A framework to measure integrated risk
    Medova, EA
    Smith, RG
    [J]. QUANTITATIVE FINANCE, 2005, 5 (01) : 105 - 121
  • [32] Integrated framework for safety management and uncertainty management
    Abrahamsen, E. B.
    Aven, T.
    Iversen, R. S.
    [J]. PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2010, 224 (O2) : 97 - 103
  • [33] Integrated risk management
    Clarke, I
    [J]. HAZARDS XV: THE PROCESS, ITS SAFETY AND THE ENVIRONMENT - GETTING IT RIGHT, 2000, (147): : 551 - 562
  • [34] A FRAMEWORK FOR RISK MANAGEMENT
    FROOT, KA
    SCHARFSTEIN, DS
    STEIN, JC
    [J]. HARVARD BUSINESS REVIEW, 1994, 72 (06) : 91 - &
  • [35] Risk management integrated
    Stavrianidis, P
    [J]. INTECH, 1999, 46 (07) : 172 - 173
  • [36] Managing Climate Change Risk in China's Agricultural Sector: The Potential for an Integrated Risk Management Framework
    Chen, Kevin Z.
    Hsu, Claire
    [J]. JOURNAL OF INTEGRATIVE AGRICULTURE, 2014, 13 (07) : 1418 - 1431
  • [37] Managing Climate Change Risk in China's Agricultural Sector: The Potential for an Integrated Risk Management Framework
    Kevin Z.Chen
    Claire Hsu
    [J]. Journal of Integrative Agriculture, 2014, (07) : 1418 - 1431
  • [38] Pension Risk Management in the Enterprise Risk Management Framework
    Lin, Yijia
    MacMinn, Richard D.
    Tian, Ruilin
    Yu, Jifeng
    [J]. JOURNAL OF RISK AND INSURANCE, 2017, 84 : 345 - 365
  • [39] Risk and knowledge-informed framework for residual risk decisions
    Lengyel, David M.
    Moses, Kelly D.
    [J]. JOURNAL OF SPACE SAFETY ENGINEERING, 2022, 9 (01): : 12 - 17
  • [40] A Conceptual Framework for Integrated Pest Management
    Stenberg, Johan A.
    [J]. TRENDS IN PLANT SCIENCE, 2017, 22 (09) : 759 - 769