Integrated Attack Tree in Residual Risk Management Framework

被引:0
|
作者
Khan, Ahmed Nawaz [1 ]
Bryans, Jeremy [1 ]
Sabaliauskaite, Giedre [2 ]
Jadidbonab, Hesamaldin [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Coventry CV1 5FB, England
[2] Swansea Univ, Dept Comp Sci, Swansea SA1 8EN, Wales
关键词
automotive cybersecurity; risk management framework; risk assessment; attack tree; ISO/SAE; 21434; SECURITY;
D O I
10.3390/info14120639
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Safety-critical cyber-physical systems (CPSs), such as high-tech cars having cyber capabilities, are highly interconnected. Automotive manufacturers are concerned about cyber attacks on vehicles that can lead to catastrophic consequences. There is a need for a new risk management approach to address and investigate cybersecurity risks. Risk management in the automotive domain is challenging due to technological improvements and advances every year. The current standard for automotive security is ISO/SAE 21434, which discusses a framework that includes threats, associated risks, and risk treatment options such as risk reduction by applying appropriate defences. This paper presents a residual cybersecurity risk management framework aligned with the framework presented in ISO/SAE 21434. A methodology is proposed to develop an integrated attack tree that considers multiple sub-systems within the CPS. Integrating attack trees in this way will help the analyst to take a broad perspective of system security. Our previous approach utilises a flow graph to calculate the residual risk to a system before and after applying defences. This paper is an extension of our initial work. It defines the steps for applying the proposed framework and using adaptive cruise control (ACC) and adaptive light control (ALC) to illustrate the applicability of our work. This work is evaluated by comparing it with the requirements of the risk management framework discussed in the literature. Currently, our methodology satisfies more than 75% of their requirements.
引用
收藏
页数:27
相关论文
共 50 条
  • [41] Integrated Framework for Virtual Team Management
    Martinic, Ante
    Fertalj, Kresimir
    Kalpic, Damir
    PROCEEDINGS OF THE ITI 2012 34TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES (ITI), 2012, : 149 - 154
  • [42] A Conceptual Framework for Integrated Pest Management
    Stenberg, Johan A.
    TRENDS IN PLANT SCIENCE, 2017, 22 (09) : 759 - 769
  • [43] Risk Assessment of Attack in Autonomous Vehicle based on a Decision Tree
    Ftaimi, Sara
    Mazri, Tomader
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (07) : 792 - 801
  • [44] Integrated Energy Management Framework - Aatral
    Thangaraj, M.
    Anuradha, S.
    PROCEEDING OF THE THIRD INTERNATIONAL SYMPOSIUM ON WOMEN IN COMPUTING AND INFORMATICS (WCI-2015), 2015, : 698 - 707
  • [45] Integrated framework for earthquake consequences management
    Momani, Naill M.
    DISASTER PREVENTION AND MANAGEMENT, 2012, 21 (02) : 184 - 205
  • [46] A framework for integrated configuration management tools
    Vanbrabant, Bart
    Joosen, Wouter
    2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 534 - 540
  • [47] Towards an Integrated IT Governance and IT Management Framework
    Pereira, Ruben
    da Silva, Miguel Mira
    2012 IEEE 16TH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE (EDOC), 2012, : 191 - 200
  • [48] An Integrated Framework for Information Security Management
    Ma, Qingxiong
    Schmidt, Mark B.
    Pearson, J. Michael
    REVIEW OF BUSINESS, 2009, 30 (01): : 58 - 69
  • [49] INTEGRATED FRAMEWORK FOR PERSONNEL UTILIZATION AND MANAGEMENT
    ROTER, B
    PERSONNEL JOURNAL, 1973, 52 (12) : 1031 - 1039
  • [50] FRAMEWORK FOR AN INTEGRATED BUSINESS PROCESS MANAGEMENT
    SCHEER, AW
    NUTTGENS, M
    ZIMMERMANN, V
    WIRTSCHAFTSINFORMATIK, 1995, 37 (05): : 426 - 434