A Framework for Cybersecurity Requirements Management in the Automotive Domain

被引:2
|
作者
Luo, Feng [1 ]
Jiang, Yifan [1 ]
Wang, Jiajia [1 ]
Li, Zhihao [1 ]
Zhang, Xiaoxian [2 ]
机构
[1] Tongji Univ, Sch Automot Studies, Shanghai 201804, Peoples R China
[2] iSOFT Infrastruct Software Co Ltd, Shanghai 200125, Peoples R China
关键词
security requirements engineering; formal methods; threat analysis and risk assessment; security specification; SECURITY; SAFETY;
D O I
10.3390/s23104979
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The rapid development of intelligent connected vehicles has increased the attack surface of vehicles and made the complexity of vehicle systems unprecedented. Original equipment manufacturers (OEMs) need to accurately represent and identify threats and match corresponding security requirements. Meanwhile, the fast iteration cycle of modern vehicles requires development engineers to quickly obtain cybersecurity requirements for new features in their developed systems in order to develop system code that meets cybersecurity requirements. However, existing threat identification and cybersecurity requirement methods in the automotive domain cannot accurately describe and identify threats for a new feature while also quickly matching appropriate cybersecurity requirements. This article proposes a cybersecurity requirements management system (CRMS) framework to assist OEM security experts in conducting comprehensive automated threat analysis and risk assessment and to help development engineers identify security requirements prior to software development. The proposed CRMS framework enables development engineers to quickly model their systems using the UML-based (i.e., capable of describing systems using UML) Eclipse Modeling Framework and security experts to integrate their security experience into a threat library and security requirement library expressed in Alloy formal language. In order to ensure accurate matching between the two, a middleware communication framework called the component channel messaging and interface (CCMI) framework, specifically designed for the automotive domain, is proposed. The CCMI communication framework enables the fast model of development engineers to match with the formal model of security experts for threat and security requirement matching, achieving accurate and automated threat and risk identification and security requirement matching. To validate our work, we conducted experiments on the proposed framework and compared the results with the HEAVENS approach. The results showed that the proposed framework is superior in terms of threat detection rates and coverage rates of security requirements. Moreover, it also saves analysis time for large and complex systems, and the cost-saving effect becomes more pronounced with increasing system complexity.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] Cybersecurity Testing for Automotive Domain: A Survey
    Luo, Feng
    Zhang, Xuan
    Yang, Zhenyu
    Jiang, Yifan
    Wang, Jiajia
    Wu, Mingzhi
    Feng, Wanqiang
    SENSORS, 2022, 22 (23)
  • [2] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [3] On Synthesizing Technical Cybersecurity Requirements for Automotive Embedded Systems
    Dattathreya, Macam S.
    Bechtel, James E.
    Mikulski, Dariusz
    2016 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE & COMPUTATIONAL INTELLIGENCE (CSCI), 2016, : 1074 - 1076
  • [4] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [5] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261
  • [6] A Service Oriented Ontology Management Framework in the Automotive Retail Domain
    Lu, Jinghui
    Wang, Shuying
    Capretz, Miriam A. M.
    CSE 2008: PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING, 2008, : 239 - 244
  • [7] Consistency of Cybersecurity Process and Product Assessments in the Automotive Domain
    Schlager, Christian
    Messnarz, Richard
    Ekert, Damjan
    Danmayr, Tobias
    Aschbacher, Laura
    Iriskic, Almin
    Macher, Georg
    Brenner, Eugen
    SYSTEMS, SOFTWARE AND SERVICES PROCESS IMPROVEMENT, EUROSPI 2023, PT I, 2023, 1890 : 343 - 355
  • [8] Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
    Plappert, Christian
    Zelle, Daniel
    Gadacz, Henry
    Rieke, Roland
    Scheuermann, Dirk
    Kraus, Christoph
    2021 29TH EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING (PDP 2021), 2021, : 266 - 275
  • [9] Development of a Novel Automotive Cybersecurity, Integrity Level, Framework
    Torok, Arpad
    Szalay, Zsolt
    Saghi, Balazs
    ACTA POLYTECHNICA HUNGARICA, 2020, 17 (01) : 141 - 159
  • [10] Reconsidering the Cybersecurity Framework in the Road Transportation Domain
    Obaid, Mohammed
    Szalay, Zsolt
    Torok, Arpad
    ACTA POLYTECHNICA HUNGARICA, 2020, 17 (09) : 57 - 83