A Framework for Cybersecurity Requirements Management in the Automotive Domain

被引:2
|
作者
Luo, Feng [1 ]
Jiang, Yifan [1 ]
Wang, Jiajia [1 ]
Li, Zhihao [1 ]
Zhang, Xiaoxian [2 ]
机构
[1] Tongji Univ, Sch Automot Studies, Shanghai 201804, Peoples R China
[2] iSOFT Infrastruct Software Co Ltd, Shanghai 200125, Peoples R China
关键词
security requirements engineering; formal methods; threat analysis and risk assessment; security specification; SECURITY; SAFETY;
D O I
10.3390/s23104979
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The rapid development of intelligent connected vehicles has increased the attack surface of vehicles and made the complexity of vehicle systems unprecedented. Original equipment manufacturers (OEMs) need to accurately represent and identify threats and match corresponding security requirements. Meanwhile, the fast iteration cycle of modern vehicles requires development engineers to quickly obtain cybersecurity requirements for new features in their developed systems in order to develop system code that meets cybersecurity requirements. However, existing threat identification and cybersecurity requirement methods in the automotive domain cannot accurately describe and identify threats for a new feature while also quickly matching appropriate cybersecurity requirements. This article proposes a cybersecurity requirements management system (CRMS) framework to assist OEM security experts in conducting comprehensive automated threat analysis and risk assessment and to help development engineers identify security requirements prior to software development. The proposed CRMS framework enables development engineers to quickly model their systems using the UML-based (i.e., capable of describing systems using UML) Eclipse Modeling Framework and security experts to integrate their security experience into a threat library and security requirement library expressed in Alloy formal language. In order to ensure accurate matching between the two, a middleware communication framework called the component channel messaging and interface (CCMI) framework, specifically designed for the automotive domain, is proposed. The CCMI communication framework enables the fast model of development engineers to match with the formal model of security experts for threat and security requirement matching, achieving accurate and automated threat and risk identification and security requirement matching. To validate our work, we conducted experiments on the proposed framework and compared the results with the HEAVENS approach. The results showed that the proposed framework is superior in terms of threat detection rates and coverage rates of security requirements. Moreover, it also saves analysis time for large and complex systems, and the cost-saving effect becomes more pronounced with increasing system complexity.
引用
收藏
页数:25
相关论文
共 50 条
  • [31] Reassessing the Pattern-Based Approach for Formalizing Requirements in the Automotive Domain
    Filipovikj, Predrag
    Nyberg, Mattias
    Rodriguez-Navas, Guillermo
    2014 IEEE 22ND INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE), 2014, : 444 - 450
  • [32] Federated Blockchained Supply Chain Management: A CyberSecurity and Privacy Framework
    Demertzis, Konstantinos
    Iliadis, Lazaros
    Pimenidis, Elias
    Tziritas, Nikolaos
    Koziri, Maria
    Kikiras, Panagiotis
    Tonkin, Michael
    ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS, AIAI 2021, 2021, 627 : 769 - 779
  • [33] Assets focus risk management framework for critical infrastructure cybersecurity risk management
    Kure, Halima Ibrahim
    Islam, Shareeful
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2019, 4 (04) : 332 - 340
  • [34] Cybersecurity Risk Management Framework for Blockchain Identity Management Systems in Health IoT
    Alamri, Bandar
    Crowley, Katie
    Richardson, Ita
    SENSORS, 2023, 23 (01)
  • [35] Context-Based and Adaptive Cybersecurity Risk Management Framework
    Melaku, Henock Mulugeta
    RISKS, 2023, 11 (06)
  • [36] Situational Crime Prevention for Automotive Cybersecurity
    Polanco, Nick
    Cheng, Betty
    ACM/IEEE 25TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS, MODELS 2022 COMPANION, 2022, : 562 - 568
  • [37] CyberROAD: A cybersecurity risk assessment ontology for automotive domain aligned with ISO/SAE 21434:2021
    Khalil, Karim
    Gehrmann, Christian
    Vogel, Guenther
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2025, 90
  • [38] SPAT: A Testbed for Automotive Cybersecurity Training
    Caviglia, Roberto
    Gaggero, Giovanni Battista
    Vincis, Nicola
    Morando, Omar
    Aceti, Alessio
    Marchese, Mario
    2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 381 - 386
  • [39] Cybersecurity policy framework requirements for the establishment of highly interoperable and interconnected health data spaces
    Luidold, Christian
    Jungbauer, Christoph
    FRONTIERS IN MEDICINE, 2024, 11
  • [40] Automotive Cybersecurity Standards - Relation and Overview
    Schmittner, Christoph
    Macher, Georg
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019, 2019, 11699 : 153 - 165