A Framework for Cybersecurity Requirements Management in the Automotive Domain

被引:2
|
作者
Luo, Feng [1 ]
Jiang, Yifan [1 ]
Wang, Jiajia [1 ]
Li, Zhihao [1 ]
Zhang, Xiaoxian [2 ]
机构
[1] Tongji Univ, Sch Automot Studies, Shanghai 201804, Peoples R China
[2] iSOFT Infrastruct Software Co Ltd, Shanghai 200125, Peoples R China
关键词
security requirements engineering; formal methods; threat analysis and risk assessment; security specification; SECURITY; SAFETY;
D O I
10.3390/s23104979
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The rapid development of intelligent connected vehicles has increased the attack surface of vehicles and made the complexity of vehicle systems unprecedented. Original equipment manufacturers (OEMs) need to accurately represent and identify threats and match corresponding security requirements. Meanwhile, the fast iteration cycle of modern vehicles requires development engineers to quickly obtain cybersecurity requirements for new features in their developed systems in order to develop system code that meets cybersecurity requirements. However, existing threat identification and cybersecurity requirement methods in the automotive domain cannot accurately describe and identify threats for a new feature while also quickly matching appropriate cybersecurity requirements. This article proposes a cybersecurity requirements management system (CRMS) framework to assist OEM security experts in conducting comprehensive automated threat analysis and risk assessment and to help development engineers identify security requirements prior to software development. The proposed CRMS framework enables development engineers to quickly model their systems using the UML-based (i.e., capable of describing systems using UML) Eclipse Modeling Framework and security experts to integrate their security experience into a threat library and security requirement library expressed in Alloy formal language. In order to ensure accurate matching between the two, a middleware communication framework called the component channel messaging and interface (CCMI) framework, specifically designed for the automotive domain, is proposed. The CCMI communication framework enables the fast model of development engineers to match with the formal model of security experts for threat and security requirement matching, achieving accurate and automated threat and risk identification and security requirement matching. To validate our work, we conducted experiments on the proposed framework and compared the results with the HEAVENS approach. The results showed that the proposed framework is superior in terms of threat detection rates and coverage rates of security requirements. Moreover, it also saves analysis time for large and complex systems, and the cost-saving effect becomes more pronounced with increasing system complexity.
引用
收藏
页数:25
相关论文
共 50 条
  • [41] Navigating the road to automotive cybersecurity compliance
    Oberti, Franco
    Abrate, Fabrizio
    Savino, Alessandro
    Parisi, Filippo
    Di Carlo, Stefano
    2024 IEEE 30TH INTERNATIONAL SYMPOSIUM ON ON-LINE TESTING AND ROBUST SYSTEM DESIGN, IOLTS 2024, 2024,
  • [42] Lightweight Cryptographic Techniques for Automotive Cybersecurity
    Jadoon, Ahmer Khan
    Wang, Licheng
    Li, Tong
    Zia, Muhammad Azam
    WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2018,
  • [43] Test and Evaluation System For Automotive Cybersecurity
    Zhang, Yanan
    Shi, Peiji
    Dong, Changqing
    Liu, Yangyang
    Shao, Xuebin
    Ma, Chao
    2018 21ST IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE 2018), 2018, : 201 - 207
  • [44] Automotive Cybersecurity Application Based on CARDIAN
    Santonicola, Emanuele
    Adinolfi, Ennio Andrea
    Coppola, Simone
    Pascale, Francesco
    FUTURE INTERNET, 2024, 16 (01)
  • [45] Cybersecurity Verification and Validation Testing in Automotive
    Ekert, Damjan
    Dobaj, Juergen
    Salamun, Alen
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2021, 27 (08) : 850 - 867
  • [46] Evaluation of Cybersecurity Management Controls and Metrics of Critical Infrastructures: A Literature Review Considering the NIST Cybersecurity Framework
    Krumay, Barbara
    Bernroider, Edward W. N.
    Walser, Roman
    SECURE IT SYSTEMS, 2018, 11252 : 369 - 384
  • [47] Persuading the Driver: A Framework for Persuasive Interface Design in the Automotive Domain
    Paraschivoiu, Irina
    Meschtscherjakov, Alexander
    Gartner, Magdalena
    Sypniewski, Jakub
    PERSUASIVE TECHNOLOGY: DEVELOPMENT OF PERSUASIVE AND BEHAVIOR CHANGE SUPPORT SYSTEMS, PERSUASIVE 2019, 2019, 11433 : 128 - 140
  • [48] Requirements and tasks for active energy management systems in automotive industry
    Franz, Enrico
    Erler, Felix
    Langer, Tino
    Schlegel, Andreas
    Stoldt, Johannes
    Richter, Mark
    Putz, Matthias
    14TH GLOBAL CONFERENCE ON SUSTAINABLE MANUFACTURING, GCSM 2016, 2017, 8 : 175 - 182
  • [49] Requirements Management in Automotive: an Empirical Study on Process Improvement Areas
    Falcini, Fabio
    Lami, Giuseppe
    2020 28TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE'20), 2020, : 271 - 279
  • [50] A framework to understand cybersecurity
    Clark, David D.
    Bridge, 2019, 49 (03) : 6 - 11