CASCADE: An Asset-driven Approach to Build Security Assurance Cases for Automotive Systems

被引:1
|
作者
Mohamad, Mazen [1 ,2 ]
Jolak, Rodi [1 ,2 ]
Askerdal, Orjan [3 ]
Steghofer, Jan-Philipp [1 ,2 ]
Scandariato, Riccardo [4 ]
机构
[1] Chalmers, Chalmersplatsen 4, S-41296 Gothenburg, Sweden
[2] Univ Gothenburg, Chalmersplatsen 4, S-41296 Gothenburg, Sweden
[3] Volvo Trucks, Herkulesgatan 75, SE-40508 Gothenburg, Sweden
[4] Hamburg Univ Technol, Schwarzenberg Campus 1, D-21073 Hamburg, Germany
关键词
Security; assurance cases; automotive systems; DESIGN SCIENCE;
D O I
10.1145/3569459
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Security Assurance Cases (SAC) are structured arguments and evidence bodies used to reason about the security of a certain system. SACs are gaining focus in the automotive industry, as the needs for security assurance are growing in this domain. However, the state-of-the-arts lack a mature approach able to suit the needs of the automotive industry. In this article, we present CASCADE, an asset-driven approach for creating SAC, which is inspired by the upcoming security standard ISO/SAE-21434 as well as the internal needs of automotive Original Equipment Manufacturers (OEMs). CASCADE also differentiates itself from the stateof-the-art by incorporating a way to reason about the quality of the constructed security assurance case. We created the approach by conducting an iterative design science research study. We illustrate the results using the example case of the road vehicle's headlamp provided in the ISO standard. We also illustrate how our approach aligns well with the structure and content of the ISO/SAE-21434 standard, hence demonstrating the practical applicability of CASCADE in an industrial context.
引用
收藏
页数:26
相关论文
共 28 条
  • [1] Asset-driven Security Assurance Cases with Built-in Quality Assurance
    Mohamad, Mazen
    Askerdal, Orjan
    Jolak, Rodi
    Steghofer, Jan-Philipp
    Scandariato, Riccardo
    [J]. 2021 IEEE/ACM 2ND INTERNATIONAL WORKSHOP ON ENGINEERING AND CYBERSECURITY OF CRITICAL SYSTEMS (ENCYCRIS 2021), 2021, : 29 - 36
  • [2] Asset-Driven Approach for Security Risk Assessment in IoT Systems
    Chehida, Salim
    Baouya, Abdelhakim
    Alonso, Diego Fernandez
    Brun, Paul-Emmanuel
    Massot, Guillemette
    Bozga, Marius
    Bensalem, Saddek
    [J]. RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2020), 2021, 12528 : 149 - 163
  • [3] Security assurance cases—state of the art of an emerging approach
    Mazen Mohamad
    Jan-Philipp Steghöfer
    Riccardo Scandariato
    [J]. Empirical Software Engineering, 2021, 26
  • [4] Safety Driven Optimization Approach for Automotive Systems
    Dhouibi, Mohamed Slim
    Saintis, Laurent
    Barreau, Mihaela
    Perquis, Jean-Marc
    [J]. 2015 61ST ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2015), 2015,
  • [5] Security assurance cases-state of the art of an emerging approach
    Mohamad, Mazen
    Steghofer, Jan-Philipp
    Scandariato, Riccardo
    [J]. EMPIRICAL SOFTWARE ENGINEERING, 2021, 26 (04)
  • [6] Security Assurance Cases for Medical Cyber-Physical Systems
    Ray, Arnab
    Cleaveland, Rance
    [J]. IEEE DESIGN & TEST, 2015, 32 (05) : 56 - 65
  • [7] A Risk based Approach for Security Assurance Evaluation of IT Systems
    Ouedraogo, Moussa
    Mouratidis, Haralambos
    Khadraoui, Djamel
    Dubois, Eric
    [J]. 2009 7TH ANNUAL COMMUNICATION NETWORKS AND SERVICES RESEARCH CONFERENCE, 2009, : 428 - +
  • [8] Towards a unified approach to safety and security in automotive systems
    Jesty, Peter H.
    Ward, David D.
    [J]. SAFETY OF SYSTEMS, 2007, : 21 - 34
  • [9] Evolutionary Algorithms to Generate Test Cases for Safety and IT-Security in Automotive Systems
    Lauber, Andreas
    Sommer, Martin
    Fuchs, Kevin
    Sax, Eric
    [J]. 2020 14TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON2020), 2020,
  • [10] Data-Driven Development, A Complementing Approach for Automotive Systems Engineering
    Bach, Johannes
    Langner, Jacob
    Otten, Stefan
    Holzaepfel, Marc
    Sax, Eric
    [J]. 2017 IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (ISSE 2017), 2017, : 283 - 288