Practical Security and Privacy Threat Analysis in the Automotive Domain: Long Term Support Scenario for Over-the-Air Updates

被引:11
|
作者
Vasenev, Alexandr [1 ]
Stahl, Florian [2 ]
Hamazaryan, Hayk [3 ]
Ma, Zhendong [4 ]
Shan, Lijun [5 ]
Kemmerich, Joerg [3 ]
Loiseaux, Claire [5 ]
机构
[1] ESI TNO, Eindhoven, Netherlands
[2] AVL Software & Funct, Regensburg, Germany
[3] ZF Friedrichshafen AG, Friedrichshafen, Germany
[4] AVL, Graz, Austria
[5] Internet Trust, Paris, France
基金
欧盟地平线“2020”;
关键词
Data Flow Diagram; STRIDE Taxonomy; LINDDUN Methodology; UNECE Threat Catalogue; Risk Management;
D O I
10.5220/0007764205500555
中图分类号
U [交通运输];
学科分类号
08 ; 0823 ;
摘要
Keeping a vehicle secure implies provide of a long-term support, where over-the-air updates (OTA) play an essential role. Clear understanding of OTA threats is essential to counter them efficiently. Existing research on OTA threats often exclude human actors, such as drivers and maintenance personnel, as well as leave aside privacy threats. This paper addresses the gap by investigates security and privacy OTA threats relevant for vehicle manufacturers for the whole product lifecycle. We report on a practical scenario "long term support", its data flow elements, and outcomes of threat analyses. We apply state of the art approaches, such as STRIDE (extended with an automotive template) and LINDDUN, to an automotive case and consider an automotive-specific UNECE OTA threat catalogue. Outcomes indicate complementarity of these methods and provide inputs to studies how well they address practical automotive cases.
引用
收藏
页码:550 / 555
页数:6
相关论文
共 6 条
  • [1] The Security Aspects of Automotive Over-the-Air Updates
    Howden, James
    Maglaras, Leandros
    Ferrag, Mohamed Amine
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2020, 10 (02) : 64 - 81
  • [2] Systematic threat assessment and security testing of automotive over-the-air (OTA) updates
    Mahmood, Shahid
    Nguyen, Hoang Nga
    Shaikh, Siraj Ahmed
    [J]. VEHICULAR COMMUNICATIONS, 2022, 35
  • [3] Assessing the Cost of Quantum Security for Automotive Over-The-Air Updates
    La Manna, Michele
    Perazzo, Pericle
    Treccozzi, Luigi
    Dini, Gianluca
    [J]. 26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [4] An Approach of Scenario-Based Threat Analysis and Risk Assessment Over-the-Air updates for an Autonomous Vehicle
    Khatun, Marzana
    Glass, Michael
    Jung, Rolf
    [J]. 2021 7TH INTERNATIONAL CONFERENCE ON AUTOMATION, ROBOTICS AND APPLICATIONS (ICARA 2021), 2021, : 122 - 127
  • [5] A Model-Based Security Testing Approach for Automotive Over-The-Air Updates
    Mahmood, Shahid
    Fouillade, Alexy
    Hoang Nga Nguyen
    Shaikh, Siraj A.
    [J]. 2020 IEEE 13TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW), 2020, : 6 - 13
  • [6] How Trustworthy are Over-The-Air (OTA) Updates for Autonomous Vehicles (AV) to Ensure Public Safety?: A Threat Model-based Security Analysis
    Chowdhury, N. M. Istiak
    Hasan, Ragib
    [J]. 2024 IEEE WORLD FORUM ON PUBLIC SAFETY TECHNOLOGY, WFPST 2024, 2024, : 87 - 92