SaSeVAL: A Safety/Security-Aware Approach for Validation of Safety-Critical Systems

被引:2
|
作者
Wolschke, Christian [1 ]
Sangchoolie, Behrooz [2 ]
Simon, Jacob [3 ]
Marksteiner, Stefan [4 ]
Braun, Tobias [1 ]
Hamazaryan, Hayk [5 ]
机构
[1] Fraunhofer IESE, Kaiserslautern, Germany
[2] RISE Res Inst Sweden, Boras, Sweden
[3] China Euro Vehicle Technol, CEVT, Gothenburg, Sweden
[4] AVL List GmbH, Graz, Austria
[5] ZF Friedrichshafen AG, Friedrichshafen, Germany
基金
欧盟地平线“2020”;
关键词
safety; security testing; attack description; threats; threat library; risk assessment;
D O I
10.1109/DSN-W52860.2021.00016
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Increasing communication and self-driving capabilities for road vehicles lead to threats which could potentially be exploited by attackers. Especially attacks leading to safety violations have to be identified to address them by appropriate measures. The impact of an attack depends on the threat exploited, potential countermeasures and the traffic situation. In order to identify such attacks and to use them for testing, we propose the systematic approach SaSeVAL for deriving attacks of autonomous vehicles. SaSeVAL is based on threats identification and safety-security analysis. The impact of automotive use cases to attacks is considered. The threat identification considers the attack interface of vehicles and classifies threat scenarios according to threat types, which are then mapped to attack types. The safety-security analysis identifies the necessary requirements which have to be tested based on the architecture of the system under test. It determines which safety impact a security violation may have, and in which traffic situations the highest impact is expected. Finally, the results of threat identification and safety-security analysis are used to describe attacks. The goal of SaSeVAL is to achieve safety validation of the vehicle w.r.t. security concerns. It traces safety goals to threats and to attacks explicitly. Hence, the coverage of safety concerns by security testing is assured. Two use cases of vehicle communication and autonomous driving are investigated to prove the applicability of the approach.
引用
收藏
页码:27 / 34
页数:8
相关论文
共 50 条
  • [41] An integrated approach to scheduling in safety-critical embedded control systems
    Bate, I
    Burns, A
    [J]. REAL-TIME SYSTEMS, 2003, 25 (01) : 5 - 37
  • [42] Simulation and Validation Framework for Safety-Critical Applications in System-of-Systems
    Murshed, Ayman
    Abuteir, Mohammed
    Obermaisser, Roman
    [J]. 2018 IEEE 23RD INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2018, : 376 - 383
  • [43] A Validation Metrics Framework for Safety-Critical Software-Intensive Systems
    Cruickshank, Kristian J.
    Michael, James Bret
    Shing, Man-Tak
    [J]. 2009 IEEE INTERNATIONAL CONFERENCE ON SYSTEM OF SYSTEMS ENGINEERING SOSE 2009, 2009, : 109 - +
  • [44] Validation and certification of safety-critical embedded systems -: The DECOS test bench
    Schoitsch, Erwin
    Althammer, Egbert
    Eriksson, Henrik
    Vinter, Jormy
    Goenczy, Laszlo
    Pataricza, Andras
    Csertan, Gyoergy
    [J]. COMPUTER SAFETY, RELIABILTIY, AND SECURITY, PROCEEDINGS, 2006, 4166 : 372 - 385
  • [45] Dual-model approach for safety-critical embedded systems
    Labiak, Grzegorz
    Wegrzyn, Marek
    Rosado-Munoz, Alfredo
    Bazydlo, Grzegorz
    [J]. MICROPROCESSORS AND MICROSYSTEMS, 2020, 72
  • [46] An Aspect-Oriented Approach for Designing Safety-Critical Systems
    Petrov, Zlatko
    Zaykov, Pavel G.
    Cardoso, Joao M. P.
    Coutinho, Jose G. F.
    Diniz, Pedro C.
    Luk, Wayne
    [J]. 2013 IEEE AEROSPACE CONFERENCE, 2013,
  • [47] SAFETY AND SECURITY PROFILES OF INDUSTRY NETWORKS USED IN SAFETY-CRITICAL APPLICATIONS
    Franekova, Maria
    [J]. TRANSPORT PROBLEMS, 2008, 3 (04) : 25 - 32
  • [48] An approach for testing safety-critical software
    Li, WW
    Xu, ZW
    Jin, Y
    [J]. NINTH GREAT LAKES SYMPOSIUM ON VLSI, PROCEEDINGS, 1999, : 180 - 183
  • [49] An Integrated Approach to Scheduling in Safety-Critical Embedded Control Systems
    I. Bate
    A. Burns
    [J]. Real-Time Systems, 2003, 25 : 5 - 37
  • [50] Design Verification and Validation for Reliable Safety-critical Autonomous Control Systems
    Yan, Rongjie
    Yang, Junjie
    Zhu, Di
    Huang, Kai
    [J]. 2018 23RD INTERNATIONAL CONFERENCE ON ENGINEERING OF COMPLEX COMPUTER SYSTEMS (ICECCS), 2018, : 170 - 179