Rule-Based Threat Analysis and Mitigation for the Automotive Domain

被引:0
|
作者
Shaaban, Abdelkader Magdy [1 ]
Jaksic, Stefan [1 ]
Veledar, Omar [2 ]
Mauthner, Thomas [2 ]
Arnautovic, Edin [3 ]
Schmittner, Christoph [1 ]
机构
[1] AIT Austrian Inst Technol GmbH, Vienna, Austria
[2] AVL List GmbH, Graz, Austria
[3] TTTech Comp Tech AG, Vienna, Austria
基金
欧盟地平线“2020”;
关键词
Security; Threat analysis; Ontology; Automated driving;
D O I
10.1007/978-3-030-83906-2_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity is given a prominent role in curbing risks encountered by novel technologies, specifically the case in the automotive domain, where the possibility of cyberattacks impacts vehicle operation and safety. The potential threats must be identified and mitigated to guarantee the flawless operation of the safety-critical systems. This paper presents a novel approach to identify security vulnerabilities in automotive architectures and automatically propose mitigation strategies using rule-based reasoning. The rules, encoded in ontologies, enable establishing clear relationships in the vast combinatorial space of possible security threats and related assets, security measures, and security requirements from the relevant standards. We evaluate our approach on a mixed-criticality platform, typically used to develop Autonomous Driving (AD) features, and provide a generalized threat model that serves as a baseline for threat analysis of proprietary AD architectures.
引用
收藏
页码:24 / 38
页数:15
相关论文
共 50 条
  • [1] Rule-based generalization of threat without similarity
    Marstaller, Lars
    Al-Jiboury, Rizah
    Kemp, Andrew H.
    Dymond, Simon
    [J]. BIOLOGICAL PSYCHOLOGY, 2021, 160
  • [2] Rule-Based System for Data Leak Threat Estimation
    Vukovic, Marin
    Katusic, Damjan
    Soic, Renato
    Weber, Mario
    [J]. 2017 25TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2017, : 342 - 346
  • [3] Rule-Based Knowledge Management in Social Threat Monitor
    Baran, Mateusz
    Ligeza, Antoni
    [J]. MULTIMEDIA COMMUNICATIONS, SERVICES AND SECURITY, MCSS 2013, 2013, 368 : 1 - 12
  • [4] Rule-based autotuning based on frequency domain identification
    McCormack, AS
    Godfrey, KR
    [J]. IEEE TRANSACTIONS ON CONTROL SYSTEMS TECHNOLOGY, 1998, 6 (01) : 43 - 61
  • [5] Fast Rule-Based Clutter Detection in Automotive Radar Data
    Kopp, Johannes
    Kellner, Dominik
    Piroli, Aldi
    Dietmayer, Klaus
    [J]. 2021 IEEE INTELLIGENT TRANSPORTATION SYSTEMS CONFERENCE (ITSC), 2021, : 3010 - 3017
  • [6] Standard Compliant Hazard and Threat Analysis for the Automotive Domain
    Beckers, Kristian
    Duerrwang, Juergen
    Holling, Dominik
    [J]. INFORMATION, 2016, 7 (03)
  • [7] Rule-based active domain brokering for the semantic Web
    Behrends, Erik
    Fritzen, Oliver
    Knabke, Tobias
    May, Wolfgang
    Schenk, Franz
    [J]. WEB REASONING AND RULE SYSTEMS, PROCEEDINGS, 2007, 4524 : 259 - +
  • [8] A rule-based framework for risk assessment in the health domain
    Cattelani, Luca
    Chesani, Federico
    Palmerini, Luca
    Palumbo, Pierpaolo
    Chiari, Lorenzo
    Bandinelli, Stefania
    [J]. INTERNATIONAL JOURNAL OF APPROXIMATE REASONING, 2020, 119 (119) : 242 - 259
  • [9] A rule-based domain specific language for fault management
    Kaya, Ozgur
    Hashemikhabir, Seyedsasan
    Togay, Cengiz
    Dogru, Ali Hikmet
    [J]. Journal of Integrated Design and Process Science, 2010, 14 (03): : 13 - 23
  • [10] A RULE-BASED DOMAIN SPECIFIC LANGUAGE FOR FAULT MANAGEMENT
    Kaya, Ozgur
    Togay, Cengiz
    Dogru, Ali
    [J]. JOURNAL OF INTEGRATED DESIGN & PROCESS SCIENCE, 2010, 14 (03) : 13 - 23