A Model-Based Security Testing Approach for Automotive Over-The-Air Updates

被引:9
|
作者
Mahmood, Shahid [1 ]
Fouillade, Alexy [2 ]
Hoang Nga Nguyen [1 ]
Shaikh, Siraj A. [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Syst Secur Grp, Coventry, W Midlands, England
[2] Grande Ecole Ingenieurs Generalistes Angers, Ecole Super Elect Ouest, Angers, France
关键词
over-the-air updates; OTA; automotive; cybersecurity; testing; testbed; testing approach; model-based security testing; attack tree;
D O I
10.1109/ICSTW50294.2020.00019
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Modern connected cars are exposed to various cybersecurity threats due to the sophisticated computing and connectivity technologies they host for providing enhanced user experience for their occupants by offering numerous innovative applications. While prior studies exist that explore cybersecurity challenges, tools and techniques for automotive systems, over-the-air (OTA) software updates for automobiles can be exploited by the attackers to compromise vehicle security and safety has not been covered extensively. This paper presents our Model-Based Security Testing (MBST) approach, designed for cybersecurity evaluation of the OTA update system for automobiles, which has an integrated testbed and a software tool that is capable of automatically generating and executing test cases by using attack trees as an input. Integrating threat modelling in the testing provides several benefits, including clear and systematic identification of different threats. Automation of the test-case generation and execution has the obvious benefits of saving time and manual effort, as manual test-case generation is both a time-consuming and error-prone process (especially, when the testing involves several test-cases). A simple simulated attack is used to demonstrate the validity and effectiveness of our testing approach. To the best of our knowledge, there is no prior research that uses a testing approach similar to our approach for automotive OTA security evaluation.
引用
收藏
页码:6 / 13
页数:8
相关论文
共 50 条
  • [1] The Security Aspects of Automotive Over-the-Air Updates
    Howden, James
    Maglaras, Leandros
    Ferrag, Mohamed Amine
    [J]. INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2020, 10 (02) : 64 - 81
  • [2] Systematic threat assessment and security testing of automotive over-the-air (OTA) updates
    Mahmood, Shahid
    Nguyen, Hoang Nga
    Shaikh, Siraj Ahmed
    [J]. VEHICULAR COMMUNICATIONS, 2022, 35
  • [3] Assessing the Cost of Quantum Security for Automotive Over-The-Air Updates
    La Manna, Michele
    Perazzo, Pericle
    Treccozzi, Luigi
    Dini, Gianluca
    [J]. 26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [4] Safe and Secure Automotive Over-the-Air Updates
    Chowdhury, Thomas
    Lesiuta, Eric
    Rikley, Kerianne
    Lin, Chung-Wei
    Kang, Eunsuk
    Kim, BaekGyu
    Shiraishi, Shinichi
    Lawford, Mark
    Wassyng, Alan
    [J]. COMPUTER SAFETY, RELIABILITY, AND SECURITY (SAFECOMP 2018), 2018, 11093 : 172 - 187
  • [5] A formal framework for security testing of automotive over-the-air update systems
    Kirk, Rhys
    Nguyen, Hoang Nga
    Bryans, Jeremy
    Shaikh, Siraj Ahmed
    Wartnaby, Charles
    [J]. JOURNAL OF LOGICAL AND ALGEBRAIC METHODS IN PROGRAMMING, 2023, 130
  • [6] Automotive Digital Twins: A Traversal Algorithm for Virtual Testing of Software over-the-air Updates
    Fuchs, Till
    Zinser, Matthias
    Renatus, Kevin
    Baeker, Bernard
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON MECHATRONICS, ICM, 2023,
  • [7] Over-The-Air Automotive Radar System Testing
    Hamberger, Gerhard F.
    Bogner, Maximilian
    Neidhardt, Steffen
    Beer, Matthias
    [J]. 2023 INTERNATIONAL WORKSHOP ON ANTENNA TECHNOLOGY, IWAT, 2023,
  • [8] How Trustworthy are Over-The-Air (OTA) Updates for Autonomous Vehicles (AV) to Ensure Public Safety?: A Threat Model-based Security Analysis
    Chowdhury, N. M. Istiak
    Hasan, Ragib
    [J]. 2024 IEEE WORLD FORUM ON PUBLIC SAFETY TECHNOLOGY, WFPST 2024, 2024, : 87 - 92
  • [9] Practical Security and Privacy Threat Analysis in the Automotive Domain: Long Term Support Scenario for Over-the-Air Updates
    Vasenev, Alexandr
    Stahl, Florian
    Hamazaryan, Hayk
    Ma, Zhendong
    Shan, Lijun
    Kemmerich, Joerg
    Loiseaux, Claire
    [J]. PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON VEHICLE TECHNOLOGY AND INTELLIGENT TRANSPORT SYSTEMS (VEHITS 2019), 2019, : 550 - 555
  • [10] A Model-Based Approach to Automotive Feature Development for Updates and Upgrades
    Schindewolf, Marc
    Wittler, Jan Willem
    Kuehn, Thomas
    Grimm, Daniel
    Sax, Eric
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON SERVICE-ORIENTED SYSTEM ENGINEERING, SOSE, 2023, : 19 - 26