A Model-Based Security Testing Approach for Automotive Over-The-Air Updates

被引:9
|
作者
Mahmood, Shahid [1 ]
Fouillade, Alexy [2 ]
Hoang Nga Nguyen [1 ]
Shaikh, Siraj A. [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Syst Secur Grp, Coventry, W Midlands, England
[2] Grande Ecole Ingenieurs Generalistes Angers, Ecole Super Elect Ouest, Angers, France
关键词
over-the-air updates; OTA; automotive; cybersecurity; testing; testbed; testing approach; model-based security testing; attack tree;
D O I
10.1109/ICSTW50294.2020.00019
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Modern connected cars are exposed to various cybersecurity threats due to the sophisticated computing and connectivity technologies they host for providing enhanced user experience for their occupants by offering numerous innovative applications. While prior studies exist that explore cybersecurity challenges, tools and techniques for automotive systems, over-the-air (OTA) software updates for automobiles can be exploited by the attackers to compromise vehicle security and safety has not been covered extensively. This paper presents our Model-Based Security Testing (MBST) approach, designed for cybersecurity evaluation of the OTA update system for automobiles, which has an integrated testbed and a software tool that is capable of automatically generating and executing test cases by using attack trees as an input. Integrating threat modelling in the testing provides several benefits, including clear and systematic identification of different threats. Automation of the test-case generation and execution has the obvious benefits of saving time and manual effort, as manual test-case generation is both a time-consuming and error-prone process (especially, when the testing involves several test-cases). A simple simulated attack is used to demonstrate the validity and effectiveness of our testing approach. To the best of our knowledge, there is no prior research that uses a testing approach similar to our approach for automotive OTA security evaluation.
引用
收藏
页码:6 / 13
页数:8
相关论文
共 50 条
  • [21] Cluster-Based Radio Channel Emulation for Over-the-Air Testing of Automotive Wireless Systems
    Berlt, Philipp
    Wollenschlager, Frank
    Bornkessel, Christian
    Hein, Matthias A.
    [J]. 2017 11TH EUROPEAN CONFERENCE ON ANTENNAS AND PROPAGATION (EUCAP), 2017,
  • [22] Automatized Solution for Over-the-Air (OTA) Testing and Validation of Automotive Radar Sensors
    Junio Rocha, Carlos
    Ribeiro, Renato
    Miguel Cruz, Pedro
    Viana, Paula
    [J]. PROCEEDINGS OF THE 2019 9TH IEEE-APS TOPICAL CONFERENCE ON ANTENNAS AND PROPAGATION IN WIRELESS COMMUNICATIONS (IEEE APWC' 19), 2019, : 370 - 374
  • [23] System architecture for installed-performance testing of automotive radars over-the-air
    Gowdu, Sreehari Buddappagari Jayapal
    Asghar, Muhammad Ehtisham
    Stephan, Ralf
    Hein, Matthias A.
    Nagel, Johannes
    Baumgaertner, Florian
    [J]. 2018 IEEE MTT-S INTERNATIONAL CONFERENCE ON MICROWAVES FOR INTELLIGENT MOBILITY (ICMIM), 2018, : 86 - 89
  • [24] Model-based testing of automotive electronics
    Lamberg, Klaus
    [J]. 2006 DESIGN AUTOMATION AND TEST IN EUROPE, VOLS 1-3, PROCEEDINGS, 2006, : 89 - 89
  • [25] Model-Based Security Testing
    Schieferdecker, Ina
    Grossmann, Juergen
    Schneider, Martin
    [J]. ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2012, (80): : 1 - 12
  • [26] An Approach of Scenario-Based Threat Analysis and Risk Assessment Over-the-Air updates for an Autonomous Vehicle
    Khatun, Marzana
    Glass, Michael
    Jung, Rolf
    [J]. 2021 7TH INTERNATIONAL CONFERENCE ON AUTOMATION, ROBOTICS AND APPLICATIONS (ICARA 2021), 2021, : 122 - 127
  • [27] Secure over-The-Air Firmware Updates for Sensor Networks
    Kerliu, Kevin
    Ross, Alexandra
    Tao, Gong
    Yun, Zelin
    Shi, Zhijie
    Han, Song
    Zhou, Shengli
    [J]. 2019 IEEE 16TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS WORKSHOPS (MASSW 2019), 2019, : 97 - 100
  • [28] Edge-Assisted Over-the-Air Software Updates
    Bhattacharjee, Arpan
    Mahmood, Hamza
    Lu, Sidi
    Ammar, Nejib
    Ganlath, Akila
    Shi, Weisong
    [J]. 2023 IEEE 9TH INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING, CIC, 2023, : 18 - 27
  • [29] A model-based approach to the security testing of network protocol implementations
    Allen, William H.
    Dou, Chin
    Marin, Gerald A.
    [J]. 31ST IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS, PROCEEDINGS, 2006, : 1008 - +
  • [30] Vulnerability Model-based Web Applications Security Testing Approach
    He Cheng
    Liu Yanfei
    [J]. ADVANCES IN MECHATRONICS AND CONTROL ENGINEERING III, 2014, 678 : 468 - 472