A Model-Based Security Testing Approach for Automotive Over-The-Air Updates

被引:9
|
作者
Mahmood, Shahid [1 ]
Fouillade, Alexy [2 ]
Hoang Nga Nguyen [1 ]
Shaikh, Siraj A. [1 ]
机构
[1] Coventry Univ, Inst Future Transport & Cities, Syst Secur Grp, Coventry, W Midlands, England
[2] Grande Ecole Ingenieurs Generalistes Angers, Ecole Super Elect Ouest, Angers, France
关键词
over-the-air updates; OTA; automotive; cybersecurity; testing; testbed; testing approach; model-based security testing; attack tree;
D O I
10.1109/ICSTW50294.2020.00019
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Modern connected cars are exposed to various cybersecurity threats due to the sophisticated computing and connectivity technologies they host for providing enhanced user experience for their occupants by offering numerous innovative applications. While prior studies exist that explore cybersecurity challenges, tools and techniques for automotive systems, over-the-air (OTA) software updates for automobiles can be exploited by the attackers to compromise vehicle security and safety has not been covered extensively. This paper presents our Model-Based Security Testing (MBST) approach, designed for cybersecurity evaluation of the OTA update system for automobiles, which has an integrated testbed and a software tool that is capable of automatically generating and executing test cases by using attack trees as an input. Integrating threat modelling in the testing provides several benefits, including clear and systematic identification of different threats. Automation of the test-case generation and execution has the obvious benefits of saving time and manual effort, as manual test-case generation is both a time-consuming and error-prone process (especially, when the testing involves several test-cases). A simple simulated attack is used to demonstrate the validity and effectiveness of our testing approach. To the best of our knowledge, there is no prior research that uses a testing approach similar to our approach for automotive OTA security evaluation.
引用
收藏
页码:6 / 13
页数:8
相关论文
共 50 条
  • [41] Poster: Edge-Assisted Over-the-Air Software Updates
    Bhattacharjee, Arpan
    Mahmood, Hamza
    Lu, Sidi
    Ammar, Nejib
    Ganlath, Akila
    Shi, Weisong
    [J]. 2023 IEEE/ACM SYMPOSIUM ON EDGE COMPUTING, SEC 2023, 2023, : 285 - 286
  • [42] On Over-the-Air Testing for Devices With Directional Antennas
    Xin, Lijian
    Li, Yong
    Zhe, Shitong
    Zhang, Xiang
    [J]. IEEE ACCESS, 2020, 8 : 121821 - 121832
  • [43] MIMO Over-The-Air Research, Development, and Testing
    Rumney, Moray
    Pirkl, Ryan
    Landmann, Markus Herrmann
    Sanchez-Hernandez, David A.
    [J]. INTERNATIONAL JOURNAL OF ANTENNAS AND PROPAGATION, 2012, 2012
  • [44] Systematic Model-Based Testing of Embedded Automotive Software
    Conrad, Mirko
    Fey, Ines
    Sadeghipour, Sadegh
    [J]. ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2005, 111 : 13 - 26
  • [45] A Model-Based Testing Framework for Automotive Embedded Systems
    Marinescu, Raluca
    Saadatmand, Mehrdad
    Bucaioni, Alessio
    Seceleanu, Cristina
    Pettersson, Paul
    [J]. 2014 40TH EUROMICRO CONFERENCE SERIES ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS (SEAA 2014), 2014, : 38 - 47
  • [46] Improving Model-Based Testing in Automotive Software Engineering
    Kriebel, Stefan
    Markthaler, Matthias
    Salman, Karin Samira
    Greifenberg, Timo
    Hillemacher, Steffen
    Rumpe, Bernhard
    Schulze, Christoph
    Wortmann, Andreas
    Orth, Philipp
    Richenhagen, Johannes
    [J]. 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - SOFTWARE ENGINEERING IN PRACTICE TRACK (ICSE-SEIP 2018), 2018, : 172 - 180
  • [47] A Formal Methodology Applied to Secure Over-the-Air Automotive Applications
    Pedroza, Gabriel
    Idrees, Muhammad Sabir
    Apvrille, Ludovic
    Roudier, Yves
    [J]. 2011 IEEE VEHICULAR TECHNOLOGY CONFERENCE (VTC FALL), 2011,
  • [48] Model-Based Security Testing of Vehicle Networks
    Sommer, Florian
    Kriesten, Reiner
    Kargl, Frank
    [J]. 2021 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2021), 2021, : 685 - 691
  • [49] Over-the-Air Software Updates in the Internet of Things: An Overview of Key Principles
    Bauwens, Jan
    Ruckebusch, Peter
    Giannoulis, Spilios
    Moerman, Ingrid
    De Poorter, Eli
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2020, 58 (02) : 35 - 41
  • [50] eUF: A framework for detecting over-the-air malicious updates in autonomous vehicles
    Qureshi, Anam
    Marvi, Murk
    Shamsi, Jawwad Ahmed
    Aijaz, Adnan
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2022, 34 (08) : 5456 - 5467