Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles

被引:9
|
作者
Lee, Chee Wei [1 ]
Madnick, Stuart [2 ,3 ]
机构
[1] MIT, Dept Engn Syst, Cambridge, MA 02139 USA
[2] MIT, Informat Technol Grp, Sloan Sch Management, Sch Engn, Cambridge, MA 02139 USA
[3] MIT, Inst Data Syst & Soc, Sch Engn, Cambridge, MA 02139 USA
关键词
cybersecurity; cybersafety; autonomous vehicles; risk analysis; Mobility-as-a-Service; Internet of Vehicles; STPA-Sec; system theoretic process analysis; cybersecurity hazards analysis; HAZARD ANALYSIS; SYSTEMS; SECURITY; SAFETY;
D O I
10.3390/electronics10101220
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Urban mobility is in the midst of a revolution, driven by the convergence of technologies such as artificial intelligence, on-demand ride services, and Internet-connected and self-driving vehicles. Technological advancements often lead to new hazards. Coupled with the increased levels of automation and connectivity in the new generation of autonomous vehicles, cybersecurity is emerging as a key threat affecting these vehicles. Traditional hazard analysis methods treat safety and security in isolation and are limited in their ability to account for interactions among organizational, sociotechnical, human, and technical components. In response to these challenges, the cybersafety method, based on System Theoretic Process Analysis (STPA and STPA-Sec), was developed to meet the growing need to holistically analyze complex sociotechnical systems. We applied cybersafety to coanalyze safety and security hazards, as well as identify mitigation requirements. The results were compared with another promising method known as Combined Harm Analysis of Safety and Security for Information Systems (CHASSIS). Both methods were applied to the Mobility-as-a-Service (MaaS) and Internet of Vehicles (IoV) use cases, focusing on over-the-air software updates feature. Overall, cybersafety identified additional hazards and more effective requirements compared to CHASSIS. In particular, cybersafety demonstrated the ability to identify hazards due to unsafe/unsecure interactions among sociotechnical components. This research also suggested using CHASSIS methods for information lifecycle analysis to complement and generate additional considerations for cybersafety. Finally, results from both methods were backtested against a past cyber hack on a vehicular system, and we found that recommendations from cybersafety were likely to mitigate the risks of the incident.
引用
收藏
页数:22
相关论文
共 31 条
  • [1] A Survey of Artificial Intelligence-Related Cybersecurity Risks and Countermeasures in Mobility-as-a-Service
    Chu, Kai-Fung
    Yuan, Haiyue
    Yuan, Jinsheng
    Guo, Weisi
    Balta-Ozkan, Nazmiye
    Li, Shujun
    [J]. IEEE INTELLIGENT TRANSPORTATION SYSTEMS MAGAZINE, 2024, : 37 - 55
  • [2] QUALITY ASSESSMENT METHOD FOR MOBILITY-AS-A-SERVICE BASED ON AUTONOMOUS VEHICLES
    He, Yinying
    Csiszar, Csaba
    [J]. INTERNATIONAL CONFERENCE ON TRAFFIC AND TRANSPORT ENGINEERING (ICTTE 2018), 2018, : 901 - 910
  • [3] Trip planning for a mobility-as-a-service system: Integrating metros and shared autonomous vehicles
    Yang, Shuang
    Wu, Jianjun
    Sun, Huijun
    Qu, Yunchao
    [J]. TRANSPORTATION RESEARCH PART E-LOGISTICS AND TRANSPORTATION REVIEW, 2023, 176
  • [4] Designing mobility-as-a-service business models using morphological analysis
    Krauss, Konstantin
    Moll, Cornelius
    Koehler, Jonathan
    Axhausen, Kay W.
    [J]. RESEARCH IN TRANSPORTATION BUSINESS AND MANAGEMENT, 2022, 45
  • [5] Assessing the willingness to pay for Mobility-as-A-Service: An Agent-Based approach
    Cisterna, Carolina
    Bigi, Federico
    Nakao, Haruko
    Viti, Francesco
    [J]. CASE STUDIES ON TRANSPORT POLICY, 2024, 17
  • [6] Cybersecurity threats mitigation in Internet of Vehicles communication system using reliable clustering and routing
    Kadam, Megha, V
    Mahajan, Hemant B.
    Uke, Nilesh J.
    Futane, Pravin R.
    [J]. MICROPROCESSORS AND MICROSYSTEMS, 2023, 102
  • [7] Resilience analysis and design for mobility-as-a-service based on enterprise architecture modeling
    Zhou, Zhengshu
    Matsubara, Yutaka
    Takada, Hiroaki
    [J]. RELIABILITY ENGINEERING & SYSTEM SAFETY, 2023, 229
  • [8] Exploring tourist preference for Mobility-as-a-Service (MaaS) - A latent class choice approach
    Chen, Ching-Fu
    Fu, Chiang
    Chen, Yu-Chun
    [J]. TRANSPORTATION RESEARCH PART A-POLICY AND PRACTICE, 2023, 174
  • [9] Adopting Mobility-as-a-Service: An empirical analysis of end-users' experiences
    Smith, Goran
    Sochor, Jana
    Karlsson, I. C. MariAnne
    [J]. TRAVEL BEHAVIOUR AND SOCIETY, 2022, 28 : 237 - 248
  • [10] Mobility-as-a-Service (MaaS) Testbed as an Integrated Approach for New Mobility - A Living Lab Case Study in Singapore
    Jin, Zhanhe Ryan
    Qiu, Anna Zhi
    [J]. HCI IN MOBILITY, TRANSPORT, AND AUTOMOTIVE SYSTEMS, 2019, 11596 : 441 - 458