Author:
Wang Yunpeng,Wang Yinghui,Qin Hongmao,Ji Haojie,Zhang Yanan,Wang Jian
Abstract
AbstractThe increasingly intelligent and connected vehicles have brought many unprecedented automotive cybersecurity threats, which may cause privacy breaches, personal injuries, and even national security issues. Before providing effective security solutions, a comprehensive risk assessment of the automotive cybersecurity must be carried out. A systematic cybersecurity risk assessment framework for automobiles is proposed in this study. It consists of an assessment process and systematic assessment methods considering the changes of threat environment, evaluation target, and available information in vehicle lifecycle. In the process of risk identification and risk analysis, the impact level and attack feasibility level are assessed based on the STRIDE model and attack tree method. An automotive cybersecurity risk matrix using a global rating algorithm is then constructed to create a quantitative risk metric. Finally, the applicability and feasibility of the proposed risk assessment framework are demonstrated through a use case, and the results prove that the proposed framework is effective. The proposed assessment framework helps to systematically derive automotive cybersecurity requirements.
Funder
National Key Research and Development Program of China
Publisher
Springer Science and Business Media LLC
Reference37 articles.
1. Steger, M., Karner, M., Hillebrand, J., et al.: A security metric for structured security analysis of cyber-physical systems supporting SAE J3061. Modelling, Analysis, and Control of Complex CPS (CPS Data), 2nd International Workshop, IEEE. (2016)
2. Xie, G., Zeng, G., Li, Z., et al.: Adaptive dynamic scheduling on multi-functional mixed-criticality automotive cyber-physical systems. IEEE Trans. Veh. Technol. 66(8), 6676–6692 (2017)
3. Xie, G., Peng, H., Li, Z., et al.: Reliability enhancement towards functional safety goal assurance in energy-aware automotive cyber-physical systems. IEEE Trans. Ind. Informat. 14(12), 5447–5462 (2018)
4. Xie, G., Peng, H., Huang, J., et al.: Energy-efficient functional safety design methodology using ASIL decomposition for automotive cyber-physical systems. IEEE Trans. Reliab. 99, 1–23 (2019)
5. Schmittner, C., Ma, Z., Schoitsch, E., et al.: A case study of FMVEA and chassis as safety and security co-analysis method for automotive cyber-physical systems. Proc. 1st ACM Workshop Cyber-Phys. Syst. Secur. 69–80 (2015)
Cited by
27 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献