Balancing Digital Forensic Investigation with Cybersecurity for Heavy Vehicle Traffic Crashes

Author:

Rayno Mars1,Daily Jeremy2

Affiliation:

1. Colorado State University Fort Collins CO 80525

2. Colorado State University Fort Collins CO

Abstract

AbstractAfter a traffic crash event, traffic crash investigators collect evidence and data to assist in reconstructing the events to determine crash causation. Some of the data collected in a crash investigation is in the form of digital data from event data recorders built into the electronic control units in the vehicles. Occasionally, traffic crashes are severe enough to destroy the typical network‐based communications protocols to extract the digital forensic data. In these cases, more invasive techniques of gathering forensic data through in‐circuit programming ports or direct reading of data bearing memory chips is needed. While a digital forensic investigation satisfies a virtuous need for society in determining the truth of a traffic crash, the same techniques can be applied by nefarious actors interested in stealing intellectual property (IP) from the same data bearing chips. The exposure of the executable binary containing the IP of the manufacturer has prompted auto makers and suppliers to eliminate access to these sources of digital forensic data by disabling the Joint Task Action Group (JTAG) instrumentation and obfuscating or encrypting the binary data. Herein lies the purpose of this paper, which is to take a systems engineering approach to balance the needs and requirements for a manufacturer to provide sufficient forensic artifacts in the case of an investigation while improving their cybersecurity posture and limiting their exposure to the theft of intellectual property or cyberat‐tack.An activity diagram is presented to show a system model for responding to and investigating a crash event. These activities inform the needs of an improved event data recorder technologies that contain information necessary to reconstruct the crash. Some proposed top level system requirements are presented with a discussion of how they satisfy the needs of the manufacturer and the crash investigator. Specific requirements of recorded data give a notion of a minimal set of recorded data to help investigators. These requirements will improve both the availability and adequacy of forensic data needed for crash event reconstruction. In addition, a separate requirement governing the preservation of Original Equipment Manufacturer (OEM) proprietary software is made, such that their intellectual property is protected to encourage the requirement compliance. Finally, a discussion of how the proposed requirements help determine if a crash event was a result of a cyber‐attack demonstrates the important nature of addressing these needs in future systems.

Publisher

Wiley

Subject

Automotive Engineering

Reference21 articles.

1. L. (NHTSA) Reish “Traffic Safety Facts 2020: A Compilation of Motor Vehicle Crash Data”. [Online]. Available:https://crashstats.nhtsa.dot.gov/Api/Public/ViewPublication/813375[Accessed: 13-Dec-2022].

2. On the Digital Forensics of Heavy Truck Electronic Control Modules

3. D.Sladovic D.Topolcic K.Hausknecht andG.Sirovatka “Investigating modern cars ”2019 42nd International Convention on Information and Communication Technology Electronics and Microelectronics (MIPRO) 2019.

4. “Bosch Diagnostics ” Bosch Diagnostics |. [Online]. Available:https://cdr.boschdiagnostics.com/cdr/. [Accessed: 13-Dec-2022].

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3