Incident Management Process Model for Automotive CyberSafety Systems Using the Business Process Model and Notation

P. Piątek
{"title":"Incident Management Process Model for Automotive CyberSafety Systems Using the Business Process Model and Notation","authors":"P. Piątek","doi":"10.1109/MMAR55195.2022.9874288","DOIUrl":null,"url":null,"abstract":"The rise of vehicle connectivity and autonomy is predicted to amplify the impact of emerging cybersecurity risks during the entire product life cycle in the automotive sector. To address all aspects of vehicle safety, including functional safety, safety of intended functionality (SOTIF), and cybersecurity, efforts must be made to collaborate across these areas during the maintenance period for incidents handling as well. Currently, much emphasis is being placed on the Incident Monitoring Process, which focuses on cybersecurity concerns. To round out the picture, safety incidents should be also considered. As a result, the research intends to examine SOTIF -related incidents in addition to cybersecurity issues. Following that, the paper gives a full model of the CyberSafety Incident Monitoring Process, which includes all industry requirements for cybersecurity monitoring as well as SOTIF-related concerns. The paper presents the proposal of using Business Process Model and Notation (BPMN) to create a complete process model. The probable practical implementation of the CyberSafety Incident Monitoring Process Model is evaluated in the last part of the study based on the phantom attack scenario to test the idea with a real-world example. As a consequence, the strategy is accurate and fits the industry goal of merging safety and cybersecurity during the maintenance phase, which reduces the time and effort necessary for faster response to various vehicle risks when time is crucial. In future research, more emphasis should be made on combining numerous incident fields, which may have an impact on vehicle safety.","PeriodicalId":169528,"journal":{"name":"2022 26th International Conference on Methods and Models in Automation and Robotics (MMAR)","volume":"208 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-08-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 26th International Conference on Methods and Models in Automation and Robotics (MMAR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MMAR55195.2022.9874288","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

The rise of vehicle connectivity and autonomy is predicted to amplify the impact of emerging cybersecurity risks during the entire product life cycle in the automotive sector. To address all aspects of vehicle safety, including functional safety, safety of intended functionality (SOTIF), and cybersecurity, efforts must be made to collaborate across these areas during the maintenance period for incidents handling as well. Currently, much emphasis is being placed on the Incident Monitoring Process, which focuses on cybersecurity concerns. To round out the picture, safety incidents should be also considered. As a result, the research intends to examine SOTIF -related incidents in addition to cybersecurity issues. Following that, the paper gives a full model of the CyberSafety Incident Monitoring Process, which includes all industry requirements for cybersecurity monitoring as well as SOTIF-related concerns. The paper presents the proposal of using Business Process Model and Notation (BPMN) to create a complete process model. The probable practical implementation of the CyberSafety Incident Monitoring Process Model is evaluated in the last part of the study based on the phantom attack scenario to test the idea with a real-world example. As a consequence, the strategy is accurate and fits the industry goal of merging safety and cybersecurity during the maintenance phase, which reduces the time and effort necessary for faster response to various vehicle risks when time is crucial. In future research, more emphasis should be made on combining numerous incident fields, which may have an impact on vehicle safety.
基于业务流程模型和符号的汽车网络安全系统事件管理流程模型
预计汽车连接和自动驾驶的兴起将在汽车行业的整个产品生命周期中放大新兴网络安全风险的影响。为了解决车辆安全的各个方面,包括功能安全、预期功能安全(SOTIF)和网络安全,在维护期间必须努力在这些领域进行协作,以处理事故。目前,重点放在事件监控过程上,该过程侧重于网络安全问题。为了使情况更全面,还应该考虑安全事件。因此,除了网络安全问题外,本研究还打算研究SOTIF相关事件。随后,本文给出了一个完整的网络安全事件监测过程模型,其中包括所有行业对网络安全监测的要求以及与sotif相关的问题。本文提出了使用业务流程模型和符号(BPMN)来创建完整流程模型的建议。在研究的最后一部分,基于虚拟攻击场景评估了网络安全事件监控过程模型的可能实际实施,以用现实世界的例子测试该想法。因此,该策略是准确的,符合行业在维护阶段将安全和网络安全相结合的目标,从而减少了在时间至关重要的情况下更快响应各种车辆风险所需的时间和精力。在未来的研究中,应该更加重视将多个可能对车辆安全产生影响的事件领域结合起来。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信