Enabling Efficient Common Criteria Security Evaluation for Connected Vehicles

A. Stamou, P. Pantazopoulos, S. Haddad, A. Amditis
{"title":"Enabling Efficient Common Criteria Security Evaluation for Connected Vehicles","authors":"A. Stamou, P. Pantazopoulos, S. Haddad, A. Amditis","doi":"10.1109/CSR51186.2021.9527905","DOIUrl":null,"url":null,"abstract":"Cyber-security assurance evaluation seeks to gain evidence that the relevant requirements of an IT system are met. Towards that end, carefully-designed evaluation processes of the considered systems are needed. The only so-far validated approach, the Common Criteria (CC) standard, relies on exhaustive evaluation tasks to provide (up to) the highest possible assurance at the expense of increased costs. When the evaluation involves the connected vehicles paradigm which integrates a mosaic of third-party modules and interfaces, applying CC becomes problematic; the cost in resources and time further increases while relevant automated tools or document templates, are scarce.This paper introduces the AFT (Assurance Framework Toolkit) which is a platform-independent online software toolkit that enables efficient CC-based cyber-security evaluations on products of the automotive cyber-physical ecosystem. A set of relevant CC-specific security assurance needs are explained and the way that the AFT software-design and functionality covers them, is presented. Subsequently, the development of the toolkit (with publicly available source-code) as well as its capability to meet the evaluation of automotive needs, are detailed. Finally, an empirical study estimates the expected AFT gains against typical CC unassisted evaluations. The proposed toolkit (along with its extendibility feature) practically tackles the cost-limitations of standardized security evaluations filling an important technology gap towards safer connected driving.","PeriodicalId":253300,"journal":{"name":"2021 IEEE International Conference on Cyber Security and Resilience (CSR)","volume":"5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-07-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Conference on Cyber Security and Resilience (CSR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSR51186.2021.9527905","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Cyber-security assurance evaluation seeks to gain evidence that the relevant requirements of an IT system are met. Towards that end, carefully-designed evaluation processes of the considered systems are needed. The only so-far validated approach, the Common Criteria (CC) standard, relies on exhaustive evaluation tasks to provide (up to) the highest possible assurance at the expense of increased costs. When the evaluation involves the connected vehicles paradigm which integrates a mosaic of third-party modules and interfaces, applying CC becomes problematic; the cost in resources and time further increases while relevant automated tools or document templates, are scarce.This paper introduces the AFT (Assurance Framework Toolkit) which is a platform-independent online software toolkit that enables efficient CC-based cyber-security evaluations on products of the automotive cyber-physical ecosystem. A set of relevant CC-specific security assurance needs are explained and the way that the AFT software-design and functionality covers them, is presented. Subsequently, the development of the toolkit (with publicly available source-code) as well as its capability to meet the evaluation of automotive needs, are detailed. Finally, an empirical study estimates the expected AFT gains against typical CC unassisted evaluations. The proposed toolkit (along with its extendibility feature) practically tackles the cost-limitations of standardized security evaluations filling an important technology gap towards safer connected driving.
为互联汽车提供高效的通用标准安全评估
网络安全保障评估旨在获得证据,证明IT系统的相关要求得到满足。为此目的,需要对所审议的系统进行精心设计的评价过程。迄今为止唯一经过验证的方法是Common Criteria (CC)标准,它依赖于详尽的评估任务,以增加的成本为代价提供(至多)最高可能的保证。当评估涉及到集成了大量第三方模块和接口的互联汽车范式时,应用CC就会出现问题;资源和时间成本进一步增加,而相关的自动化工具或文档模板却很少。本文介绍了AFT(保证框架工具包),这是一个独立于平台的在线软件工具包,可以对汽车网络物理生态系统的产品进行有效的基于cc的网络安全评估。解释了一组相关的特定于cc的安全保证需求,并介绍了AFT软件设计和功能涵盖这些需求的方式。随后,详细介绍了该工具包的开发(具有公开可用的源代码)及其满足汽车需求评估的能力。最后,一项实证研究估计了典型的CC独立评估的预期AFT收益。提出的工具包(以及其可扩展性)实际上解决了标准化安全评估的成本限制,填补了迈向更安全的联网驾驶的重要技术空白。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信