A simulation framework for automotive cybersecurity risk assessment

IF 4.3 3区 材料科学 Q1 ENGINEERING, ELECTRICAL & ELECTRONIC
Don Nalin Dharshana Jayaratne , Suraj Harsha Kamtam , Siraj Ahmed Shaikh , Muhamad Azfar Ramli , Qian Lu , Rakhi Manohar Mepparambath , Hoang Nga Nguyen , Abdur Rakib
{"title":"A simulation framework for automotive cybersecurity risk assessment","authors":"Don Nalin Dharshana Jayaratne ,&nbsp;Suraj Harsha Kamtam ,&nbsp;Siraj Ahmed Shaikh ,&nbsp;Muhamad Azfar Ramli ,&nbsp;Qian Lu ,&nbsp;Rakhi Manohar Mepparambath ,&nbsp;Hoang Nga Nguyen ,&nbsp;Abdur Rakib","doi":"10.1016/j.simpat.2024.103005","DOIUrl":null,"url":null,"abstract":"<div><p>Human-initiated disruptions such as cyberattacks on connected vehicles have the potential to cause cascading failures in transport systems, leading to systemic risks. ‘ISO/SAE 21434:2021 Road vehicles - Cybersecurity engineering’ is the current standard for risk management of road vehicles. However, the threat analysis and risk assessment framework given in the standard focuses on asset-level analysis and assessment. Hence, this study develops a novel simulation-based framework to perform threat analysis and risk assessment on connected vehicles from a transport network perspective. The proposed framework is developed based on the ISO/SAE 21434 threat analysis and risk assessment methodology. We demonstrate the applicability and usefulness of the framework through a remote attack via the cellular network on the in-vehicle communication bus system of a connected vehicle to show the potential impacts on the transport network. Based on the findings of our case studies, we exemplify how cyberattacks on individual system components of a connected vehicle have the potential to cause systemic failures.</p></div>","PeriodicalId":3,"journal":{"name":"ACS Applied Electronic Materials","volume":null,"pages":null},"PeriodicalIF":4.3000,"publicationDate":"2024-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S1569190X24001199/pdfft?md5=8fc9b5419afcd3b7fa0b3826ddccdaf9&pid=1-s2.0-S1569190X24001199-main.pdf","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACS Applied Electronic Materials","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1569190X24001199","RegionNum":3,"RegionCategory":"材料科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, ELECTRICAL & ELECTRONIC","Score":null,"Total":0}
引用次数: 0

Abstract

Human-initiated disruptions such as cyberattacks on connected vehicles have the potential to cause cascading failures in transport systems, leading to systemic risks. ‘ISO/SAE 21434:2021 Road vehicles - Cybersecurity engineering’ is the current standard for risk management of road vehicles. However, the threat analysis and risk assessment framework given in the standard focuses on asset-level analysis and assessment. Hence, this study develops a novel simulation-based framework to perform threat analysis and risk assessment on connected vehicles from a transport network perspective. The proposed framework is developed based on the ISO/SAE 21434 threat analysis and risk assessment methodology. We demonstrate the applicability and usefulness of the framework through a remote attack via the cellular network on the in-vehicle communication bus system of a connected vehicle to show the potential impacts on the transport network. Based on the findings of our case studies, we exemplify how cyberattacks on individual system components of a connected vehicle have the potential to cause systemic failures.

汽车网络安全风险评估模拟框架
由人为因素引发的破坏,如对联网车辆的网络攻击,有可能导致运输系统出现连锁故障,从而引发系统性风险。ISO/SAE 21434:2021 道路车辆--网络安全工程 "是道路车辆风险管理的现行标准。然而,该标准给出的威胁分析和风险评估框架侧重于资产层面的分析和评估。因此,本研究开发了一个基于模拟的新框架,从运输网络的角度对联网车辆进行威胁分析和风险评估。建议的框架是基于 ISO/SAE 21434 威胁分析和风险评估方法开发的。我们通过蜂窝网络对互联车辆的车载通信总线系统进行远程攻击,展示了该框架的适用性和实用性,从而显示出对交通网络的潜在影响。根据我们的案例研究结果,我们举例说明了对互联车辆单个系统组件的网络攻击有可能导致系统故障。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
CiteScore
7.20
自引率
4.30%
发文量
567
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信