车载网络网络安全测试研究

Feng Luo, Xuan Zhang, Shuo Hou
{"title":"车载网络网络安全测试研究","authors":"Feng Luo, Xuan Zhang, Shuo Hou","doi":"10.1109/ICITES53477.2021.9637070","DOIUrl":null,"url":null,"abstract":"The development of technologies such as Information Communication Technology (ICT), Internet of Vehicles (IoVs), and industrial intelligence has made automotive cybersecurity issues more prominent. Cybersecurity issues have gradually attracted widespread attention in the field of Intelligent Connected Vehicles (ICV). Cybersecurity testing is an effective means to ensure the cybersecurity of Cyber-Physical Systems (CPS). Fuzzing and penetration testing are both important methods of security testing. In SAE J3061 and the impending ISO/SAE 21434, it is clearly mentioned that fuzzing and penetration testing technologies should be applied in the development of automotive cybersecurity activities, but no specific testing details are involved. The WP.29 regulations also require security tests to verify the effectiveness of security measures when conducting type approval with regard to cybersecurity. There is neither a standardized method for how to conduct automotive cybersecurity testing, nor specific testing tools. In this paper, a brief overview of the applied security testing methods in the automotive domain is provided first. Then, we present a cybersecurity testing method, which extends the Penetration Testing Execution Standard (PTES) from the perspective of testing processes. Besides, we also design and develop a security testing tool for the in-vehicle network to assist security analysis. Finally, taking Controller Area Network with Flexible Data Rate (CAN FD) as an example, the proposed method is applied to the designed testbed.","PeriodicalId":370828,"journal":{"name":"2021 International Conference on Intelligent Technology and Embedded Systems (ICITES)","volume":"83 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Research on Cybersecurity Testing for In-vehicle Network\",\"authors\":\"Feng Luo, Xuan Zhang, Shuo Hou\",\"doi\":\"10.1109/ICITES53477.2021.9637070\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The development of technologies such as Information Communication Technology (ICT), Internet of Vehicles (IoVs), and industrial intelligence has made automotive cybersecurity issues more prominent. Cybersecurity issues have gradually attracted widespread attention in the field of Intelligent Connected Vehicles (ICV). Cybersecurity testing is an effective means to ensure the cybersecurity of Cyber-Physical Systems (CPS). Fuzzing and penetration testing are both important methods of security testing. In SAE J3061 and the impending ISO/SAE 21434, it is clearly mentioned that fuzzing and penetration testing technologies should be applied in the development of automotive cybersecurity activities, but no specific testing details are involved. The WP.29 regulations also require security tests to verify the effectiveness of security measures when conducting type approval with regard to cybersecurity. There is neither a standardized method for how to conduct automotive cybersecurity testing, nor specific testing tools. In this paper, a brief overview of the applied security testing methods in the automotive domain is provided first. Then, we present a cybersecurity testing method, which extends the Penetration Testing Execution Standard (PTES) from the perspective of testing processes. Besides, we also design and develop a security testing tool for the in-vehicle network to assist security analysis. Finally, taking Controller Area Network with Flexible Data Rate (CAN FD) as an example, the proposed method is applied to the designed testbed.\",\"PeriodicalId\":370828,\"journal\":{\"name\":\"2021 International Conference on Intelligent Technology and Embedded Systems (ICITES)\",\"volume\":\"83 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 International Conference on Intelligent Technology and Embedded Systems (ICITES)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICITES53477.2021.9637070\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Conference on Intelligent Technology and Embedded Systems (ICITES)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITES53477.2021.9637070","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

信息通信技术(ICT)、车联网(IoVs)、工业智能等技术的发展,使得汽车网络安全问题更加突出。在智能网联汽车领域,网络安全问题逐渐受到广泛关注。网络安全测试是保证网络物理系统网络安全的有效手段。模糊测试和渗透测试都是重要的安全测试方法。在SAE J3061和即将发布的ISO/SAE 21434中,明确提到在汽车网络安全活动的开发中应应用模糊测试和渗透测试技术,但没有涉及具体的测试细节。WP.29条例还要求在进行关于网络安全的型式批准时进行安全测试,以验证安全措施的有效性。对于如何进行汽车网络安全测试,既没有标准化的方法,也没有特定的测试工具。本文首先对汽车领域应用的安全测试方法进行了简要概述。然后,从测试过程的角度对渗透测试执行标准(PTES)进行了扩展,提出了一种网络安全测试方法。此外,我们还设计和开发了车载网络的安全测试工具,以辅助安全分析。最后,以灵活数据速率控制器局域网(CAN FD)为例,将该方法应用于所设计的试验台。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Research on Cybersecurity Testing for In-vehicle Network
The development of technologies such as Information Communication Technology (ICT), Internet of Vehicles (IoVs), and industrial intelligence has made automotive cybersecurity issues more prominent. Cybersecurity issues have gradually attracted widespread attention in the field of Intelligent Connected Vehicles (ICV). Cybersecurity testing is an effective means to ensure the cybersecurity of Cyber-Physical Systems (CPS). Fuzzing and penetration testing are both important methods of security testing. In SAE J3061 and the impending ISO/SAE 21434, it is clearly mentioned that fuzzing and penetration testing technologies should be applied in the development of automotive cybersecurity activities, but no specific testing details are involved. The WP.29 regulations also require security tests to verify the effectiveness of security measures when conducting type approval with regard to cybersecurity. There is neither a standardized method for how to conduct automotive cybersecurity testing, nor specific testing tools. In this paper, a brief overview of the applied security testing methods in the automotive domain is provided first. Then, we present a cybersecurity testing method, which extends the Penetration Testing Execution Standard (PTES) from the perspective of testing processes. Besides, we also design and develop a security testing tool for the in-vehicle network to assist security analysis. Finally, taking Controller Area Network with Flexible Data Rate (CAN FD) as an example, the proposed method is applied to the designed testbed.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信