基于模型的车辆网络安全测试

Florian Sommer, R. Kriesten, F. Kargl
{"title":"基于模型的车辆网络安全测试","authors":"Florian Sommer, R. Kriesten, F. Kargl","doi":"10.1109/CSCI54926.2021.00179","DOIUrl":null,"url":null,"abstract":"Modern vehicles consist of a large number of electronic information technology components, which communicate with each other and external components. To protect vehicles against security attacks, automotive-specific standards and regulations require an integration of security concepts and measures in vehicles. Security testing techniques, such as penetration tests, are used to verify and validate those measures. However, these methods are usually carried out manually in late phases of development. Thus, identified vulnerabilities can only be eliminated at a late stage leading to a high investment of time and resources. This paper presents a model-based security testing approach which aims to enable security tests early on in the vehicle development process in an automated way. This allows vulnerabilities to be identified and eliminated at an early stage during development. Therefore, we show our concept to create a security model based on a vehicle network. This model can be used to automatically derive attack paths for security testing. We further illustrate our approach by applying it to a real-world vehicle network.","PeriodicalId":206881,"journal":{"name":"2021 International Conference on Computational Science and Computational Intelligence (CSCI)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Model-Based Security Testing of Vehicle Networks\",\"authors\":\"Florian Sommer, R. Kriesten, F. Kargl\",\"doi\":\"10.1109/CSCI54926.2021.00179\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Modern vehicles consist of a large number of electronic information technology components, which communicate with each other and external components. To protect vehicles against security attacks, automotive-specific standards and regulations require an integration of security concepts and measures in vehicles. Security testing techniques, such as penetration tests, are used to verify and validate those measures. However, these methods are usually carried out manually in late phases of development. Thus, identified vulnerabilities can only be eliminated at a late stage leading to a high investment of time and resources. This paper presents a model-based security testing approach which aims to enable security tests early on in the vehicle development process in an automated way. This allows vulnerabilities to be identified and eliminated at an early stage during development. Therefore, we show our concept to create a security model based on a vehicle network. This model can be used to automatically derive attack paths for security testing. We further illustrate our approach by applying it to a real-world vehicle network.\",\"PeriodicalId\":206881,\"journal\":{\"name\":\"2021 International Conference on Computational Science and Computational Intelligence (CSCI)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-12-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 International Conference on Computational Science and Computational Intelligence (CSCI)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CSCI54926.2021.00179\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Conference on Computational Science and Computational Intelligence (CSCI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSCI54926.2021.00179","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

现代车辆由大量的电子信息技术部件组成,这些部件之间相互通信,并与外部部件通信。为了保护车辆免受安全攻击,汽车专用标准和法规要求在车辆中集成安全概念和措施。安全性测试技术,例如渗透测试,用于验证和确认这些度量。然而,这些方法通常是在开发的后期手工执行的。因此,确定的漏洞只能在后期阶段消除,这会导致大量的时间和资源投资。本文提出了一种基于模型的安全测试方法,旨在以自动化的方式在车辆开发过程的早期进行安全测试。这允许在开发的早期阶段识别和消除漏洞。因此,我们展示了基于车辆网络创建安全模型的概念。该模型可用于自动导出攻击路径,用于安全测试。我们通过将其应用于现实世界的车辆网络来进一步说明我们的方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Model-Based Security Testing of Vehicle Networks
Modern vehicles consist of a large number of electronic information technology components, which communicate with each other and external components. To protect vehicles against security attacks, automotive-specific standards and regulations require an integration of security concepts and measures in vehicles. Security testing techniques, such as penetration tests, are used to verify and validate those measures. However, these methods are usually carried out manually in late phases of development. Thus, identified vulnerabilities can only be eliminated at a late stage leading to a high investment of time and resources. This paper presents a model-based security testing approach which aims to enable security tests early on in the vehicle development process in an automated way. This allows vulnerabilities to be identified and eliminated at an early stage during development. Therefore, we show our concept to create a security model based on a vehicle network. This model can be used to automatically derive attack paths for security testing. We further illustrate our approach by applying it to a real-world vehicle network.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信