基于 ISO/SAE 21434 的重型车辆网络威胁易感性评估

IF 5.3 Q1 ENGINEERING, ELECTRICAL & ELECTRONIC
Narges Rahimi;Beth-Anne Schuelke-Leech;Mitra Mirhassani
{"title":"基于 ISO/SAE 21434 的重型车辆网络威胁易感性评估","authors":"Narges Rahimi;Beth-Anne Schuelke-Leech;Mitra Mirhassani","doi":"10.1109/OJVT.2025.3550307","DOIUrl":null,"url":null,"abstract":"TARA, which stands for Threat Analysis and Risk Assessment, serves as the foundational stage of cybersecurity implementation, particularly in the context of vehicular systems. While various considerations and risk assessment frameworks have been discussed in recent years, there is a notable lack of TARA models specifically designed for heavy-duty (HD) vehicles. The security considerations and vulnerabilities in HD vehicles differ significantly from those in light-duty (LD) vehicles, leading to different security impacts and varying attack feasibility. This makes existing models inadequate for accurately assessing risks in the context of HD vehicles. This study introduces a novel risk assessment model tailored for HD vehicles, addressing gaps in existing TARA frameworks such as EVITA, HEAVENS, and ISO/SAE 21434. The key contribution of this work lies in the customization of impact and feasibility metrics within the ISO/SAE framework to better account for the unique security challenges posed by HD vehicles. Unlike prior models, this approach adapts the impact criteria to reflect the diverse range of security concerns specific to HD vehicles, which have been inadequately addressed in existing frameworks. Additionally, through a comprehensive analysis of threat vectors and vehicle interfaces, the model refines feasibility criteria, ensuring a more accurate and context-aware assessment of security risks. By adopting these enhancements, the proposed model offers more precise risk assessments that align with HD vehicle considerations, helping to prioritize threats and make optimal decisions regarding risk treatment.","PeriodicalId":34270,"journal":{"name":"IEEE Open Journal of Vehicular Technology","volume":"6 ","pages":"969-990"},"PeriodicalIF":5.3000,"publicationDate":"2025-03-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10921673","citationCount":"0","resultStr":"{\"title\":\"Cyber Threat Susceptibility Assessment for Heavy-Duty Vehicles Based on ISO/SAE 21434\",\"authors\":\"Narges Rahimi;Beth-Anne Schuelke-Leech;Mitra Mirhassani\",\"doi\":\"10.1109/OJVT.2025.3550307\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"TARA, which stands for Threat Analysis and Risk Assessment, serves as the foundational stage of cybersecurity implementation, particularly in the context of vehicular systems. While various considerations and risk assessment frameworks have been discussed in recent years, there is a notable lack of TARA models specifically designed for heavy-duty (HD) vehicles. The security considerations and vulnerabilities in HD vehicles differ significantly from those in light-duty (LD) vehicles, leading to different security impacts and varying attack feasibility. This makes existing models inadequate for accurately assessing risks in the context of HD vehicles. This study introduces a novel risk assessment model tailored for HD vehicles, addressing gaps in existing TARA frameworks such as EVITA, HEAVENS, and ISO/SAE 21434. The key contribution of this work lies in the customization of impact and feasibility metrics within the ISO/SAE framework to better account for the unique security challenges posed by HD vehicles. Unlike prior models, this approach adapts the impact criteria to reflect the diverse range of security concerns specific to HD vehicles, which have been inadequately addressed in existing frameworks. Additionally, through a comprehensive analysis of threat vectors and vehicle interfaces, the model refines feasibility criteria, ensuring a more accurate and context-aware assessment of security risks. By adopting these enhancements, the proposed model offers more precise risk assessments that align with HD vehicle considerations, helping to prioritize threats and make optimal decisions regarding risk treatment.\",\"PeriodicalId\":34270,\"journal\":{\"name\":\"IEEE Open Journal of Vehicular Technology\",\"volume\":\"6 \",\"pages\":\"969-990\"},\"PeriodicalIF\":5.3000,\"publicationDate\":\"2025-03-11\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10921673\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Open Journal of Vehicular Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10921673/\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"ENGINEERING, ELECTRICAL & ELECTRONIC\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Open Journal of Vehicular Technology","FirstCategoryId":"1085","ListUrlMain":"https://ieeexplore.ieee.org/document/10921673/","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"ENGINEERING, ELECTRICAL & ELECTRONIC","Score":null,"Total":0}
引用次数: 0

摘要

TARA代表威胁分析和风险评估,是网络安全实施的基础阶段,特别是在车辆系统的背景下。虽然近年来讨论了各种考虑因素和风险评估框架,但明显缺乏专门为重型(HD)车辆设计的TARA模型。高清车辆的安全考虑和漏洞与轻型(LD)车辆有很大不同,导致安全影响不同,攻击可行性也不同。这使得现有模型无法准确评估高清车辆的风险。本研究引入了一种针对HD车辆量身定制的新型风险评估模型,解决了EVITA、HEAVENS和ISO/SAE 21434等现有TARA框架的不足。这项工作的关键贡献在于在ISO/SAE框架内定制影响和可行性指标,以更好地解决高清车辆带来的独特安全挑战。与之前的模型不同,该方法调整了影响标准,以反映HD车辆特有的各种安全问题,这些问题在现有框架中没有得到充分解决。此外,通过对威胁载体和车辆接口的全面分析,该模型细化了可行性标准,确保对安全风险进行更准确和情境感知的评估。通过采用这些增强功能,所提出的模型提供了更精确的风险评估,与HD车辆的考虑相一致,有助于优先考虑威胁,并就风险处理做出最佳决策。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Cyber Threat Susceptibility Assessment for Heavy-Duty Vehicles Based on ISO/SAE 21434
TARA, which stands for Threat Analysis and Risk Assessment, serves as the foundational stage of cybersecurity implementation, particularly in the context of vehicular systems. While various considerations and risk assessment frameworks have been discussed in recent years, there is a notable lack of TARA models specifically designed for heavy-duty (HD) vehicles. The security considerations and vulnerabilities in HD vehicles differ significantly from those in light-duty (LD) vehicles, leading to different security impacts and varying attack feasibility. This makes existing models inadequate for accurately assessing risks in the context of HD vehicles. This study introduces a novel risk assessment model tailored for HD vehicles, addressing gaps in existing TARA frameworks such as EVITA, HEAVENS, and ISO/SAE 21434. The key contribution of this work lies in the customization of impact and feasibility metrics within the ISO/SAE framework to better account for the unique security challenges posed by HD vehicles. Unlike prior models, this approach adapts the impact criteria to reflect the diverse range of security concerns specific to HD vehicles, which have been inadequately addressed in existing frameworks. Additionally, through a comprehensive analysis of threat vectors and vehicle interfaces, the model refines feasibility criteria, ensuring a more accurate and context-aware assessment of security risks. By adopting these enhancements, the proposed model offers more precise risk assessments that align with HD vehicle considerations, helping to prioritize threats and make optimal decisions regarding risk treatment.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
9.60
自引率
0.00%
发文量
25
审稿时长
10 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信