A simulation framework for automotive cybersecurity risk assessment

被引:1
|
作者
Jayaratne, Don Nalin Dharshana [1 ,3 ]
Kamtam, Suraj Harsha [1 ]
Shaikh, Siraj Ahmed [2 ,3 ]
Ramli, Muhamad Azfar [3 ]
Lu, Qian [1 ]
Mepparambath, Rakhi Manohar
Nguyen, Hoang Nga [2 ]
Rakib, Abdur [1 ,2 ]
机构
[1] Coventry Univ, Ctr Future Transport & Cities CFTC, Coventry, England
[2] Swansea Univ, Dept Comp Sci, Syst Secur Grp SSG, Swansea, Wales
[3] ASTAR, Inst High Performance Comp IHPC, Singapore, Singapore
关键词
Connected vehicles; Automotive cybersecurity; Risk assessment; Simulation; VULNERABILITIES;
D O I
10.1016/j.simpat.2024.103005
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Human-initiated disruptions such as cyberattacks on connected vehicles have the potential to cause cascading failures in transport systems, leading to systemic risks. 'ISO/SAE 21434:2021 Road vehicles- Cybersecurity engineering' is the current standard for risk management of road vehicles. However, the threat analysis and risk assessment framework given in the standard focuses on asset-level analysis and assessment. Hence, this study develops a novel simulation- based framework to perform threat analysis and risk assessment on connected vehicles from a transport network perspective. The proposed framework is developed based on the ISO/SAE 21434 threat analysis and risk assessment methodology. We demonstrate the applicability and usefulness of the framework through a remote attack via the cellular network on the in-vehicle communication bus system of a connected vehicle to show the potential impacts on the transport network. Based on the findings of our case studies, we exemplify how cyberattacks on individual system components of a connected vehicle have the potential to cause systemic failures.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [2] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261
  • [3] Research and Application of Risk Assessment Method for Automotive Cybersecurity
    Ji, Haojie
    Yu, Haiyang
    Wang, Yinghui
    Peng, Jing
    CICTP 2021: ADVANCED TRANSPORTATION, ENHANCED CONNECTION, 2021, : 1535 - 1544
  • [4] Yet another cybersecurity risk assessment framework
    Ekstedt, Mathias
    Afzal, Zeeshan
    Mukherjee, Preetam
    Hacks, Simon
    Lagerstrom, Robert
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1713 - 1729
  • [5] Yet another cybersecurity risk assessment framework
    Mathias Ekstedt
    Zeeshan Afzal
    Preetam Mukherjee
    Simon Hacks
    Robert Lagerström
    International Journal of Information Security, 2023, 22 : 1713 - 1729
  • [6] PRISM: a strategic decision framework for cybersecurity risk assessment
    Goel, Rajni
    Kumar, Anupam
    Haddow, James
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 591 - 625
  • [7] Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management
    Ganin, Alexander A.
    Quach, Phuoc
    Panwar, Mahesh
    Collier, Zachary A.
    Keisler, Jeffrey M.
    Marchese, Dayton
    Linkov, Igor
    RISK ANALYSIS, 2020, 40 (01) : 183 - 199
  • [8] A Framework for Cybersecurity Requirements Management in the Automotive Domain
    Luo, Feng
    Jiang, Yifan
    Wang, Jiajia
    Li, Zhihao
    Zhang, Xiaoxian
    SENSORS, 2023, 23 (10)
  • [9] FRAPE: A Framework for Risk Assessment, Prioritization and Explainability of vulnerabilities in cybersecurity
    Parente, F. R.
    Rodrigues, Emanuel B.
    Mattos, Cesar L. C.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2025, 89
  • [10] A Quantitative Risk Assessment Framework for the Cybersecurity of Networked Medical Devices
    Van Devender, Maureen S.
    McDonald, Jeffrey Todd
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY ICCWS, 2023, : 402 - 411