A simulation framework for automotive cybersecurity risk assessment

被引:1
|
作者
Jayaratne, Don Nalin Dharshana [1 ,3 ]
Kamtam, Suraj Harsha [1 ]
Shaikh, Siraj Ahmed [2 ,3 ]
Ramli, Muhamad Azfar [3 ]
Lu, Qian [1 ]
Mepparambath, Rakhi Manohar
Nguyen, Hoang Nga [2 ]
Rakib, Abdur [1 ,2 ]
机构
[1] Coventry Univ, Ctr Future Transport & Cities CFTC, Coventry, England
[2] Swansea Univ, Dept Comp Sci, Syst Secur Grp SSG, Swansea, Wales
[3] ASTAR, Inst High Performance Comp IHPC, Singapore, Singapore
关键词
Connected vehicles; Automotive cybersecurity; Risk assessment; Simulation; VULNERABILITIES;
D O I
10.1016/j.simpat.2024.103005
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Human-initiated disruptions such as cyberattacks on connected vehicles have the potential to cause cascading failures in transport systems, leading to systemic risks. 'ISO/SAE 21434:2021 Road vehicles- Cybersecurity engineering' is the current standard for risk management of road vehicles. However, the threat analysis and risk assessment framework given in the standard focuses on asset-level analysis and assessment. Hence, this study develops a novel simulation- based framework to perform threat analysis and risk assessment on connected vehicles from a transport network perspective. The proposed framework is developed based on the ISO/SAE 21434 threat analysis and risk assessment methodology. We demonstrate the applicability and usefulness of the framework through a remote attack via the cellular network on the in-vehicle communication bus system of a connected vehicle to show the potential impacts on the transport network. Based on the findings of our case studies, we exemplify how cyberattacks on individual system components of a connected vehicle have the potential to cause systemic failures.
引用
收藏
页数:16
相关论文
共 50 条
  • [21] CyberROAD: A cybersecurity risk assessment ontology for automotive domain aligned with ISO/SAE 21434:2021
    Khalil, Karim
    Gehrmann, Christian
    Vogel, Guenther
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2025, 90
  • [22] An Adversarial Risk Analysis Framework for Cybersecurity
    Rios Insua, David
    Couce-Vieira, Aitor
    Rubio, Jose A.
    Pieters, Wolter
    Labunets, Katsiaryna
    G. Rasines, Daniel
    RISK ANALYSIS, 2021, 41 (01) : 16 - 36
  • [23] Cybersecurity risk assessment of VDR
    Soner, Omer
    Kayisoglu, Gizem
    Bolat, Pelin
    Tam, Kimberly
    JOURNAL OF NAVIGATION, 2023, 76 (01): : 20 - 37
  • [24] Semantic Risk Assessment for Cybersecurity
    Aviad, Adiel
    Wecel, Krzysztof
    Abramowicz, Witold
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 513 - 520
  • [25] Cybersecurity Value-at-Risk Framework
    Sanghvi, Anuj Dilip
    Cryar, Ryan
    2023 IEEE POWER & ENERGY SOCIETY GENERAL MEETING, PESGM, 2023,
  • [26] Cybersecurity Threat Analysis, Risk Assessment and Design Patterns for Automotive Networked Embedded Systems: A Case Study
    Dobaj, Juergen
    Ekert, Damjan
    Stolfa, Jakub
    Stolfa, Svatopluk
    Macher, Georg
    Messnarz, Richard
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2021, 27 (08) : 830 - 849
  • [27] An assessment framework for explainable AI with applications to cybersecurity
    Calzarossa, Maria Carla
    Giudici, Paolo
    Zieni, Rasha
    ARTIFICIAL INTELLIGENCE REVIEW, 2025, 58 (05)
  • [28] Automotive Electronics, IT, and Cybersecurity
    Moeller, Dietmar P. F.
    Haas, Roland E.
    Akhilesh, K. B.
    2017 IEEE INTERNATIONAL CONFERENCE ON ELECTRO INFORMATION TECHNOLOGY (EIT), 2017, : 575 - 580
  • [29] Cybersecurity Risk Assessment for Space Systems
    Vessels, Ly
    Heffner, Kenneth
    Johnson, Daniel
    2019 IEEE SPACE COMPUTING CONFERENCE (SCC), 2019, : 11 - 19
  • [30] A Systems Approach for Cybersecurity Risk Assessment
    Meshkat, Leila
    Miller, Robert L.
    2022 68TH ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2022), 2022,