Security Crash Test - Practical Security Evaluations of Automotive Onboard IT Components
نویسندگان
چکیده
Modern vehicles consist of many interconnected, software-based IT components which are tested very carefully for correct functional behavior to avoid safety problems, e.g. that the brakes suddenly stop working. However, in contrast to safety testing systematic testing against potential security gaps is not yet a common procedure within the automotive domain. This however could eventually enable a malicious entity to be able to attack a safety-critical IT component or even the whole vehicle. Several real-world demonstrations have already shown that this risk is not only academic theory [1]. Facing this challenge, the paper at hand first introduces some potential automotive security attacks and some important automotive security threats. It then explains in more detail how to identify and evaluate potential security threats for automotive IT components based on theoretical security analyses and practical security testing. Lastly, we propose " automotive security evaluation assurance levels " (ASEAL) which define up to four discrete security testing levels.
منابع مشابه
Automotive Security Testing - The Digital Crash Test
Modern vehicles consist of many interconnected, software-based IT components which are tested very carefully for correct functional behavior to avoid safety problems, e.g. the brakes suddenly stop working. However, in contrast to safety testing systematic testing against potential security gaps is not yet a common procedure within the automotive domain. This however could eventually enable a ma...
متن کاملEffective and Efficient Security Policy Engines for Automotive On-Board Networks
The configuration of security mechanisms in automotive onboard networks makes it necessary to define and deploy adapted security policies. This paper discusses how to design policy engines that implement an effective enforcement in such architectures despite the complexity of the protocol stacks of on-board electronic control units. It also evaluates how policies expressed in XACML can be adapt...
متن کاملSafety-Critical Automotive and Industrial Data Security
Automotive and industrial data security is researched for almost a decade now and the author started doing research and working in this area in 2003. Recent attacks impressively demonstrated weaknesses that were anticipated for a while now. In the area of automotive data security, a research team of the University of Washington and University of California, San Diego, was able to hack into a mo...
متن کاملOCTANE: An Extensible Open Source Car Security Testbed
Security research and training using cyber-physical systems (e.g., automotive networks) is challenging because of the need to replicate the interactions between the hardware components and the control software of the systems. These interactions are challenging to replicate due to dynamic inputs in real-world environments that cause various interactions of hardware components and control softwar...
متن کاملAn Experimental Model for In-vehicle Networks and Subsystems
We pursue an experimental setup that gathers various in-vehicle networks and subsystems that are critical from a security perspective. As cyber-attacks to cars have become a reality, the model comes handy for both research and engineering education. The usefulness of this empirical model stems from both being helpful in creating a realistic view on the security of automotive systems and for cre...
متن کامل