Security Crash Test - Practical Security Evaluations of Automotive Onboard IT Components

نویسندگان

  • Stephanie Bayer
  • Thomas Enderle
  • Dennis-Kengo Oka
  • Marko Wolf
چکیده

Modern vehicles consist of many interconnected, software-based IT components which are tested very carefully for correct functional behavior to avoid safety problems, e.g. that the brakes suddenly stop working. However, in contrast to safety testing systematic testing against potential security gaps is not yet a common procedure within the automotive domain. This however could eventually enable a malicious entity to be able to attack a safety-critical IT component or even the whole vehicle. Several real-world demonstrations have already shown that this risk is not only academic theory [1]. Facing this challenge, the paper at hand first introduces some potential automotive security attacks and some important automotive security threats. It then explains in more detail how to identify and evaluate potential security threats for automotive IT components based on theoretical security analyses and practical security testing. Lastly, we propose " automotive security evaluation assurance levels " (ASEAL) which define up to four discrete security testing levels.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Automotive Security Testing - The Digital Crash Test

Modern vehicles consist of many interconnected, software-based IT components which are tested very carefully for correct functional behavior to avoid safety problems, e.g. the brakes suddenly stop working. However, in contrast to safety testing systematic testing against potential security gaps is not yet a common procedure within the automotive domain. This however could eventually enable a ma...

متن کامل

Effective and Efficient Security Policy Engines for Automotive On-Board Networks

The configuration of security mechanisms in automotive onboard networks makes it necessary to define and deploy adapted security policies. This paper discusses how to design policy engines that implement an effective enforcement in such architectures despite the complexity of the protocol stacks of on-board electronic control units. It also evaluates how policies expressed in XACML can be adapt...

متن کامل

Safety-Critical Automotive and Industrial Data Security

Automotive and industrial data security is researched for almost a decade now and the author started doing research and working in this area in 2003. Recent attacks impressively demonstrated weaknesses that were anticipated for a while now. In the area of automotive data security, a research team of the University of Washington and University of California, San Diego, was able to hack into a mo...

متن کامل

OCTANE: An Extensible Open Source Car Security Testbed

Security research and training using cyber-physical systems (e.g., automotive networks) is challenging because of the need to replicate the interactions between the hardware components and the control software of the systems. These interactions are challenging to replicate due to dynamic inputs in real-world environments that cause various interactions of hardware components and control softwar...

متن کامل

An Experimental Model for In-vehicle Networks and Subsystems

We pursue an experimental setup that gathers various in-vehicle networks and subsystems that are critical from a security perspective. As cyber-attacks to cars have become a reality, the model comes handy for both research and engineering education. The usefulness of this empirical model stems from both being helpful in creating a realistic view on the security of automotive systems and for cre...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014