首页> 外文会议>Euromicro International Conference on Parallel, Distributed and Network-Based Processing >Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
【24h】

Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain

机译:汽车域内网络安全工程的攻击表面评估

获取原文

摘要

Connected smart cars enable new attacks that may have serious consequences. Thus, the development of new cars must follow a cybersecurity engineering process as defined for example in ISO/SAE 21434. A central part of such a process is the threat and risk assessment including an attack feasibility rating. In this paper, we present an attack surface assessment with focus on the attack feasibility rating compliant to ISO/SAE 21434. We introduce a reference architecture with assets constituting the attack surface, the attack feasibility rating for these assets, and the application of this rating on typical use cases. The attack feasibility rating assigns attacks and assets to an evaluation of the attacker dimensions such as the required knowledge and the feasibility of attacks derived from it. Our application of sample use cases shows how this rating can be used to assess the feasibility of an entire attack path. The attack feasibility rating can be used as a building block in a threat and risk assessment according to ISO/SAE 21434.
机译:连接的智能汽车使新的攻击可能具有严重后果。因此,新车的发展必须遵循例如ISO / SAE 21434中所定义的网络安全工程过程。这种过程的中心部分是包括攻击可行性等级的威胁和风险评估。在本文中,我们展示了一种攻击表面评估,重点是符合ISO / SAE 21434的攻击可行性等级。我们引入了构成攻击表面的资产的参考架构,这些资产的攻击可行性等级以及该评级的应用关于典型用例。攻击可行性评级将攻击和资产分配给攻击者尺寸的评估,例如所需的知识和攻击的可行性。我们的样本用例的应用显示了如何使用该评级来评估整个攻击路径的可行性。根据ISO / SAE 21434,攻击可行性额定值可以用作威胁和风险评估中的构建块。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号