首页> 外文会议>International Joint Conference on e-Business and Telecommunications >Attack surface and vulnerability assessment of automotive Electronic Control Units
【24h】

Attack surface and vulnerability assessment of automotive Electronic Control Units

机译:汽车电子控制单元的受攻击面和易损性评估

获取原文
获取外文期刊封面目录资料

摘要

Modern vehicles are controlled by an on-board network of ECUs (Electronic Control Units), which are specially designed computers that contain tightly tailored and customized software. Especially the trends for ECU connectivity and for semi-autonomous driver assistance functions may have an impact on passenger safety and require thorough security assessments, yet the ECU divergence strains those assessments. We therefore propose an easily automated, quantitative, probabilistic method and metric based on ECU development data and software flash images for the attack surface and vulnerability assessment automation. Our method and metric is designed for the integration into an (iterative) engineering process and the facilitation of code reviews and other security assessments, such as penetration tests. The automotive attack surface comprises especially internal communication interfaces, including diagnosis protocols, external and user-accessible interfaces, such as USB sockets, as well as low-level hardware interfaces. Some exemplary indicators for the vulnerability are access restrictions, casing tamper-resistance, code size, previously found vulnerabilities; strictness of compilers, frameworks and application binary interfaces; conducted security audits and deployed exploit mitigation techniques. This paper's main contributions are I) a method and a metric for collecting attack surface and predicting the engineering effort for a code injection exploit from ECU development data and II) an application of our metric and method into our graph-based security assessment.
机译:现代车辆由ECU(电子控制单元)车载网络控制,ECU是专门设计的计算机,其中包含紧密定制和定制的软件。尤其是ECU连接性和半自动驾驶员辅助功能的发展趋势可能会对乘客安全产生影响,并需要进行全面的安全评估,但是ECU的分歧使这些评估变得困难。因此,我们基于ECU开发数据和软件闪存映像,为攻击面和漏洞评估自动化提供了一种易于自动化,定量,概率性的方法和度量。我们的方法和指标旨在集成到(迭代)工程流程中,并简化代码审查和其他安全评估,例如渗透测试。汽车攻击面尤其包括内部通信接口,包括诊断协议,外部和用户可访问的接口(例如USB插槽)以及底层硬件接口。该漏洞的一些示例性指标是访问限制,机壳防篡改,代码大小,先前发现的漏洞;编译器,框架和应用程序二进制接口的严格性;进行了安全审核,并部署了缓解漏洞的技术。本文的主要贡献是:I)一种收集攻击面并根据ECU开发数据预测代码注入漏洞的工程工作量的方法和度量,以及II)将我们的度量和方法应用于基于图形的安全评估中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号