首页> 外文期刊>Computers & Security >Building an automotive security assurance case using systematic security evaluations
【24h】

Building an automotive security assurance case using systematic security evaluations

机译:使用系统的安全评估来构建汽车安全保证案例

获取原文
获取原文并翻译 | 示例
       

摘要

Security testing and assurance in the automotive domain is challenging. This is predominantly due to the increase in the amount of software and the number of connective entry points in the modern vehicle. In this paper we build on earlier work by using a systematic security evaluation to enumerate undesirable behaviours, enabling the assignment of severity ratings in a (semi-) automated manner. We demonstrate this in two case studies; firstly with the native Bluetooth connection in an automotive head unit, and secondly with an aftermarket diagnostics device. We envisage that the resulting severity classifications would add weight to a security assurance case, both as evidence and as guidance for future test cases. (C) 2018 Elsevier Ltd. All rights reserved.
机译:汽车领域的安全测试和保证具有挑战性。这主要是由于现代汽车中软件数量的增加和连接入口点的数量增加。在本文中,我们通过使用系统的安全性评估来枚举不良行为,从而以(半)自动方式分配严重等级,从而在早期工作的基础上进行开发。我们在两个案例研究中证明了这一点;首先是在汽车主机中使用本地蓝牙连接,其次是在售后诊断设备上。我们设想,由此产生的严重性分类将为安全保证案例增加权重,既作为证据,也为将来的测试案例提供指导。 (C)2018 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号