亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

Combining Cyber Security Intelligence to Refine Automotive Cyber Threats

计算机安全 计算机科学 汽车工业 网络攻击 工程类 航空航天工程
作者
Florian Sommer,Mona Gierl,Reiner Kriesten,Frank Kargl,Eric Sax
出处
期刊:ACM transactions on privacy and security [Association for Computing Machinery]
卷期号:27 (2): 1-34 被引量:1
标识
DOI:10.1145/3644075
摘要

Modern vehicles increasingly rely on electronics, software, and communication technologies (cyber space) to perform their driving task. Over-The-Air (OTA) connectivity further extends the cyber space by creating remote access entry points. Accordingly, the vehicle is exposed to security attacks that are able to impact road safety. A profound understanding of security attacks, vulnerabilities, and mitigations is necessary to protect vehicles against cyber threats. While automotive threat descriptions, such as in UN R155, are still abstract, this creates a risk that potential vulnerabilities are overlooked and the vehicle is not secured against them. So far, there is no common understanding of the relationship of automotive attacks, the concrete vulnerabilities they exploit, and security mechanisms that would protect the system against these attacks. In this article, we aim at closing this gap by creating a mapping between UN R155, Microsoft STRIDE classification, Common Attack Pattern Enumeration and Classification (CAPEC), and Common Weakness Enumeration (CWE). In this way, already existing detailed knowledge of attacks, vulnerabilities, and mitigations is combined and linked to the automotive domain. In practice, this refines the list of UN R155 threats and therefore supports vehicle manufacturers, suppliers, and approval authorities to meet and assess the requirements for vehicle development in terms of cybersecurity. Overall, 204 mappings between UN threats, STRIDE, CAPEC attack patterns, and CWE weaknesses were created. We validated these mappings by applying our Automotive Attack Database (AAD) that consists of 361 real-world attacks on vehicles. Furthermore, 25 additional attack patterns were defined based on automotive-related attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
4秒前
5秒前
7秒前
ajianq发布了新的文献求助10
9秒前
lily发布了新的文献求助10
10秒前
Perry完成签到,获得积分10
10秒前
Anthocyanidin完成签到,获得积分10
18秒前
lily完成签到,获得积分10
19秒前
Owen应助科研通管家采纳,获得10
21秒前
完美的海完成签到 ,获得积分0
38秒前
Demi发布了新的文献求助20
42秒前
jyy完成签到,获得积分10
45秒前
49秒前
朴素千愁发布了新的文献求助20
53秒前
57秒前
1分钟前
1分钟前
雪中发布了新的文献求助30
1分钟前
清脆大米发布了新的文献求助10
1分钟前
斯文败类应助kante采纳,获得10
1分钟前
无花果应助天大青年采纳,获得10
1分钟前
1分钟前
甜甜圆圆完成签到,获得积分10
1分钟前
1分钟前
1分钟前
kante发布了新的文献求助10
1分钟前
cille发布了新的文献求助10
1分钟前
嘟嘟发布了新的文献求助10
1分钟前
ShowMaker给学习的苹果的求助进行了留言
1分钟前
思源应助田柾国采纳,获得10
1分钟前
桐桐应助清风浮云采纳,获得10
1分钟前
1分钟前
清风浮云完成签到,获得积分10
1分钟前
kante完成签到,获得积分10
1分钟前
田柾国发布了新的文献求助10
1分钟前
2分钟前
brg1小王子发布了新的文献求助10
2分钟前
2分钟前
2分钟前
jerry完成签到,获得积分10
2分钟前
高分求助中
Evolution 10000
Sustainability in Tides Chemistry 2800
юрские динозавры восточного забайкалья 800
English Wealden Fossils 700
Diagnostic immunohistochemistry : theranostic and genomic applications 6th Edition 500
Chen Hansheng: China’s Last Romantic Revolutionary 500
China's Relations With Japan 1945-83: The Role of Liao Chengzhi 400
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3150492
求助须知:如何正确求助?哪些是违规求助? 2801881
关于积分的说明 7845881
捐赠科研通 2459245
什么是DOI,文献DOI怎么找? 1309130
科研通“疑难数据库(出版商)”最低求助积分说明 628656
版权声明 601727