2016
DOI: 10.14257/astl.2016.139.68
|View full text |Cite
|
Sign up to set email alerts
|

Threat Modeling for Automotive Security Analysis

Abstract: Connected and intelligent vehicles create new risks to cybersecurity and road safety. Threat modeling is a building block in automotive security engineering that identifies potential threats for corresponding mitigations. In this paper, we address how to conduct threat modeling for automotive security analysis during the development lifecycle. We propose a practical and efficient approach to threat modeling, extending existing tool support and demonstrating its applicability and feasibility.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
10
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
4
4
1

Relationship

1
8

Authors

Journals

citations
Cited by 27 publications
(10 citation statements)
references
References 3 publications
0
10
0
Order By: Relevance
“…An IEC 62443 compliant risk analysis was presented by M.Fockel et al [24] for the development of industrial control systems. This methodology was also used by Zhendong Ma and Christoph Schmittner for the threat modelling of connected and intelligent vehicles [25] and by A. Vasenev et al [3] for a automotive case considering specific OTA threats. Nevertheless, it has to be pointed out that the STRIDE methodology addresses the system elements (assets) and threats identification, it does not cover the impact and likelihood estimations, nor the risk computation.…”
Section: Related Workmentioning
confidence: 99%
“…An IEC 62443 compliant risk analysis was presented by M.Fockel et al [24] for the development of industrial control systems. This methodology was also used by Zhendong Ma and Christoph Schmittner for the threat modelling of connected and intelligent vehicles [25] and by A. Vasenev et al [3] for a automotive case considering specific OTA threats. Nevertheless, it has to be pointed out that the STRIDE methodology addresses the system elements (assets) and threats identification, it does not cover the impact and likelihood estimations, nor the risk computation.…”
Section: Related Workmentioning
confidence: 99%
“…For security ISO/SAE 21434 [6] is still in development and SAE J3061 was pushed back to work in progress. We use threat modeling as a well established security analysis method for the automotive domain [28], [29], [30]. In order to support a consistent engineering workflow we utilize a threat modeling add-in for Enterprise Architect (EA) [31] 12 .…”
Section: Application Of the Approachmentioning
confidence: 99%
“…Several of the general approaches involve techniques for security threat assessments and workflows to support security-aware development [55,56]. For example, SAHARA [57] combines hazard and risk analysis with security threat modeling for automotive systems.…”
Section: Security Solutions For Automotive Systemsmentioning
confidence: 99%