An STPA-based Approach for Systematic Security Analysis of In-vehicle Diagnostic and Software Update Systems

06/16/2020
by   Jinghua Yu, et al.
0

The in-vehicle diagnostic and software update system, which supports remote diagnostic and Over-The-Air (OTA) software updates, is a critical attack goal in automobiles. Adversaries can inject malicious software into vehicles or steal sensitive information through communication channels. Therefore, security analysis, which identifies potential security issues, needs to be conducted in system design. However, existing security analyses of in-vehicle systems are threat-oriented, which start with threat identification and assess risks by brainstorming. In this paper, a system-oriented approach is proposed on the basis of the System-Theoretic Process Analysis (STPA). The proposed approach extends the original STPA from the perspective of data flows and is applicable for information-flow-based systems. Besides, we propose a general model for in-vehicle diagnostic and software update systems and use it to establish a security analysis guideline. In comparison with threat-oriented approaches, the proposed approach shifts from focusing on threats to system vulnerabilities and seems to be efficient to prevent the system from known or even unknown threats. Furthermore, as an extension of the STPA, which has been proven to be applicable to high level designs, the proposed approach can be well integrated into high-level analyses and perform co-design in different disciplines within a unified STPA framework.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/04/2020

Data-Flow-Based Extension of the System-Theoretic Process Analysis for Security (STPA-Sec)

Security analysis is an essential activity in security engineering to id...
research
06/25/2021

SaSeVAL: A Safety/Security-Aware Approach for Validation of Safety-Critical Systems

Increasing communication and self-driving capabilities for road vehicles...
research
02/18/2021

Security audit logging in microservice-based systems: survey of architecture patterns

Objective. Service-oriented architecture increases technical abilities f...
research
06/18/2021

Risk-Oriented Design Approach For Forensic-Ready Software Systems

Digital forensic investigation is a complex and time-consuming activity ...
research
06/23/2018

A Recursive PLS (Partial Least Squares) based Approach for Enterprise Threat Management

Most of the existing solutions to enterprise threat management are preve...
research
07/05/2023

ScalOTA: Scalable Secure Over-the-Air Software Updates for Vehicles

Over-the-Air (OTA) software updates are becoming essential for electric/...
research
06/12/2023

Are Software Updates Useless Against Advanced Persistent Threats?

A dilemma worth Shakespeare's Hamlet is increasingly haunting companies ...

Please sign up or login with your details

Forgot password? Click here to reset