An Agnostic Domain Specific Language for Implementing Attacks in an Automotive Use Case
Abstract
This paper presents a Domain Specific Language (DSL) for generically describing cyber attacks, agnostic to specific system-under-test(SUT). The creation of the presented DSL is motivated by an automotive use case. The concepts of the DSL are generic such thatattacks on arbitrary systems can be addressed.The ongoing trend to improve the user experience of vehicles with connected services implies an enhanced connectivity as well asremote accessible interface opens potential attack vectors. This might also impact safety and the proprietary nature of potential SUTs.Reusing tests of attack vectors to industrialize testing them on multiple SUTs mandates an abstraction mechanism to port an attackfrom one system to another. The DSL therefore generically describes attacks for the usage with a test case generator (and executionenvironment) also described in this paper. The latter use this description and a database with SUT-specific information to generateattack implementations for a multitude of different (automotive) SUTs.
Cite
@article{arxiv.2107.02916,
title = {An Agnostic Domain Specific Language for Implementing Attacks in an Automotive Use Case},
author = {Christian Wolschke and Stefan Marksteiner and Tobias Braun and Markus Wolf},
journal= {arXiv preprint arXiv:2107.02916},
year = {2021}
}
Comments
13 pages, 4 figures, accepted at the 10th International Workshop on Security of Mobile Applications (IWSMA 2021) in conjunction with the 16th International Conference on Availability, Reliability and Security (ARES 2021)