English

A Systematic Approach to Automotive Security

Cryptography and Security 2023-04-18 v2

Abstract

We propose a holistic methodology for designing automotivesystems that consider security a central concern at every design stage.During the concept design, we model the system architecture and definethe security attributes of its components. We perform threat analysis onthe system model to identify structural security issues. From that analysis,we derive attack trees that define recipes describing steps to successfullyattack the system's assets and propose threat prevention measures.The attack tree allows us to derive a verification and validation (V&V)plan, which prioritizes the testing effort. In particular, we advocate usinglearning for testing approaches for the black-box components. It consistsof inferring a finite state model of the black-box component from its executiontraces. This model can then be used to generate new relevanttests, model check it against requirements, and compare two differentimplementations of the same protocol. We illustrate the methodologywith an automotive infotainment system example. Using the advocated approach, we could also document unexpected and potentially criticalbehavior in our example systems.

Keywords

Cite

@article{arxiv.2303.02894,
  title  = {A Systematic Approach to Automotive Security},
  author = {Masoud Ebrahimi and Stefan Marksteiner and Dejan Ničković and Roderick Bloem and David Schögler and Philipp Eisner and Samuel Sprung and Thomas Schober and Sebastian Chlup and Christoph Schmittner and Sandra König},
  journal= {arXiv preprint arXiv:2303.02894},
  year   = {2023}
}

Comments

Presented at Formal Methods 2023 25th International Symposium (FM'23). 12 pages, 5 figures

R2 v1 2026-06-28T09:02:43.123Z