Survey and Classification of Automotive Security Attacks

Обзор и классификация атак на автомобильные системы
Florian Sommer, Jürgen Dürrwang, Reiner Kriesten
2019-04-19

attack surfaceautomotive security attacksconnected and autonomous vehiclessecurity attack taxonomythreat analysis
Due to current development trends in the automotive industry towards stronger connected and autonomous driving, the attack surface of vehicles is growing which increases the risk of security attacks. This has been confirmed by several research projects in which vehicles were attacked in order to trigger various functions. In some cases these functions were critical to operational safety. To make automotive systems more secure, concepts must be developed that take existing attacks into account. Several taxonomies were proposed to analyze and classify security attacks. However, in this paper we show that the existing taxonomies were not designed for application in the automotive development process and therefore do not provide enough degree of detail for supporting development phases such as threat analysis or security testing. In order to be able to use the information that security attacks can provide for the development of security concepts and for testing automotive systems, we propose a comprehensive taxonomy with degrees of detail which addresses these tasks. In particular, our proposed taxonomy is designed in such a wa, that each step in the vehicle development process can leverage it.
1
Existing security-attack taxonomies lack sufficient detail and are not designed to support automotive development activities such as threat analysis and security testing.
2
Increasing vehicle connectivity and autonomy expands the automotive attack surface and raises security risks.
3
Research demonstrations have shown that attackers can trigger vehicle functions, including functions critical to operational safety.
4
The paper proposes a comprehensive, detail-graduated taxonomy of automotive security attacks that supports security concept development and testing throughout every vehicle development phase.

security attacks on connected and autonomous automotive systems and vehicles

classification and taxonomic characterization of automotive security attacks for threat analysis, security testing, and vehicle development processes

Publication Details
Publication Date
2019-04-19
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Florian Sommer
Jürgen Dürrwang
Reiner Kriesten
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%