Automotive Innovation ›› 2021, Vol. 4 ›› Issue (3): 253-261.doi: 10.1007/s42154-021-00140-6

• • 上一篇    下一篇

A Systematic Risk Assessment Framework of Automotive Cybersecurity

Yunpeng Wang, Yinghui Wang, Hongmao Qin, Haojie Ji, Yanan Zhang & Jian Wang 
  

  1. School of Electronic and Information Engineering, Beihang University
    Hefei Innovation Research Institute, Beihang University
  • 出版日期:2021-08-16 发布日期:2021-08-16

A Systematic Risk Assessment Framework of Automotive Cybersecurity

Yunpeng Wang, Yinghui Wang, Hongmao Qin, Haojie Ji, Yanan Zhang & Jian Wang    

  1. School of Electronic and Information Engineering, Beihang University
    Hefei Innovation Research Institute, Beihang University
  • Online:2021-08-16 Published:2021-08-16

摘要:

The increasingly intelligent and connected vehicles have brought many unprecedented automotive cybersecurity threats, which may cause privacy breaches, personal injuries, and even national security issues. Before providing effective security solutions, a comprehensive risk assessment of the automotive cybersecurity must be carried out. A systematic cybersecurity risk assessment framework for automobiles is proposed in this study. It consists of an assessment process and systematic assessment methods considering the changes of threat environment, evaluation target, and available information in vehicle lifecycle. In the process of risk identification and risk analysis, the impact level and attack feasibility level are assessed based on the STRIDE model and attack tree method. An automotive cybersecurity risk matrix using a global rating algorithm is then constructed to create a quantitative risk metric. Finally, the applicability and feasibility of the proposed risk assessment framework are demonstrated through a use case, and the results prove that the proposed framework is effective. The proposed assessment framework helps to systematically derive automotive cybersecurity requirements.

Abstract:

The increasingly intelligent and connected vehicles have brought many unprecedented automotive cybersecurity threats, which may cause privacy breaches, personal injuries, and even national security issues. Before providing effective security solutions, a comprehensive risk assessment of the automotive cybersecurity must be carried out. A systematic cybersecurity risk assessment framework for automobiles is proposed in this study. It consists of an assessment process and systematic assessment methods considering the changes of threat environment, evaluation target, and available information in vehicle lifecycle. In the process of risk identification and risk analysis, the impact level and attack feasibility level are assessed based on the STRIDE model and attack tree method. An automotive cybersecurity risk matrix using a global rating algorithm is then constructed to create a quantitative risk metric. Finally, the applicability and feasibility of the proposed risk assessment framework are demonstrated through a use case, and the results prove that the proposed framework is effective. The proposed assessment framework helps to systematically derive automotive cybersecurity requirements.