作者
Madeline Cheah, Siraj A Shaikh, Jeremy Bryans, Paul Wooderson
发表日期
2018/8/1
期刊
Computers & Security
卷号
77
页码范围
360-379
出版商
Elsevier Advanced Technology
简介
Security testing and assurance in the automotive domain is challenging. This is predominantly due to the increase in the amount of software and the number of connective entry points in the modern vehicle. In this paper we build on earlier work by using a systematic security evaluation to enumerate undesirable behaviours, enabling the assignment of severity ratings in a (semi-) automated manner. We demonstrate this in two case studies; firstly with the native Bluetooth connection in an automotive head unit, and secondly with an aftermarket diagnostics device. We envisage that the resulting severity classifications would add weight to a security assurance case, both as evidence and as guidance for future test cases.
引用总数
20192020202120222023202461898152
学术搜索中的文章