Title
Building an automotive security assurance case using systematic security evaluations.
Abstract
Security testing and assurance in the automotive domain is challenging. This is predominantly due to the increase in the amount of software and the number of connective entry points in the modern vehicle. In this paper we build on earlier work by using a systematic security evaluation to enumerate undesirable behaviours, enabling the assignment of severity ratings in a (semi-) automated manner. We demonstrate this in two case studies; firstly with the native Bluetooth connection in an automotive head unit, and secondly with an aftermarket diagnostics device. We envisage that the resulting severity classifications would add weight to a security assurance case, both as evidence and as guidance for future test cases.
Year
DOI
Venue
2018
10.1016/j.cose.2018.04.008
Computers & Security
Keywords
Field
DocType
Automotive,Bluetooth,Cybersecurity,Security assurance,Penetration testing
Security testing,Computer science,Computer security,Software security assurance,Automotive security,Software,Test case,Bluetooth,Automotive industry
Journal
Volume
ISSN
Citations 
77
0167-4048
2
PageRank 
References 
Authors
0.46
16
4
Name
Order
Citations
PageRank
Madeline Cheah1182.75
Siraj A. Shaikh29013.85
Jeremy W. Bryans317513.88
Paul Wooderson451.54