网络安全越来越被认为是汽车系统的一个重要话题,特别是在联网和自动驾驶领域。即将出台的法规对汽车领域的网络安全提出了多层次的要求,以获得型号批准。在组织层面,需要一个涵盖整个车辆生命周期和生态系统的网络安全管理系统(CSMS)。此外,必须对申请型号批准的每一种车辆类型的网络安全进行论证。由于这些要求与现有的型号批准要求相比具有新颖性,因此正在进行测试阶段。CSMS的组成部分和范围是一个开放的问题。本文概述了CSMS的要求,确定了方法和差距,并对能够满足这些要求的潜在框架进行了展望。


之后,在第三节中概述了汽车网络安全的现有构建模块和开放点。在第四节中,提出了一个起点来定义一个符合CSMS的流程,涵盖整个生命周期。

如果车辆支持售后软件、服务、应用程序或数据的存储或执行,则需要有专门的受保护环境。所需要的信息需要通过整个供应链收集和验证。
III.汽车网络安全框架的技术现状

证据需要显示网络安全的完整性和充分性。完整性表明,根据目前的最先进的技术,所有的风险都得到了考虑。充分性表明,处理风险的方式是充分的。 完整性可以通过提供证据证明在整个生命周期内采用了系统的程序来证明。充分性的证据需要表明风险得到了充分的处理。这方面的保证要求可以从通用标准和NIST的测试指南中获取。提出的技术从文件审查开始,包括对已经使用的系统进行持续测试和评估的技术。对于网络安全保障来说,一个挑战是如何确定什么时候产生的证据是足够的。
IV.CSMS框架

每当车辆运行过程中检测到事故或故障,响应阶段就会转发一份报告。然后,该响应在预测阶段由人工处理和分析,或通过[50]中提出的自动推理机制进行处理和分析。获得的结果被转发到故障或事件库,这是CSMS的一部分。这个存储库在适应阶段经常被扫描,根据优先级标准,选择一个报告的故障或事件进行调查,从而触发下一个持续改进周期。
V.结论
参考文献:
[1]C. Ebert and C. Jones, “Embedded software: Facts, figures, and future.,”IEEE Computer, vol. 42, no. 4, 2009.
[2]European Commission, “A European strategy on Cooperative Intelligent Transport Systems, a milestone towards cooperative, connected and automated mobility,” 2016.
[3]Intel, “Safety First for Automated Driving,” 2019.
[4]S. Strobl, D. Hofbauer, C. Schmittner, S. Maksuti, M. Tauber, and J. Delsing, “Connected cars Threats, vulnerabilities and their impact,” in 2018 IEEE Industrial Cyber-Physical Systems (ICPS), (St. Petersburg), pp. 375–380, IEEE, 2018.
[5]M. Ring, J. Durrwang, F. Sommer, and R. Kriesten, “Survey on vehicular attacks - building a vulnerability database,” in 2015 IEEE International Conference on Vehicular Electronics and Safety (ICVES), (Yokohama), pp. 208–212, IEEE, 2015.
[6]Charlie Miller and Chris Valasek, “Remote Exploitation of an Unaltered Passenger Vehicle,” tech. rep., Black Hat 2015, 2015.
[7]Wikipedia, “World forum for harmonization of vehicle regulations.” https://w.wiki/8tP, (accessed 2019-09-07).
[8]UNECE,“TaskforceonCyberSecu- rityand(OTA)softwareupdates(CS/OTA).” https://wiki.unece.org/pages/viewpage.action?pageId=40829521, (accessed 2019-09-07).
[9]W. Kerber and D. Moeller, “Access to data in connected cars and the recent reform of the motor vehicle type approval regulation,” 2019.
[10]UNECE WP.29 GRVA, “Draft recommendation on cyber security of the task force on cyber security and over-the-air issues of unece wp.29 grva.” https://wiki.unece.org/pages/viewpage.action?pageId=60362218, 2018-09-21 (accessed 2019-09-07).
[11]UNECE WP.29 GRVA, “DGRVA-01-xx (UN-CS OTA) Final Draft Recommendation on Software Updates incl. Annex A-B.” https://wiki.unece.org/pages/viewpage.action?pageId=60362218, 2018- 09-21 (accessed 2019-09-07).
[12]ISO/TC 22/SC 32, “ISO 26262 Road vehicles - Functional safety,” ISO
- International Standardization Organization, 2018.
[13]SAE Vehicle Electrical System Security Committee and others, “Sae j3061-cybersecurity guidebook for cyber-physical automotive systems,” SAE-Society of Automotive Engineers, 2016.
[14]ISO, “Risk management–principles and guidelines,” International Or- ganization for Standardization, Geneva, Switzerland, 2009.
[15]J. T. Force, “Risk management framework for information systems and organizations,” NIST Special Publication, vol. 800, p. 37, 2018.
[16]A. Karahasanovic, P. Kleberger, and M. Almgren, “Adapting threat modeling methods for the automotive industry,” in Proceedings of the 15th ESCAR Conference, pp. 1–10, 2017.
[17]Z. Ma and C. Schmittner, “Threat modeling for automotive security analysis,” Advanced Science and Technology Letters, vol. 139, pp. 333– 339, 2016.
[18]M. Wolf, “Combining safety and security threat modeling to improve automotive penetration testing,” 2019.
[19]G. Macher, H. Sporer, R. Berlach, E. Armengaud, and C. Kreiner, “Sahara: a security-aware hazard and risk analysis method,” in Pro- ceedings of the 2015 Design, Automation & Test in Europe Conference & Exhibition, pp. 621–624, EDA Consortium, 2015.
[20]C. Schmittner, Z. Ma, and P. Smith, “Fmvea for safety and security anal- ysis of intelligent and cooperative vehicles,” in International Conference on Computer Safety, Reliability, and Security, pp. 282–288, Springer, 2014.
[21]“Common Methodology for Information Technology Security Evalua- tion - Evaluation methodology,” Sept. 2012.
[22]A. Ruddle, D. Ward, B. Weyl, S. Idrees, Y. Roudier, M. Friedewald,
T. Leimbach, A. Fuchs, S. Gu¨rgens, O. Henniger, et al., “Deliverable d2.3: Security requirements for automotive on-board networks based on dark-side scenarios,” 2009.
[23]D. Dominic, S. Chhawri, R. M. Eustice, D. Ma, and A. Weimerskirch, “Risk assessment for cooperative automated driving,” in Proceedings of the 2nd ACM Workshop on Cyber-Physical Systems Security and Privacy, pp. 47–58, ACM, 2016.
[24]M. Islam, C. Sandberg, A. Bokesand, T. Olovsson, H. Broberg,P. Kleberger, A. Lautenbach, A. Hansson, A. So¨derberg-Rivkin, and S. Kadhirvelan, “Deliverable d2-security models,” HEAVENS Project, Deliverable D, vol. 2, 2014.
[25]T. Vogt, “Tool-chain enriched security development in automotive indus- try.” Presentation at the 12th Graz Symposium Virtual Vehicle (GSVF), 05 2019.
[26]B. Sheehan, F. Murphy, M. Mullins, and C. Ryan, “Connected and autonomous vehicles: A cyber-risk classification framework,” Trans- portation Research Part A: Policy and Practice, vol. 124, pp. 523–536, 2019.
[27]Information Assurance Solutions Group, “Defense in depth.pdf,” 2010.
[28]Andy Birnie and Timo van Roermund, “A multi-layer vehicle security framework,” 2016.
[29]F. Sagstetter, M. Lukasiewycz, S. Steinhorst, M. Wolf, A. Bouard, W. R. Harris, S. Jha, T. Peyrin, A. Poschmann, and S. Chakraborty, “Security challenges in automotive hardware/software architecture design,” in Proceedings of the Conference on Design, Automation and Test in Europe, pp. 458–463, EDA Consortium, 2013.
[30]M. Wolf, A. Weimerskirch, and C. Paar, “Security in automotive bus systems,” in Workshop on Embedded Security in Cars, Bochum, 2004.
[31]S.-F. Lokman, A. T. Othman, and M.-H. Abu-Bakar, “Intrusion detection system for automotive controller area network (can) bus system: a review,” EURASIP Journal on Wireless Communications and Networking, vol. 2019, no. 1, p. 184, 2019.
[32]L. Chen, J. Franklin, and A. Regenscheid, “Guidelines on hardware- rooted security in mobile devices,” tech. rep., National Institute of Standards and Technology, 2012.
[33]A. Barber, “Status of work in process on iso/sae 21434 automotive cybersecurity standard,” presentation, ISO SAE International, vol. 10, 2018.
[34]C. Schmittner, G. Griessnig, and Z. Ma, “Status of the development of iso/sae 21434,” in European Conference on Software Process Improve- ment, pp. 504–513, Springer, 2018.
[35]IEC, “Iec 62443 - security for industrial automation and control sys- tems,” International Electrotechnical Commission, 2018.
[36]E. Barker and W. Barker, “Recommendation for key management, part 2: Best practices for key management organizations (2nd draft),” tech. rep., National Institute of Standards and Technology, 2018.
[37]M. Broy, I. H. Kruger, A. Pretschner, and C. Salzmann, “Engineering automotive software,” Proceedings of the IEEE, vol. 95, no. 2, pp. 356– 373, 2007.
[38]O.-S. Goia et al., “Tisax assessment for information security in the automotive industry,” 2019.
[39]ISO, “Information technology security techniques information security management systems requirements,” International Organization for Standardization, Geneva, Switzerland, 2013.
[40]G. Macher, A. Much, A. Riel, R. Messnarz, and C. Kreiner, “Automotive spice, safety and cybersecurity integration,” 09 2017.
[41]A. ISAC, “Automotive information sharing and analysis center.” https://www.automotiveisac.com/, (accessed 2019-09-23).
[42]C. Johnson, M. Badger, D. Waltermire, J. Snyder, and C. Skorupka, “Guide to cyber threat information sharing,” tech. rep., National Institute of Standards and Technology, 2016.
[43]A. K. Mandal, A. Cortesi, P. Ferrara, F. Panarotto, and F. Spoto, “Vulner- ability analysis of android auto infotainment apps,” in Proceedings of the 15th ACM International Conference on Computing Frontiers, pp. 183– 190, ACM, 2018.
[44]P. Kleberger, T. Olovsson, and E. Jonsson, “An in-depth analysis of the security of the connected repair shop,” in The Seventh International Conference on Systems and Networks Communications (ICSNC), Pro- ceedings. Lisbon, 18-23 November, 2012. IARIA., p. 99, 2012.
[45]E. A. M. A. ACEA, “Safe and secure access to vehicle data.” https://cardatafacts.eu/, (accessed 2019-09-23).
[46]M. McCarthy, M. Seidl, S. Mohan, J. Hopkin, A. Stevens, and F. Og- nissanto, “Access to in-vehicle data and resources,” 2017.
[47]I. ISO, IEC, “Systems and software engineering systems and software assurance part 1: Concepts and vocabulary.” ”https://www.iso.org/obp/ui/iso:std:73567:en”, 2019.
[48]T. Kelly and R. Weaver, “The goal structuring notation–a safety argu- ment notation,” in Proceedings of the dependable systems and networks 2004 workshop on assurance cases, p. 6, Citeseer, 2004.
[49]K. Scarfone, M. Souppaya, A. Cody, and A. Orebaugh, “Technical guide to information security testing and assessment,” NIST Special Publication, vol. 800, no. 115, pp. 2–25, 2008.
[50]J. Dobaj, J. Iber, M. Krisper, and C. Kreiner, “Towards Executable Dependability Properties,” 2018.
[51]J. Dobaj, M. Krisper, and G. Macher, “Towards Cyber-Physical Infras- tructure as-a-Service (CPIaaS) in the Era of Industry 4.0,” 2019.
[52]W. Haas and P. Langjahr, “Cross-domain vehicle control units in modern E/E architectures,” 2016.
分享不易,恳请点个【👍】和【在看】