Cybersecurity risk analysis of an automated driving system
- New laws and technologies, but also persistent problems like truck driver shortage, have led to advances in the field of autonomous driving and consequently to new cyberrisks. We present the results of our cyber security risk analysis for a Control Center-supervised Level 4 Automated Driving System (ADS), whose system model we created through expert interviews with a global truck manufacturer. Example damage scenarios with high impact rating include Disclosure of video data, Loss of ADS function in motion, Dangerous driving maneuvers, and Activation outside of Operational Design Domain. We have identified over 200 threat scenarios, consisting of a combination of main attack steps that threaten specific parts of the item and preparation steps that determine how these parts are accessed and by which type of attacker. Without taking controls into account, the realization of these threat scenarios results in 65 significant risks. We propose to treat the threat scenarios, on the one hand, by claims concerning implementation-relevant aspects as Detection of system failure and security controls such as Authentic transmission of data. We conclude by detailing principles we have extracted from our analysis that can be applied to other cyber security risk analyses of automated driving systems.
Author: | Patrick WagnerORCiDGND, Nikolai PuchORCiDGND, David EmeisORCiDGND |
---|---|
URN: | urn:nbn:de:hbz:294-103919 |
DOI: | https://doi.org/10.13154/294-10391 |
Parent Title (English): | 21th escar Europe : The World's Leading Automotive Cyber Security Conference (Hamburg, 15. - 16.11.2023) |
Document Type: | Part of a Book |
Language: | English |
Date of Publication (online): | 2023/10/25 |
Date of first Publication: | 2023/10/25 |
Publishing Institution: | Ruhr-Universität Bochum, Universitätsbibliothek |
Tag: | Automated Driving; Cyber Security; Logistics; Risk Analysis; Truck |
Pagenumber: | 15 |
Dewey Decimal Classification: | Allgemeines, Informatik, Informationswissenschaft / Informatik |
open_access (DINI-Set): | open_access |
Konferenz-/Sammelbände: | 21th escar Europe : The World's Leading Automotive Cyber Security Conference |
Licence (German): | Keine Creative Commons Lizenz - es gelten die Rechteeinräumung und das deutsche Urheberrecht |