ACTISM: Threat-informed Dynamic Security Modelling for Automotive Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Huang, Shaofei, Poskitt, Christopher M., Shar, Lwin Khin
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929699009069056
author Huang, Shaofei
Poskitt, Christopher M.
Shar, Lwin Khin
author_facet Huang, Shaofei
Poskitt, Christopher M.
Shar, Lwin Khin
contents Evolving cybersecurity threats in complex cyber-physical systems pose significant risks to system functionality and safety. This experience report introduces ACTISM (Automotive Consequence-Driven and Threat-Informed Security Modelling), an integrated security modelling framework that enhances the resilience of automotive systems by dynamically updating their cybersecurity posture in response to prevailing and evolving threats, attacker tactics, and their impact on system functionality and safety. ACTISM addresses the existing knowledge gap in static security assessment methodologies by providing a dynamic and iterative framework. We demonstrate the effectiveness of ACTISM by applying it to a real-world example of the Tesla Electric Vehicle's In-Vehicle Infotainment system, illustrating how the security model can be adapted as new threats emerge. We also report the results of a practitioners' survey on the usefulness of ACTISM and its future directions. The survey highlights avenues for future research and development in this area, including automated vulnerability management workflows for automotive systems.
format Preprint
id arxiv_https___arxiv_org_abs_2412_00416
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle ACTISM: Threat-informed Dynamic Security Modelling for Automotive Systems
Huang, Shaofei
Poskitt, Christopher M.
Shar, Lwin Khin
Cryptography and Security
Evolving cybersecurity threats in complex cyber-physical systems pose significant risks to system functionality and safety. This experience report introduces ACTISM (Automotive Consequence-Driven and Threat-Informed Security Modelling), an integrated security modelling framework that enhances the resilience of automotive systems by dynamically updating their cybersecurity posture in response to prevailing and evolving threats, attacker tactics, and their impact on system functionality and safety. ACTISM addresses the existing knowledge gap in static security assessment methodologies by providing a dynamic and iterative framework. We demonstrate the effectiveness of ACTISM by applying it to a real-world example of the Tesla Electric Vehicle's In-Vehicle Infotainment system, illustrating how the security model can be adapted as new threats emerge. We also report the results of a practitioners' survey on the usefulness of ACTISM and its future directions. The survey highlights avenues for future research and development in this area, including automated vulnerability management workflows for automotive systems.
title ACTISM: Threat-informed Dynamic Security Modelling for Automotive Systems
topic Cryptography and Security
url https://arxiv.org/abs/2412.00416