An STPA-based Approach for Systematic Security Analysis of In-vehicle Diagnostic and Software Update Systems
Jinghua Yu, Stefan Wagner, Feng Luo

TL;DR
This paper introduces a system-oriented security analysis method based on STPA for in-vehicle diagnostic and software update systems, focusing on data flows to identify vulnerabilities and improve security design.
Contribution
It extends STPA to include data flow analysis for information systems and provides a general model and guidelines for security assessment of in-vehicle systems.
Findings
Shifts focus from threats to system vulnerabilities.
Applicable for high-level design and co-design processes.
Enhances security analysis efficiency for automotive systems.
Abstract
The in-vehicle diagnostic and software update system, which supports remote diagnostic and Over-The-Air (OTA) software updates, is a critical attack goal in automobiles. Adversaries can inject malicious software into vehicles or steal sensitive information through communication channels. Therefore, security analysis, which identifies potential security issues, needs to be conducted in system design. However, existing security analyses of in-vehicle systems are threat-oriented, which start with threat identification and assess risks by brainstorming. In this paper, a system-oriented approach is proposed on the basis of the System-Theoretic Process Analysis (STPA). The proposed approach extends the original STPA from the perspective of data flows and is applicable for information-flow-based systems. Besides, we propose a general model for in-vehicle diagnostic and software update systems…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSafety Systems Engineering in Autonomy · Information and Cyber Security · Advanced Software Engineering Methodologies
