Technical Report: Automating Vehicle SOA Threat Analysis using a Model-Based Methodology
Yuri Gil Dantas, Simon Barner, Pei Ke, Vivek Nigam, Ulrich, Schoepp

TL;DR
This paper introduces an automated, model-based approach for vehicle threat analysis in SOA environments, enhancing security guarantees and enabling systematic attack path enumeration, validated on the Apollo autonomous driving system.
Contribution
It presents a novel automated threat analysis methodology using a model-based engineering approach with an intruder model for automotive SOA systems.
Findings
Automatically enumerates attack paths on Apollo
Identifies attack paths not previously reported
Provides precise security guarantees with respect to safety goals
Abstract
While the adoption of Service-Oriented Architectures (SOA) eases the implementation of features such as autonomous driving and over-the-air updates, it also increases the vehicle's exposure to attacks that may place road-users in harm. To address this problem, standards (ISO 21434/UNECE) expect manufacturers to produce security arguments and evidence by carrying out appropriate threat analysis. As key threat analysis steps, e.g., damage/threat scenario and attack path enumeration, are often carried out manually and not rigorously, security arguments lack precise guarantees, e.g., traceability w.r.t. safety goals, especially under system updates. This article proposes automated methods for threat analysis using a model-based engineering methodology that provides precise guarantees with respect to safety goals. This is accomplished by proposing an intruder model for automotive SOA which…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Safety Systems Engineering in Autonomy · Advanced Software Engineering Methodologies
