A Study of The Risk Quantification Method of Cyber-Physical Systems focusing on Direct-Access Attacks to In-Vehicle Networks.

IEICE Trans. Fundam. Electron. Commun. Comput. Sci.(2023)

引用 0|浏览3
暂无评分
摘要
Cyber-physical systems, in which ICT systems and field devices are interconnected and interlocked, have become widespread. More threats need to be taken into consideration when designing the secu-rity of cyber-physical systems. Attackers may cause damage to the physical world by attacks which exploit vulnerabilities of ICT systems, while other attackers may use the weaknesses of physical boundaries to exploit ICT systems. Therefore, it is necessary to assess such risks of attacks properly. A direct-access attack in the field of automobiles is the latter type of at-tacks where an attacker connects unauthorized equipment to an in-vehicle network directly and attempts unauthorized access. But it has been consid-ered as less realistic and evaluated less risky than other threats via network entry points by conventional risk assessment methods. We focused on re-assessing threats via direct access attacks in proposing effective security design procedures for cyber-physical systems based on a guideline for au-tomobiles, JASO TP15002. In this paper, we focus on "fitting to a specific area or viewpoint" of such a cyber-physical system, and devise a new risk quantification method, RSS-CWSS CPS based on CWSS, which is also a vulnerability evaluation standard for ICT systems. It can quantify the char-acteristics of the physical boundaries in cyber-physical systems.
更多
查看译文
关键词
risk quantification method,cyber-physical,direct-access,in-vehicle
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要