Skip to main content
QUICK REVIEW

[论文解读] Vehicle Security: Risk Assessment in Transportation

Kaveh Bakhsh Kelarestaghi, Foruhandeh, Mahsa|arXiv (Cornell University)|Apr 19, 2018
Vehicular Ad Hoc Networks (VANETs)Engineering参考文献 29被引用 17
一句话总结

本文提出了一种针对智能交通系统(ITS)中车载网络的风险驱动型漏洞评估框架,识别出可能危及安全、隐私和系统完整性的网络威胁。通过聚合个体风险并使用影响-可能性矩阵,该研究量化了系统级风险,并为政策制定者和工程师提供了可操作的见解。

ABSTRACT

Intelligent Transportation Systems (ITS) are critical infrastructure that are not immune to both physical and cyber threats. Vehicles are cyber/physical systems which are a core component of ITS, can be either a target or a launching point for an attack on the ITS network. Unknown vehicle security vulnerabilities trigger a race among adversaries to exploit the weaknesses and security experts to mitigate the vulnerability. In this study, we identified opportunities for adversaries to take control of the in-vehicle network, which can compromise the safety, privacy, reliability, efficiency, and security of the transportation system. This study contributes in three ways to the literature of ITS security and resiliency. First, we aggregate individual risks that are associated with hacking the in-vehicle network to determine system-level risk. Second, we employ a risk-based model to conduct a qualitative vulnerability-oriented risk assessment. Third, we identify the consequences of hacking the in-vehicle network through a risk-based approach, using an impact-likelihood matrix. The qualitative assessment communicates risk outcomes for policy analysis. The outcome of this study would be of interest and usefulness to policymakers and engineers concerned with the potential vulnerabilities of the critical infrastructures.

研究动机与目标

  • 识别并评估针对车载网络的网络威胁,这些威胁可能危及交通系统的安全性和可靠性。
  • 通过聚合车载网络中的个体漏洞,构建系统级风险模型。
  • 采用定性风险驱动方法,评估车载网络被利用的可能性和潜在影响。
  • 通过结构化的影响-可能性矩阵,向政策制定者和工程师传达风险结果,以支持政策与工程决策。

提出的方法

  • 将车载网络漏洞带来的个体网络风险聚合为系统级风险评估。
  • 采用定性风险驱动模型,基于威胁的可能性和潜在影响评估其风险。
  • 使用影响-可能性矩阵对不同攻击场景的风险水平进行分类与可视化。
  • 聚焦于智能交通系统(ITS)中网络/物理系统的漏洞。
  • 开展以漏洞为导向的风险评估,以识别攻击向量及其后果。
  • 将研究成果整合进面向政策相关方的风险沟通框架中。

实验结果

研究问题

  • RQ1在智能交通系统中,哪些是可能危及车载网络的主要网络威胁?
  • RQ2如何将个体车载网络风险聚合,以评估整体系统级风险?
  • RQ3车载网络被利用对交通系统安全性和可靠性的影响与可能性如何?
  • RQ4风险驱动方法如何有效向政策制定者和工程师传达威胁后果?
  • RQ5哪些关键漏洞可能使攻击者能够控制车辆网络?

主要发现

  • 车载网络易受网络攻击影响,可能危及安全性、隐私性、可靠性及系统效率。
  • 研究表明,未知安全漏洞导致攻击者与安全专家之间展开一场争夺,即谁先利用风险或加以缓解。
  • 通过基于风险的模型聚合个体风险因素,可有效量化系统级风险。
  • 影响-可能性矩阵为政策与工程决策提供了清晰的定性风险结果可视化。
  • 该框架使利益相关方能够根据潜在影响和被利用的可能性,优先处理漏洞。
  • 研究结果可直接应用于通过主动风险管理提升智能交通系统的韧性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。