Overview of Attack Graph Generation For Automotive Systems
Mera Nizam-Edden Saulaiman, Miklos Kozlovszky, Á. Csilling, Anna Bánáti, Abdallah Benhamida · 2022
Modern vehicles of today integrate new services and advanced functionalities to bring comfort and safety features to the driver and passengers. As these vehicles are connected to external networks, they are similar to an Internet of Things device (IoT). The legacy definition of automotive security focuses on the safety of the vehicle, preventing physical attacks on the vehicle, but like an IOT device, the connected vehicle now has a wide attack surface that enables new, even remote attacks with serious consequences on the safety and security of the driver. Attack graphs are an efficient tool to automatically analyze security vulnerabilities in a system, it’s widely used in the IT domain but not so popular in the Automotive domain because of the high complexity of the automotive network.Currently defining assets and threat scenarios is done manually by experts in the automotive domain, which is a tedious and error-prone process. Increasing the automation of this process is necessary for efficient vehicle security assessment. In this paper, we will discuss The idea of an automated attack graph generation tool for Threat analysis in the automotive domain. We evaluate open-source attack analysis methodologies and frameworks from the IT domain that already provide automation to this critical task, define a general model, and map the concepts to the automotive domain.