Browse Publications Technical Papers 11-01-02-0005
2018-11-02

Enhancement of Automotive Penetration Testing with Threat Analyses Results 11-01-02-0005

This also appears in SAE International Journal of Transportation Cybersecurity and Privacy-V127-11EJ

In this work, we present an approach to support penetration tests by combining safety and security analyses to enhance automotive security testing. Our approach includes a new way to combine safety and threat analyses to derive possible test cases. We reuse outcomes of a performed safety analysis as the input for a threat analysis. We show systematically how to derive test cases, and we present the applicability of our approach by deriving and performing test cases for a penetration test of an automotive electronic control unit (ECU). Therefore, we selected an airbag control unit due to its safety-critical functionality. During the penetration test, the selected control unit was installed on a test bench, and we were able to successfully exploit a discovered vulnerability, causing the detonation of airbags.

SAE MOBILUS

Subscribers can view annotate, and download all of SAE's content. Learn More »

Access SAE MOBILUS »

Members save up to 19% off list price.
Login to see discount.
We also recommend:
TECHNICAL PAPER

Hardware/Software Co-Design of an Automotive Embedded Firewall

2017-01-1659

View Details

STANDARD

V2X Communications Message Set Dictionary

J2735_202211

View Details

TECHNICAL PAPER

Model Based Development of Automotive Human Machine Interfaces

2004-21-0019

View Details

X