Browse Publications Technical Papers 2021-01-0183

Deep Learning Based Real Time Vulnerability Fixes Verification Mechanism for Automotive Firmware/Software 2021-01-0183

Software vulnerability management is one of the most critical and crucial security techniques, which analyzes the automotive software/firmware across the digital cockpit, ADAS, V2X, etc. domains for vulnerabilities, and provides security patches for the concerned Common Vulnerabilities and Exposures (CVE). The process of automotive SW/FW vulnerability management system between the OEMs and vendors happen through a channel of fixing a certain number of vulnerabilities by 1st tier supplier which needs to be verified in front of OEMs for the fixed number and type of patches in there deliverable SW/FW. The gap of verification between for the fixed patches between the OEMs and 1st tier supplier requires a reliable human independent intelligent technique to have a trustworthiness of verification. Hence, in this regard, a novel machine learning based intelligent verification technique is proposed which is free from human intervention to verify the certain number and type of vulnerabilities fixes in the embedded binary image. The technique involves training the machine learning models for software/firmware patched binaries and inferring the application of patches on the verification binary image by using the trained machine-learning model. The technique verifies the vulnerability fixes for all the given number of vulnerabilities in a given package from the whole binary image. Hence, the proposed approach resolves the vulnerability patches verification issue using an intelligent artificial intelligence-based technique among OEMs and 1st tier supplier, which is free from human interference.


Subscribers can view annotate, and download all of SAE's content. Learn More »


Members save up to 16% off list price.
Login to see discount.
Special Offer: Download multiple Technical Papers each year? TechSelect is a cost-effective subscription option to select and download 12-100 full-text Technical Papers per year. Find more information here.