Cybersecurity risk analysis of an automated driving system

  • New laws and technologies, but also persistent problems like truck driver shortage, have led to advances in the field of autonomous driving and consequently to new cyberrisks. We present the results of our cyber security risk analysis for a Control Center-supervised Level 4 Automated Driving System (ADS), whose system model we created through expert interviews with a global truck manufacturer. Example damage scenarios with high impact rating include Disclosure of video data, Loss of ADS function in motion, Dangerous driving maneuvers, and Activation outside of Operational Design Domain. We have identified over 200 threat scenarios, consisting of a combination of main attack steps that threaten specific parts of the item and preparation steps that determine how these parts are accessed and by which type of attacker. Without taking controls into account, the realization of these threat scenarios results in 65 significant risks. We propose to treat the threat scenarios, on the one hand, by claims concerning implementation-relevant aspects as Detection of system failure and security controls such as Authentic transmission of data. We conclude by detailing principles we have extracted from our analysis that can be applied to other cyber security risk analyses of automated driving systems.

Download full text files

Export metadata

Additional Services

Share in Twitter Search Google Scholar
Metadaten
Author:Patrick WagnerORCiDGND, Nikolai PuchORCiDGND, David EmeisORCiDGND
URN:urn:nbn:de:hbz:294-103919
DOI:https://doi.org/10.13154/294-10391
Parent Title (English):21th escar Europe : The World's Leading Automotive Cyber Security Conference (Hamburg, 15. - 16.11.2023)
Document Type:Part of a Book
Language:English
Date of Publication (online):2023/10/25
Date of first Publication:2023/10/25
Publishing Institution:Ruhr-Universität Bochum, Universitätsbibliothek
Tag:Automated Driving; Cyber Security; Logistics; Risk Analysis; Truck
Pagenumber:15
Dewey Decimal Classification:Allgemeines, Informatik, Informationswissenschaft / Informatik
open_access (DINI-Set):open_access
Konferenz-/Sammelbände:21th escar Europe : The World's Leading Automotive Cyber Security Conference
Licence (German):License LogoKeine Creative Commons Lizenz - es gelten die Rechteeinräumung und das deutsche Urheberrecht