Authors:
Yuri Dantas
1
;
Simon Barner
2
;
Pei Ke
3
;
Vivek Nigam
3
and
Ulrich Schöpp
1
Affiliations:
1
Fortiss GmbH, Munich, Germany
;
2
Huawei Technologies Düsseldorf GmbH, Düsseldorf, Germany
;
3
fortiss GmbH, Munich, Germany
Keyword(s):
Automotive, Threat Analysis, Service-Oriented Architectures, Automation, Safe, Secure-by-Design.
Abstract:
This article proposes automated methods for threat analysis using a model-based engineering methodology that provides precise guarantees with respect to safety goals. This is accomplished by proposing an intruder model for automotive SOA which together with the system architecture and the loss scenarios identified by safety analysis are used as input for computing assets, impact rating, damage/threat scenarios, and attack paths. To validate the proposed methodology, we developed a faithful model of the autonomous driving functions of the Apollo framework, a widely used open source autonomous driving stack. The proposed machinery automatically enumerates several attack paths on Apollo, including attack paths not reported in the literature.