Published December 7, 2023 | Version v1
Conference paper Open

Creating a Security Enforcement Environment for a Vehicular Platform

  • 1. AEGIS IT RESEARCH GmbH, Braunschweig, Germany
  • 2. Technical University of Munich, Munich, Germany
  • 3. Technical University of Braunschweig, Braunschweig, Germany

Description

The ever-increasing complexity of automotive platforms combined with the introduction of commercial off-the-shelf software components (e.g., for the entertainment system) creates multiple attack vectors that adversaries can leverage to attack the platform. Traditional analysis techniques have difficulty dealing with such complex environments, especially considering the need for low-cost solutions. Hence, we propose in this paper to turn the logic around, and instead of trying to discover all possible vulnerabilities, we monitor the execution of a software system to ensure that it does not deviate from its nominal profile. In this paper, we demonstrate a technique for creating a state model mapping the execution of a system, and then by observing its interaction with the runtime environment through its invocation of various library functions, we can ensure that off-nominal behavior can be detected and acted upon. The valuation results provide further evidence of the wrapper mechanism's effectiveness and highlight its potential to enhance security while minimizing the impact on performance.

Notes (English)

This work is supported by the following European Union-funded projects: a) JCOP (Agreement No.: INEA/CE- F/ICT/A2020/2373266), b) CyberSecPro (Agreement No.: 101083594), c) SecOPERA (Agreement No.: 101070599) and d) CyberSecDome (Agreement No.: 101120779).

Files

Tsantekidis_et_al_CSCN2023.pdf

Files (557.2 kB)

Name Size Download all
md5:5b2ed3973a903c36672e1a3f09c575c2
557.2 kB Preview Download

Additional details

Funding

European Commission
SecOPERA - Secure OPen source softwarE and hardwaRe Adaptable framework 101070599
European Commission
CyberSecDome - An innovative Virtual Reality based intrusion detection, incident investigation and response approach for enhancing the resilience, security, privacy and accountability of complex and heterogeneous digital systems and infrastructures 101120779
European Commission
Joint Cybersecurity Operations Platform (JCOP) INEA/CEF/ICT/A2020/2373266
European Commission
Cyber Security Competence Development (CyberSecPro) 101083594