Creating a Security Enforcement Environment for a Vehicular Platform
- 1. AEGIS IT RESEARCH GmbH, Braunschweig, Germany
- 2. Technical University of Munich, Munich, Germany
- 3. Technical University of Braunschweig, Braunschweig, Germany
Description
The ever-increasing complexity of automotive platforms combined with the introduction of commercial off-the-shelf software components (e.g., for the entertainment system) creates multiple attack vectors that adversaries can leverage to attack the platform. Traditional analysis techniques have difficulty dealing with such complex environments, especially considering the need for low-cost solutions. Hence, we propose in this paper to turn the logic around, and instead of trying to discover all possible vulnerabilities, we monitor the execution of a software system to ensure that it does not deviate from its nominal profile. In this paper, we demonstrate a technique for creating a state model mapping the execution of a system, and then by observing its interaction with the runtime environment through its invocation of various library functions, we can ensure that off-nominal behavior can be detected and acted upon. The valuation results provide further evidence of the wrapper mechanism's effectiveness and highlight its potential to enhance security while minimizing the impact on performance.
Notes (English)
Files
Tsantekidis_et_al_CSCN2023.pdf
Files
(557.2 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:5b2ed3973a903c36672e1a3f09c575c2
|
557.2 kB | Preview Download |
Additional details
Identifiers
Funding
- European Commission
- SecOPERA - Secure OPen source softwarE and hardwaRe Adaptable framework 101070599
- European Commission
- CyberSecDome - An innovative Virtual Reality based intrusion detection, incident investigation and response approach for enhancing the resilience, security, privacy and accountability of complex and heterogeneous digital systems and infrastructures 101120779
- European Commission
- Joint Cybersecurity Operations Platform (JCOP) INEA/CEF/ICT/A2020/2373266
- European Commission
- Cyber Security Competence Development (CyberSecPro) 101083594