Proposing HEAVENS 2.0 – an automotive risk assessment model

Aljoscha Lautenbach, M. Almgren, T. Olovsson
{"title":"Proposing HEAVENS 2.0 – an automotive risk assessment model","authors":"Aljoscha Lautenbach, M. Almgren, T. Olovsson","doi":"10.1145/3488904.3493378","DOIUrl":null,"url":null,"abstract":"Risk-based security models have seen a steady rise in popularity over the last decades, and several security risk assessment models have been proposed for the automotive industry. The new UN vehicle regulation 155 on cybersecurity provisions for vehicle type approval, as part of the 1958 agreement on vehicle harmonization, mandates the use of risk assessment to mitigate cybersecurity risks and is expected to be adopted into national laws in 54 countries within 1 to 3 years. This new legislation will also apply to autonomous vehicles. The automotive cybersecurity engineering standard ISO/SAE 21434 is seen as a way to fulfill the new UN legislation, so we can expect quick and wide industry adoption. One risk assessment model that has gained some popularity and is in active use in several companies is the HEAVENS model, but since ISO/SAE 21434 introduces additional requirements on the risk assessment process, the original HEAVENS model does not fulfill the standard. In this paper, we investigate the gap between the HEAVENS risk assessment model and ISO/SAE 21434, and we identify and propose 12 model updates to HEAVENS to close this gap. We also discuss identified weaknesses of the HEAVENS risk assessment model and propose 5 additional model updates to overcome them. In accordance with these 17 identified model updates, we propose HEAVENS 2.0, a new risk assessment model based on HEAVENS which is fully compliant with ISO/SAE 21434.","PeriodicalId":332312,"journal":{"name":"Proceedings of the 5th ACM Computer Science in Cars Symposium","volume":"92 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-11-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 5th ACM Computer Science in Cars Symposium","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3488904.3493378","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Risk-based security models have seen a steady rise in popularity over the last decades, and several security risk assessment models have been proposed for the automotive industry. The new UN vehicle regulation 155 on cybersecurity provisions for vehicle type approval, as part of the 1958 agreement on vehicle harmonization, mandates the use of risk assessment to mitigate cybersecurity risks and is expected to be adopted into national laws in 54 countries within 1 to 3 years. This new legislation will also apply to autonomous vehicles. The automotive cybersecurity engineering standard ISO/SAE 21434 is seen as a way to fulfill the new UN legislation, so we can expect quick and wide industry adoption. One risk assessment model that has gained some popularity and is in active use in several companies is the HEAVENS model, but since ISO/SAE 21434 introduces additional requirements on the risk assessment process, the original HEAVENS model does not fulfill the standard. In this paper, we investigate the gap between the HEAVENS risk assessment model and ISO/SAE 21434, and we identify and propose 12 model updates to HEAVENS to close this gap. We also discuss identified weaknesses of the HEAVENS risk assessment model and propose 5 additional model updates to overcome them. In accordance with these 17 identified model updates, we propose HEAVENS 2.0, a new risk assessment model based on HEAVENS which is fully compliant with ISO/SAE 21434.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
提出 HEAVENS 2.0--汽车风险评估模型
过去几十年来,基于风险的安全模型逐渐流行起来,并为汽车行业提出了多个安全风险评估模型。作为 1958 年车辆协调协议的一部分,新的联合国车辆法规 155 涉及车辆类型批准的网络安全规定,强制要求使用风险评估来降低网络安全风险,预计将在 1 到 3 年内被 54 个国家的国家法律所采纳。这项新立法也将适用于自动驾驶汽车。汽车网络安全工程标准 ISO/SAE 21434 被认为是履行联合国新立法的一种方式,因此我们可以期待行业快速、广泛地采用这一标准。HEAVENS 模型是一种风险评估模型,该模型已在一些公司得到广泛应用,但由于 ISO/SAE 21434 对风险评估流程提出了额外要求,因此最初的 HEAVENS 模型并不符合标准。在本文中,我们研究了 HEAVENS 风险评估模型与 ISO/SAE 21434 之间的差距,并确定和提出了 12 项 HEAVENS 模型更新,以弥补这一差距。我们还讨论了 HEAVENS 风险评估模型的不足之处,并提出了 5 项额外的模型更新以克服这些不足之处。根据这 17 项已确定的模型更新,我们提出了 HEAVENS 2.0,这是一个基于 HEAVENS 的新风险评估模型,完全符合 ISO/SAE 21434 标准。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Comparison of De-Identification Techniques for Privacy Preserving Data Analysis in Vehicular Data Sharing Improved Sensor Model for Realistic Synthetic Data Generation Proposing HEAVENS 2.0 – an automotive risk assessment model Following the White Rabbit: Integrity Verification Based on Risk Analysis Results Real-time Uncertainty Estimation Based On Intermediate Layer Variational Inference
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1