Formalising UPTANE in CSP for Security Testing
Formalising UPTANE in CSP for Security Testing
复制标题
在 CSP 中正式化 UPTANE 以进行安全测试
DOI:
10.1109/qrs-c55045.2021.00124
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
David Price
中科院分区:
文献类型:
--
作者:
Rhys Kirk;N. H. Nga;J. Bryans;S. Shaikh;D. Evans;David Price
Modern vehicles are susceptible to cybersecurity attacks due to the complexity of their electronics architecture and a progressive integration of connectivity technologies. A promising solution to resolve cybersecurity issues is Over-The-Air (OTA) updates. Recently, Uptane has been introduced and is currently considered as the de facto security standard for automotive OTA system solutions. To ensure that a system, Uptane, can deliver updates to secure a vehicle, the system itself must be sufficiently secure as to not become an attack vector itself. To this end, we present a model-based security testing approach to OTA updates for automotive vehicles. This is done by modelling the OTA update system and the Dolev-Yao attackers in Communicating Sequential Processes (CSP). The combined models can be verified to generate security test cases and provide a comprehensive evaluation of attackers on the Uptane system.