Conducting forensic investigations of cyber attacks on automobile in-vehicle networks

Conducting forensic investigations of cyber attacks on automobile in-vehicle networks
复制标题

对汽车车载网络的网络攻击进行取证调查

DOI:
10.4018/jdcf.2009040103
复制
发表时间:
2008
期刊:
Int. J. Digit. Crime Forensics
影响因子:
--
通讯作者:
Ulf Larson
Ulf Larson
中科院分区:
--
文献类型:
--
作者:
Dennis K. Nilsson;Ulf Larson

文献摘要

被引文献

相似文献

引入无线网关作为汽车车载网络的入口点,大大减少了执行诊断和固件更新的工作量。不幸的是,同样的网关也允许网络攻击针对未受保护的网络,目前缺乏适当的手段来检测和调查安全相关事件。在本文中,我们讨论了执行车载网络的数字取证调查的细节。分析了当前网络的特征,建立了攻击者模型。基于攻击者模型和一组普遍接受的取证调查原则,我们导出了检测、数据收集和事件重建的需求列表。然后,我们使用Brian Carrier的数字犯罪现场模型作为模板来说明这些要求如何影响调查。对于模型的每个阶段,我们展示了满足需求的好处和不遵守需求的影响。
The introduction of the wireless gateway as an entry point to an automobile in-vehicle network reduces the effort of performing diagnostics and firmware updates considerably. Unfortunately, the same gateway also allows cyber attacks to target the unprotected network, which currently lacks proper means for detecting and investigating security-related events. In this paper, we discuss the specifics of performing a digital forensic investigation of an in-vehicle network. An analysis of the current features of the network is performed, and an attacker model is developed. Based on the attacker model and a set of generally accepted forensic investigation principles, we derive a list of requirements for detection, data collection, and event reconstruction. We then use Brian Carrier's Digital Crime Scene Model as a template to illustrate how the requirements affect an investigation. For each phase of the model, we show the benefits of meeting the requirements and the implications of not complying with them.