课题基金 / 基金详情

VPTaaS: Cyber Penetration Test as a Service for Future Vehicles

VPTaaS: Cyber Penetration Test as a Service for Future Vehicles
VPTaaS:网络渗透测试作为未来车辆的服务
批准号:
10076995
负责人:
金额:
$4.08万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2023
资助国家:
英国
项目状态:
已结题
起止时间:
2023 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
汽车行业正面临着来自网络犯罪的日益增长的威胁,2015年因安全相关问题召回了140万辆汽车,以及2020年6月因勒索软件攻击而导致北美工厂停产。因此,对于汽车制造商和车主来说,采取积极措施保护其车辆免受网络威胁至关重要,例如实施强大的安全措施和程序,作为车辆服务的一部分定期进行网络健康检查,以及进行渗透测试。然而,目前的渗透测试服务通常覆盖范围不完整,测试环境有限,时间限制,成本高,假阳性和假阴性,以及有限的测试范围。为了满足这一需求,该提案提出了仅针对车辆的渗透测试即服务(VPTaaS),旨在检测和响应车辆内部和周围的网络安全事件,包括收集和分析日志事件数据,响应安全事件,并调查异常的根本原因。此外,VPTaaS还将提供有关网络安全和软件更新实践及其各自行业标准的实施支持、评估、证明和认证服务,以及鼓励白帽黑客报告他们发现的漏洞的激励和奖励计划。
英文摘要
The automotive industry is facing an ever-growing threat from cybercrime, as evidenced by the 1.4 million vehicles recalled in 2015 due to security-related issues, and the halt in production across North American plants in June 2020 due to ransomware attacks. Thus, it is essential for vehicle manufacturers as well as vehicle owner to take proactive steps to protect their vehicles from cyber threats, such as implementing robust security measures and procedures, performing periodic cyber health-checks as part of vehicular servicing, and conducting penetration testing.However, current penetration testing services often have incomplete coverage, limited testing environments, time constraints, high costs, false positives and negatives, and limited scope of testing. To address this need, this proposal puts forth a Penetration Test as a Service (VPTaaS) specialized only for vehicles, designed to detect and respond to cybersecurity events in and around vehicles, including the collection and analysis of log event data, responding to security events, and investigating root causes of anomalies. Additionally, VPTaaS will offer implementation support, assessment, attestation, and certification services with respect to cybersecurity and software-update practices and their respective industry standards, as well as incentive and reward programs to encourage white-hat hackers to report vulnerabilities they discover.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
Cyber体系脆弱性仿真分析方法研究
  • 批准号:
    61403400
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    24.0万元
  • 批准年份:
    2014
  • 负责人:
    许相莉
  • 依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
  • 批准号:
    61374179
  • 项目类别:
    面上项目
  • 资助金额:
    77.0万元
  • 批准年份:
    2013
  • 负责人:
    胡晓峰
  • 依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
  • 批准号:
    61300132
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    23.0万元
  • 批准年份:
    2013
  • 负责人:
    王竹晓
  • 依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
  • 批准号:
    61174035
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2011
  • 负责人:
    贺筱媛
  • 依托单位: