课题基金 / 基金详情

Feasibility study of Generative AI in Automotive Cybersecurity Threat Modelling

Feasibility study of Generative AI in Automotive Cybersecurity Threat Modelling
生成式人工智能在汽车网络安全威胁建模中的可行性研究
批准号:
10080056
负责人:
金额:
$6.35万
依托单位:
依托单位国家:
英国
项目类别:
Collaborative R&D
财政年份:
2023
资助国家:
英国
项目状态:
已结题
起止时间:
2023 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
由于AECS(自动、电动、互联和共享)技术的进步,运输业正在经历一场革命性的变革。这导致了汽车专用网络安全工具的一波创新浪潮。随着汽车变得越来越软件定义和连接,网络攻击的风险呈指数级上升,使汽车网络安全成为一个严峻的挑战。此外,汽车网络安全现在受到联合国欧洲经济委员会国家的监管,这进一步增加了该行业遵守国际标准化组织/SAE 21434标准、联合国欧洲经济委员会R155/R156法规的压力。未实施网络安全措施将导致2024年7月后失去市场准入。最近发布的ISO/SAE 21434标准包括第15条和第8条,这些条款描述了进行威胁和风险评估(TARA)和管理汽车产品漏洞的过程和要求。然而,这些标准并没有促进或强制使用特定的网络安全工具来进行风险评估和漏洞管理。目前汽车网络安全工具的状态是手动的、劳动密集型的、成本高昂的、缺乏自动化的,导致风险评估和威胁建模缓慢、无管理。随着数字化和以软件为导向的交通工具日益增多,网络安全变得至关重要。当前工具的不足要求解决方案满足监管标准,同时简化和自动化网络安全风险评估和威胁建模。Secure Elements Innovation CRISKLE是用于进行威胁和风险评估、漏洞管理和威胁建模的尖端软件即服务(SaaS)平台。CRISKLE自动化了ISO/SAE 21434标准第15条和第8条中概述的要求,集成了联合国欧洲经济委员会WP 29附件5中的威胁建模场景和基于项目需求的定制场景。然而,需要使用生成性人工智能来生成和自动化威胁库/场景,以增强CRISKLE的智能,以指导安全专业人员进行风险评估并基于新的威胁模型生成安全控制。通过将生成性人工智能集成到CRISKLE中,我们的目标是开发更有效的网络安全威胁模型。这项可行性研究提供了一个机会,探索生成性人工智能在交通(汽车)网络安全行业中尚未开发的潜力,超越生成威胁模型和安全控制的传统方法,从而提高和加速CRISKLE的有效性。通过这项可行性研究,我们将与生成性人工智能和汽车网络安全领域的领先专家合作,利用我们团队在这两个领域的专业知识。这项研究是将我们定位在交通网络安全革命前沿的关键一步,为向大众市场提供具有集成生成性人工智能能力的增强型网络安全工具解决方案铺平了道路。
英文摘要
The transportation industry is experiencing a revolutionary transformation due to advancements in AECS (autonomous, electric, connected, and shared) technology. This has led to a wave of innovations in automotive-specific cybersecurity tooling. As vehicles become increasingly software-defined and connected, the risk of cyber-attacks rises exponentially, making automotive cybersecurity a critical challenge. Moreover, automotive cybersecurity is now regulated in the UNECE countries, adding further pressure on the industry to comply with the ISO/SAE 21434 standard, UNECE R155/R156 regulation. Failure to implement cybersecurity measures will result in the loosing access to market after July 2024\.The recently published ISO/SAE 21434 standard includes clauses 15 and 8, which describe the process and requirements for conducting threat and risk assessments (TARA) and managing vulnerabilities for automotive products. However, the standards do not promote or mandate specific cybersecurity tools for conducting risk assessments and vulnerability management.The current state of automotive cybersecurity tooling is manual, labour-intensive, costly, and lacks automation, resulting in slow, unmanaged risk assessments and threat modelling. With increasing digitisation and software-oriented vehicles, cybersecurity becomes crucial. The inadequacy of the current tooling demands a solution that meets regulatory standards while streamlining and automating cybersecurity risk assessments and threat modelling.Secure Elements innovation CRISKLE, is a cutting-edge software as a service (SaaS) platform for conducting threat and risk assessments, vulnerability management and threat modelling. CRISKLE automates requirements outlined in Clause 15 and Clause 8 of the ISO/SAE 21434 standard, integrating threat modelling scenarios from UNECE WP 29 Annex 5 and customised scenarios based on project needs. However, there is a need to generate and automate threat libraries/scenarios using Generative AI to enhance CRISKLE's intelligence to guide security professionals in conducting risk assessments and generating security controls based on the new threat models.By integrating Generative AI in CRISKLE, we aim to develop more effective cybersecurity threat models.This feasibility study presents an opportunity to explore the untapped potential of Generative AI in the transportation (automotive) cybersecurity industry, moving beyond traditional methods of generating threat models and security controls thereby improving and accelerating the effectiveness of CRISKLE.Through this feasibility study, we will collaborate with leading experts in Generative AI and automotive cybersecurity, leveraging our team's expertise in both domains. This study is a crucial step in positioning ourselves at the forefront of the transportation cybersecurity revolution paving the way for enhanced cybersecurity tooling solutions with integrated Generative AI capability to be made available to mass market.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
Incentive and governance schenism study of corporate green washing behavior in China: Based on an integiated view of econfiguration of environmental authority and decoupling logic
  • 批准号:
    --
  • 项目类别:
    外国学者研究基金项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    YU BYUNGJUN
  • 依托单位:
糖尿病ED中成纤维细胞衰老调控内皮细胞线粒体稳态失衡的机制研究
  • 批准号:
    82371634
  • 项目类别:
    面上项目
  • 资助金额:
    49.00万元
  • 批准年份:
    2023
  • 负责人:
    赵福军
  • 依托单位:
酶响应的中性粒细胞外泌体载药体系在眼眶骨缺损修复中的作用及机制研究
  • 批准号:
    82371102
  • 项目类别:
    面上项目
  • 资助金额:
    49.00万元
  • 批准年份:
    2023
  • 负责人:
    苏蕴
  • 依托单位:
CBP/p300-HADH轴在基础胰岛素分泌调节中的作用和机制研究
  • 批准号:
    82370798
  • 项目类别:
    面上项目
  • 资助金额:
    49.00万元
  • 批准年份:
    2023
  • 负责人:
    王晓
  • 依托单位: