2015Unpublished venueRequires access

Testing and Evaluation to Improve Data Security of Automotive Embedded Systems

Johannes Weschke, Filip Hesslund

Open publisher page 2 citations

Abstract

In the last two decades, the number of electronic control units (ECUs) in vehicles has increased dramatically. This has resulted in an increased complexity of the vehicles electrical and electronic systems. Electrical and electronic systems have gone from just controlling the engine to controlling every part of the vehicle, from the infotainment system to safety-critical systems. To allow for better collaboration between players in the automotive industry, a development partnership called AUTOSAR has emerged. Included in AUTOSAR is a module handling diagnostics (DCM). The module can be used to read data and change parameters in the ECUs and in the ECU software, since the DCM can access con dential information about the vehicle and modify running software of the ECU, for example the software controlling the engine, it is an attractive target for adversaries. There has been no published research about the security of the DCM module of the AUTOSAR software architecture (that we know of) and how the safety of the passengers can be a ected in the case of a security breach. This thesis tries to ll this research gap by conducting a threat analysis and risk assessment for the DCM module inside AUTOSAR. This thesis evaluates the security of an ECU assumed to control the engine of a vehicle and how possible consequences of an intrusion can a ect the overall safety. It also presents a number of tests used to evaluate the threats and risks found. The tests done targets threats regarding denial of service, tampering, and information disclosure. The thesis is concluded with proposing countermeasures for the threats and risks.

About this research paper

What this paper is about

In the last two decades, the number of electronic control units (ECUs) in vehicles has increased dramatically. This has resulted in an increased complexity of the vehicles electrical and electronic systems. Electrical and electronic systems have gone from just controlling the engine to controlling every part of the vehicle, from the infotainment system to safety-critical systems. To allow for better collaboration between players in the automotive industry, a development partnership called AUTOSAR has emerged. Included in AUTOSAR is a module handling diagnostics (DCM). The module can be used to read data and change parameters in the ECUs and in the ECU software, since the DCM can access con dential information about the vehicle and modify running software of the ECU, for example the software controlling the engine, it is an attractive target for adversaries. There has been no published research about the security of the DCM module of the AUTOSAR software architecture (that we know of) and how the safety of the passengers can be a ected in the case of a security breach. This thesis tries to ll this research gap by conducting a threat analysis and risk assessment for the DCM module inside AUTOSAR. This thesis evaluates the security of an ECU assumed to control the engine of a vehicle and how possible consequences of an intrusion can a ect the overall safety. It also presents a number of tests used to evaluate the threats and risks found. The tests done targets threats regarding denial of service, tampering, and information disclosure. The thesis is concluded with proposing countermeasures for the threats and risks.

Why it matters

OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In the last two decades, the number of electronic control units (ECUs) in vehicles has increased dramatically. This has resulted in an increased complexity of the vehicles electrical and electronic systems. Electrical and electronic systems have gone from just controlling the engine to controlling every part of the vehicle, from the infotainment system to safety-critical systems. To allow for better collaboration between players in the automotive industry, a development partnership called AUTOSAR has emerged. Included in AUTOSAR is a module handling diagnostics (DCM). The module can be used to read data and change parameters in the ECUs and in the ECU software, since the DCM can access con dential information about the vehicle and modify running software of the ECU, for example the software controlling the engine, it is an attractive target for adversaries. There has been no published research about the security of the DCM module of the AUTOSAR software architecture (that we know of) and how the safety of the passengers can be a ected in the case of a security breach. This thesis tries to ll this research gap by conducting a threat analysis and risk assessment for the DCM module inside AUTOSAR. This thesis evaluates the security of an ECU assumed to control the engine of a vehicle and how possible consequences of an intrusion can a ect the overall safety. It also presents a number of tests used to evaluate the threats and risks found. The tests done targets threats regarding denial of service, tampering, and information disclosure. The thesis is concluded with proposing countermeasures for the threats and risks.

Key concepts: AUTOSAR, Electronic control unit, Computer security, Denial-of-service attack, Engineering, Software, Automotive industry, Embedded system

Related papers

Back to paper searchBrowse research topicsOriginal source
Testing and Evaluation to Improve Data Security of Automotive Embedded Systems — Research Paper | ScholarLens