https://www.mdu.se/

mdu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Social Engineering Exploits in Automotive Software Security: Modeling Human-targeted Attacks with SAM
Technische Hochschule Nürnberg, Germany. (DPAC)ORCID iD: 0000-0002-2941-7948
Mälardalen University, School of Innovation, Design and Engineering, Embedded Systems. Technische Hochschule Nürnberg, Germany. (DPAC)
MetaCase.
Friedrich Alexander Universität Erlangen, Germany.
2021 (English)In: Proceedings of the 31th European Safety and Reliability Conference / [ed] Bruno Castanier, Marko Cepin, David Bigaud and Christophe Berenguer, Singapore: Research Publishing Services, 2021Conference paper, Published paper (Refereed)
Abstract [en]

Security cannot be implemented into a system retrospectively without considerable effort, so security must be takeninto consideration already at the beginning of the system development. The engineering of automotive softwareis by no means an exception to this rule. For addressing automotive security, the AUTOSAR and EAST-ADLstandards for domain-specific system and component modeling provide the central foundation as a start. The EASTADLextension SAM enables fully integrated security modeling for traditional feature-targeted attacks. Due to theCOVID-19 pandemic, the number of cyber-attacks has increased tremendously and of these, about 98 percent arebased on social engineering attacks. These social engineering attacks exploit vulnerabilities in human behaviors,rather than vulnerabilities in a system, to inflict damage. And these social engineering attacks also play a relevantbut nonetheless regularly neglected role for automotive software. The contribution of this paper is a novel modelingconcept for social engineering attacks and their criticality assessment integrated into a general automotive softwaresecurity modeling approach. This makes it possible to relate social engineering exploits with feature-related attacks.To elevate the practical usage, we implemented an integration of this concept into the established, domain-specificmodeling tool MetaEdit+. The tool support enables collaboration between stakeholders, calculates vulnerabilityscores, and enables the specification of security objectives and measures to eliminate vulnerabilities.

Place, publisher, year, edition, pages
Singapore: Research Publishing Services, 2021.
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:mdh:diva-62428DOI: 10.3850/981-973-0000-00-0OAI: oai:DiVA.org:mdh-62428DiVA, id: diva2:1755772
Conference
ESREL2021
Available from: 2023-05-09 Created: 2023-05-09 Last updated: 2023-05-12Bibliographically approved
In thesis
1. Extending and Improving the Security Abstraction Model for Architectural Models of Autonomous Vehicles
Open this publication in new window or tab >>Extending and Improving the Security Abstraction Model for Architectural Models of Autonomous Vehicles
2023 (English)Licentiate thesis, comprehensive summary (Other academic)
Place, publisher, year, edition, pages
Västerås: Mälardalens universitet, 2023
Series
Mälardalen University Press Licentiate Theses, ISSN 1651-9256 ; 343
National Category
Software Engineering
Research subject
Computer Science
Identifiers
urn:nbn:se:mdh:diva-62550 (URN)978-91-7485-600-2 (ISBN)
Presentation
2023-06-19, room Case, Mälardalens universitet, Västerås, 13:15 (English)
Opponent
Supervisors
Available from: 2023-05-12 Created: 2023-05-12 Last updated: 2023-05-29Bibliographically approved

Open Access in DiVA

fulltext(360 kB)117 downloads
File information
File name FULLTEXT01.pdfFile size 360 kBChecksum SHA-512
9aa2ac4f3c8920d4775f66f257ad601555252fe5584693077b673a5e2a3d5aa798c9b42719845b6e86d452813df832be21ef272528c93e50ba1286f97e098cc4
Type fulltextMimetype application/pdf

Other links

Publisher's full text

Authority records

Bergler, Matthias

Search in DiVA

By author/editor
Bergler, Matthias
By organisation
Embedded Systems
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 117 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 304 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf