Creating and sharing knowledge for telecommunications

Computing an Automotive Cybersecurity Maturity Level Assessment Programme

Grümer, P. ; Brandão, P.

Computing an Automotive Cybersecurity Maturity Level Assessment Programme, Proc ACM ACM Computer Science in Cars Symposium ACM CSCS, Darmstadt, Germany, Vol. , pp. - , December, 2023.

Digital Object Identifier: 10.1145/3631204.3631865

 

Abstract
Cybersecurity is key for the new and future vehicles that heavily rely on IT systems and depend on data exchange. These vehicles will bring countless new features and are potentially capable of autonomous driving. This paper studies and details a framework that uses the Common Vulnerability Scoring System (CVSS) for evaluating cybersecurity in the automotive world. We present a theoretical model to create a 5-grade rating system based on the CVSS for the Electronic Control Units (ECUs) of the vehicle. It will enable evaluating the cybersecurity quality of vehicles, so to establish a trustworthy and reliable environment. The model is based on Threat Analysis and Risk Assessment (TARA), Vulnerability Analysis and Risk Assessment (VARA), and Security Development Lifecycle (SDL) that is already used in the development of car components. Using such a system, will instigate the automotive industry to more heavily address cybersecurity.