A survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends is presented and several security recommendations for software engineering teams are provided based on the findings.
Abstract
The increased level of connectivity for vehicles leads to sophisticated and challenging software security concerns for automotive Original Equipment Manufacturers (OEMs) and suppliers. With a Connected Vehicle (CV) communicating with multiple entities (road infrastructure, other vehicles, OEMs, cloud, etc.), new attack surfaces are exposed to intruders. For instance, in 2023, ethical hackers demonstrated remote access to critical vehicle controls like steering and braking through vulnerabilities in infotainment and telematics systems. Several OEMs also reported production disruptions due to ransomware targeting software development infrastructure. Additionally, the current state of the art fails to provide a holistic view of a secure software development process for CVs. This paper presents a survey of automotive software vulnerabilities and associated attack vectors and analyzes the significant changes in security trends. Moreover, the vulnerabilities are tracked across the Software Development Life Cycle (SDLC). We include 413 new automotive software vulnerabilities identified within the last 2 years and 9 months in our study. Additionally, 20 automotive software repositories with 827 vulnerable libraries are identified by scanning sources such as repositories, SBOMs (Software Bill of Materials), images, and manifest files. We provide several security recommendations for software engineering teams based on the findings. Our findings are a step forward to support the maintenance of automotive software quality in terms of security across its entire life cycle.
A layered test architecture tailored for ECM applications is constructed, security risks of the XCP protocol under unauthenticated and weak-permission scenarios are identified, and engineering-oriented mitigation strategies are proposed.
Ruo-Fei Xing, Ke-Xun He, Bai-Zheng Wang et al.· International Conference on...· 0 citations
Connected and Autonomous Vehicles (CAVs) with Vehicle-to-Everything (V2X) communication are transforming transportation systems, but their increasing connectivity and automation introduce critical challenges where safety and cybersecurity intersect. Traditional approaches treat safety analysis through Hazard Analysis a...
Chaima Zaghouani, Mohamed K. Elhadad, Hakim Ghazzai et al.· IEEE Open Journal of Intelli...· 0 citations
Cybersecurity has become one of the most critical challenges in the intelligent and connected vehicle ecosystem of today. As modern vehicles become increasingly connected and intelligent, the frequency and sophistication of cyberattacks targeting automotive systems continue to grow at an alarming rate. Ensuring robust...
Farshideh Kordi, Paul Fortier, A. Miled· Italian National Conference...· 0 citations
The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins, and provide the identification of research gaps and recommendations on creation of new tools.
Ebtesam S. Alqahtani, Mohammad Hammoudeh· 0 citations
Industrial Control Systems (ICS) form the backbone of critical infrastructure, enabling automation and control in sectors such as energy, water, and manufacturing. The convergence of Operational Technology (OT) and Information Technology (IT) has introduced significant cybersecurity challenges, particularly for legacy...
Lukumba Phiri, Mukubesa Kamutumwa· International Journal of App...· 0 citations