Assessment of Automotive Attack Feasibility Methods in Comparison to Railway and Aviation Methods
摘要
An important part of the automotive cybersecurity risk assessment is the attack feasibility evaluation, which determines the effort an attacker needs to exploit an attack path. In our work, we systematically analyze the suggested attack feasibility methods across the automotive, railway, and aviation sectors. Our main focus is the suggested methods of the ISO/SAE 21434, which we compared with the performance of the methods suggested in the CLC/TS 50701 and DO-326A/DO-356A standards. The comparison was done by applying the suggested feasibility methods to real-life automotive cyberattacks. Through this, we demonstrate significant variability in feasibility assessments based on the method used. Our application of methods helps to understand how these methods actually perform on real-life attacks rather than theoretical constructs, and enables a comparison to realistic evaluations and other methods. Our findings highlight biases in existing methodologies and create recommendations for improving the methods we evaluated.