Systematic Vulnerability Assessment: Mapping Architecture Flow and Ranking Components for Vulnerability in Connected Automated Vehicles
摘要
Connected and autonomous vehicles (CAVs) are becoming increasingly integral to modern transportation systems, and ensuring their cybersecurity is of paramount importance. In this paper, we present a comprehensive architectural flow of a CAV, encompassing various components such as entry systems, Control Area Networks (CANs), Sensor fusion and gateway Electronic Control Unit (ECU), On-Board Diagnostics (OBD), In-Vehicle Infotainment System (IVI), GPS, cameras and sensors, power train, and chassis systems. A scoring criterion is defined based on five attributes—accessibility, impact, types of attack that can happen, defense or countermeasure available, and number of attacks that can happen. Scores for major components are assigned based on the criteria. The scores are useful in determining how vulnerable each component is. The study indicates that the most vulnerable component is the ECU. Many of critical components, such as the engines and chassis systems, are connected to the ECU. This is the primary cause of the CAV cyberattacks. The On-Board Diagnostics (OBD) system is the least vulnerable component because of its restricted connectivity. It also has little control on the major elements. The study's findings show how important it is to establish a strong cybersecurity protocol. A cybersecurity plan will ensure the safe and secure operation of CAVs. This is accurate for the CAV's extremely sensitive parts.