A Requirements Optimization Method for Automotive Cyber Security Assurance
摘要
As the automotive industry enters the era of electrification, the proliferation of in-vehicle components has concomitantly escalated the vulnerability to potential cyber-attacks. In our previous research, we introduced a GSN (Goal Structuring Notation)-based model for automotive cyber security assurance, which was validated by analyzing the ISO/SAE 21434 standard. Despite providing a quantitative benchmark, this approach lacked targeted remediation strategies tailored to specific attack scenarios. To bridge this gap, we integrate risk assessment methodologies with optimization techniques. Leveraging the genetic evolution algorithm, we devise an innovative solution that minimizes targeted risks, harnessing the remarkable capabilities of genetic algorithms in combinatorial optimization problems. This approach offers a method to support the development of cyber security assurance case for in-vehicle systems, and fresh perspectives and effective solutions for bolstering automotive cyber security.