Next Article in Journal
Emerging Digital Technologies in Healthcare with a Spotlight on Cybersecurity: A Narrative Review
Next Article in Special Issue
Is Short-Term Memory Made of Two Processing Units? Clues from Italian and English Literatures down Several Centuries
Previous Article in Journal
adaptMLLM: Fine-Tuning Multilingual Language Models on Low-Resource Languages with Integrated LLM Playgrounds
Previous Article in Special Issue
KVMod—A Novel Approach to Design Key-Value NoSQL Databases
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Integrated Attack Tree in Residual Risk Management Framework

by
Ahmed Nawaz Khan
1,*,
Jeremy Bryans
1,
Giedre Sabaliauskaite
2 and
Hesamaldin Jadidbonab
1
1
Institute of Future Transport and Cities, Coventry University, Coventry CV1 5FB, UK
2
Department of Computer Science, Swansea University, Swansea SA1 8EN, UK
*
Author to whom correspondence should be addressed.
Information 2023, 14(12), 639; https://doi.org/10.3390/info14120639
Submission received: 12 September 2023 / Revised: 26 October 2023 / Accepted: 18 November 2023 / Published: 29 November 2023
(This article belongs to the Special Issue Feature Papers in Information in 2023)

Abstract

Safety-critical cyber-physical systems (CPSs), such as high-tech cars having cyber capabilities, are highly interconnected. Automotive manufacturers are concerned about cyber attacks on vehicles that can lead to catastrophic consequences. There is a need for a new risk management approach to address and investigate cybersecurity risks. Risk management in the automotive domain is challenging due to technological improvements and advances every year. The current standard for automotive security is ISO/SAE 21434, which discusses a framework that includes threats, associated risks, and risk treatment options such as risk reduction by applying appropriate defences. This paper presents a residual cybersecurity risk management framework aligned with the framework presented in ISO/SAE 21434. A methodology is proposed to develop an integrated attack tree that considers multiple sub-systems within the CPS. Integrating attack trees in this way will help the analyst to take a broad perspective of system security. Our previous approach utilises a flow graph to calculate the residual risk to a system before and after applying defences. This paper is an extension of our initial work. It defines the steps for applying the proposed framework and using adaptive cruise control (ACC) and adaptive light control (ALC) to illustrate the applicability of our work. This work is evaluated by comparing it with the requirements of the risk management framework discussed in the literature. Currently, our methodology satisfies more than 75% of their requirements.
Keywords: automotive cybersecurity; risk management framework; risk assessment; attack tree; ISO/SAE 21434 automotive cybersecurity; risk management framework; risk assessment; attack tree; ISO/SAE 21434

Share and Cite

MDPI and ACS Style

Khan, A.N.; Bryans, J.; Sabaliauskaite, G.; Jadidbonab, H. Integrated Attack Tree in Residual Risk Management Framework. Information 2023, 14, 639. https://doi.org/10.3390/info14120639

AMA Style

Khan AN, Bryans J, Sabaliauskaite G, Jadidbonab H. Integrated Attack Tree in Residual Risk Management Framework. Information. 2023; 14(12):639. https://doi.org/10.3390/info14120639

Chicago/Turabian Style

Khan, Ahmed Nawaz, Jeremy Bryans, Giedre Sabaliauskaite, and Hesamaldin Jadidbonab. 2023. "Integrated Attack Tree in Residual Risk Management Framework" Information 14, no. 12: 639. https://doi.org/10.3390/info14120639

APA Style

Khan, A. N., Bryans, J., Sabaliauskaite, G., & Jadidbonab, H. (2023). Integrated Attack Tree in Residual Risk Management Framework. Information, 14(12), 639. https://doi.org/10.3390/info14120639

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop