Quantitative Evaluation and Analysis of On-board Network Components Risk Rate Based on AFC-TARA

Zuo Zheng,Wang Yunpeng,Ma Bin,Zou Bosong,Cao Yaoguang,Yang Shichun
DOI: https://doi.org/10.19562/j.chinasae.qcgc.2023.ep.004
2023-01-01
Abstract:The first step of information security design is threat analysis and risk assessment(TARA), which determines security requirements and objectives, and provides a basis for the forward development of information security and the repair of security vulnerabilities. However, the current TARA can only evaluate the impact of malicious attack and security vulnerabilities, which can’t support quantitative evaluation of the effectiveness of protection strategies. Therefore, an attack and fix combined threat analysis and risk assessment(AFC-TARA) method is proposed in this paper. By converting the security state of the system-level on-board network architecture into a continuous-time Markov chain model, and associating the vulnerability mining, vulnerability repair and security defense strategy with the transition rate, a system-level on-board network architecture security assessment and analysis that comprehensively considers attack variables and defense variables are finally realized.
What problem does this paper attempt to address?