Modern vehicles become increasingly digitalized with advanced information technology-based solutions like advanced driving assistance systems and vehicle-to-x communications. These systems are complex and interconnected. Rising complexity and increasing outside exposure has created a steadily rising demand for more cyber-secure systems. Thus, also standardization bodies and regulators issued standards and regulations to prescribe more secure development processes. This security, however, also has to be validated and verified. In order to keep pace with the need for more thorough, quicker and comparable testing, today's generally manual testing processes have to be structured and optimized. Based on existing and emerging standards for cybersecurity engineering, this paper therefore outlines a structured testing process for verifying and validating automotive cybersecurity, for which there is no standardized method so far. Despite presenting a commonly structured framework, the process is flexible in order to allow implementers to utilize their own, accustomed toolsets.
翻译:现代车辆日益数字化,采用先进的信息技术解决方案,如先进的驾驶协助系统和车辆对车辆的通信。这些系统是复杂和相互关联的。越来越复杂和外部接触不断增加,导致对更多网络安全系统的需求不断增加。因此,标准化机构和监管机构也发布了标准和条例,以规定更安全的开发程序。然而,这种安全也必须得到验证和核实。为了跟上更彻底、更快和可比测试的需要,今天一般的人工测试程序必须加以构建和优化。因此,根据现有的和新出现的网络安全工程标准,本文件概述了核实和验证汽车网络安全的结构化测试程序,迄今为止还没有标准化的方法。尽管提出了共同的结构化框架,但这一过程是灵活的,以便让实施者能够利用自己的老旧工具。