A Digital Twin (DT) is a digital representation of a physical object used to simulate it before it is built or to predict failures after the object is deployed. The DT concept was originally applied to manufacturing but has been gaining attention in other areas. In this article, we introduce a novel concept called Cyber Digital Twin (CDT), which transfers the idea of the DT to automotive software for the purpose of security analysis. In our approach, the ECU software (i.e., firmware) is transformed into a CDT, which contains automatically extracted, security-relevant information from the firmware. With this, we can evaluate automotive security requirements through automated security requirements verification using policy enforcement checks and detection of security vulnerabilities. The evaluation can be done continuously using newly integrated checks and published security vulnerabilities.
翻译:数字双胞胎(DT)是用于模拟其建构之前或部署后预测故障的实物物体的数字表示。DT概念最初适用于制造,但在其他领域日益受到注意。在本篇文章中,我们引入了名为Cyber Digital Twin(CDT)的新概念,将DT的概念转换为汽车软件,以便进行安全分析。在我们的方法中,ECU软件(即固态软件)转变为CDT,其中载有自动提取的、与安全有关的公司软件信息。这样,我们可以通过自动安全要求核查,通过政策执行检查和安全弱点的检测,评估汽车安全需要。评估可以持续地使用新整合的检查和公布的安全弱点。