thecybersecurityreview

CYBERSECURITY REVIEWFEBRUARY - APRIL 2024 19The summary of Figure 2. is as follows: (1) Standard cybersecurity testing can verify most products' missing or incorrect functionality due to gaps between intended functionality (in planned specification) and realized functionality (in practical implementation). (2) The unspecified behavior of potential cybersecurity bugs and vulnerabilities is identified through non-standard cybersecurity testing or penetration testing (Under ISO 27001, penetration testing detects cybersecurity vulnerabilities and exhibits the practical probability of different attack scenarios )Standard cybersecurity testing aims to identify and reduce cybersecurity defects within a system during the design and development phases. It includes static and dynamic standard cybersecurity testing.Non-standard cybersecurity testing aims to exploit cybersecurity defects by simulating real-world attacks from a hacker's perspective after the development phase or in the late stage of the development phase. It includes penetration testing and vulnerability assessment.3. CHALLENGES IN CYBERSECURITY TESTINGPenetration testing (pen-testing) in the automotive industry presents unique challenges due to the trend towards the Software-Defined Vehicle (SDV), driven by advancements in connectivity, artificial intelligence, and software technologies. Key features of SDV include connectivity for real-time data exchange, over-the-air updates for remote software enhancements, integration of artificial intelligence for autonomous driving and advanced driver assistance systems, and a software-defined cockpit with customizable user experiences.THE SUMMARY OF CHALLENGES IS AS FOLLOWS:1. COMPLEXITY OF ECOSYSTEM: Modern vehiclescan have hundreds of Electronic Control Units (ECUs) and multiple communication systems, making them very complex. Performing pen-testing for such a system requires specialized knowledge.2. REAL-TIME SYSTEMS: Automotive systems oftenoperate in real-time, requiring pen-testers to be aware of timing and resource constraints.3. SUPPLY CHAIN CYBERSECURITY: The automotiveindustry relies on a vast supply chain for components and software. Performing comprehensive pen-testing has to involve components throughout the entire supply chain.4. REGULATORY COMPLIANCE: Pen-testing mustfulfill the technical recommendations from ISO/SAE 21434 and regulation requirements from UNECE R155. 5. INTEROPERABILITY CHALLENGES: Testing thesecurity of interfaces between different components and systems within a vehicle or across vehicles can be challenging due to varying standards and protocols. This requires well-trained pen-testers in the limited talent pool of cybersecurity.Collaboration between automotive manufacturers, cybersecurity researchers, and regulatory bodies is essential to address these challenges effectively. Continental offers end-to-end cyber security solutions from Argus and Elektrobit for all connected vehicle electronics. Both firms are subsidiaries wholly owned by Continental. Through this, we enable vehicle manufacturers to prevent, understand, and respond to cyber threats. Part of this process includes providing professional security services through Argus, which can offer pen-testing to support OEMs in fulfilling the requirements of the UNECE R155 regulations. Figure 2. Cybersecurity testing and unspecific behaviors Figure 3. Cybersecurity Testing CatalogsPENETRATION TESTING IS ONE ASPECT THAT IS GROWING IN INTEREST, AS EMPLOYING SIMULATED CYBERATTACKS CAN REVEAL POTENTIAL VULNERABILITIES, ESPECIALLY AT THE LATER STAGES OF PRODUCT DEVELOPMENT
< Page 9 | Page 11 >