Cyber Risk Assessment Study and Mitigation Proposal: A case Study for an Automotive Company
2024 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE credits
Student thesis
Abstract [en]
This thesis focuses on increasing the cybersecurity of automotive company’s ECU (electronic control unit) systems. Through comprehensive risk assessment and vulnerability scanning, ECUs are key components of modern automotive systems. It manages important vehicle functions. This makes security paramount.
Our research begins with a detailed threat analysis and risk assessment. Based on the TARA (Threat Analysis and Risk Assessment) methodology, we identify key assets, potential vulnerabilities and classify threats using the STRIDE model. High-risk areas include network communications and physical interfaces. It has been found to be vulnerable to spoofing,tampering, and denial-of-service attacks.
Using the Snyk tool, we performed a vulnerability scan of the ECU software, identifying several high severity issues. These findings highlight the need for strict security measures.
The key conclusion of our research is that ECU systems face significant security risks that require immediate attention. By using multi-factor authentication Safe coding practices and regular software updates Automotive companies can thus greatly improve the safety of their ECU systems. This thesis provides a roadmap
Place, publisher, year, edition, pages
2024. , p. [22]
Keywords [en]
Cybersecurity, IoT, Risk assessment, Vulnerability scan, Threat Analysis and Risk Assessment (TARA), Threat analysis, Cyber threats, ECU
National Category
Embedded Systems
Identifiers
URN: urn:nbn:se:hv:diva-22074Local ID: EXD600OAI: oai:DiVA.org:hv-22074DiVA, id: diva2:1878031
Subject / course
Computer science
Educational program
Master in Cybersecurity
Supervisors
Examiners
2024-07-242024-06-262025-09-30Bibliographically approved