Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Cyber Risk Assessment Study and Mitigation Proposal: A case Study for an Automotive Company
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2024 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This thesis focuses on increasing the cybersecurity of automotive company’s ECU (electronic control unit) systems. Through comprehensive risk assessment and vulnerability scanning, ECUs are key components of modern automotive systems. It manages important vehicle functions. This makes security paramount.

Our research begins with a detailed threat analysis and risk assessment. Based on the TARA (Threat Analysis and Risk Assessment) methodology, we identify key assets, potential vulnerabilities and classify threats using the STRIDE model. High-risk areas include network communications and physical interfaces. It has been found to be vulnerable to spoofing,tampering, and denial-of-service attacks.

Using the Snyk tool, we performed a vulnerability scan of the ECU software, identifying several high severity issues. These findings highlight the need for strict security measures.

The key conclusion of our research is that ECU systems face significant security risks that require immediate attention. By using multi-factor authentication Safe coding practices and regular software updates Automotive companies can thus greatly improve the safety of their ECU systems. This thesis provides a roadmap

Place, publisher, year, edition, pages
2024. , p. [22]
Keywords [en]
Cybersecurity, IoT, Risk assessment, Vulnerability scan, Threat Analysis and Risk Assessment (TARA), Threat analysis, Cyber threats, ECU
National Category
Embedded Systems
Identifiers
URN: urn:nbn:se:hv:diva-22074Local ID: EXD600OAI: oai:DiVA.org:hv-22074DiVA, id: diva2:1878031
Subject / course
Computer science
Educational program
Master in Cybersecurity
Supervisors
Examiners
Available from: 2024-07-24 Created: 2024-06-26 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

fulltext(1193 kB)530 downloads
File information
File name FULLTEXT01.pdfFile size 1193 kBChecksum SHA-512
d046896617525a685debd6b9beed1e42716decab90d6e8894eb6b8588affb88ed4c8d14c429af49e65325fd72a6e443ba8426c5ceb4b5927f6f7ba489ccfb2c6
Type fulltextMimetype application/pdf

By organisation
Department of Engineering Science
Embedded Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 531 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 694 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf