System, method and program product for enhancing threat analysis and risk assessment

CN122783263APending Publication Date: 2026-09-18TOYOTA JIDOSHA KK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610317849.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-03-17
Filing Date
2026-03-16
Publication Date
2026-09-18

AI Technical Summary

Technical Problem

最近的车辆的功能变得更高级且更复杂,因此,为了保证车辆安全(safely)且安心地(securely)进行动作,对更坚牢的(robust)汽车的网络安全的要求也变得更高级且更复杂

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122783263A_ABST
    Figure CN122783263A_ABST
Patent Text Reader

Abstract

The present disclosure provides systems, methods, and computer program products that automatically reinforce threat analysis and risk assessment. According to an exemplary embodiment, a system can be configured to acquire a plurality of components in a vehicle and vehicle architecture information that specifies a plurality of connections among the plurality of components, generate a graph having the plurality of components and the plurality of connections, identify, based on the graph, a path from an entry point to an asset that passes through at least one of the plurality of connections, acquire an attack feasibility score for the path, acquire impact assessment data for the path, acquire a risk level for the path based on the attack feasibility score for the path and the impact assessment data for the path, and acquire a mitigation strategy for the path based on the risk level for the path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The exemplary implementations of this disclosure relate to automotive cybersecurity, and more specifically, to the enhancement of threat analysis and risk assessment in automotive cybersecurity. Background Technology

[0002] Modern vehicles are capable of a wide range of complex functions, such as generating telemetry data, sending and receiving data via the internet, providing driver assistance, and similar functions. As the functions of modern vehicles become more advanced and complex, the cybersecurity requirements for more robust vehicles also become more advanced and complex in order to ensure that vehicles operate safely and securely.

[0003] To improve security in modern vehicles, the process of Threat Analysis and Risk Assessment (TARA) has been proposed and outlined by various standardization organizations, such as the International Organization for Standardization (ISO), the Society of Automotive Engineers (SAE), and similar organizations (e.g., ISO / SAE 21434).

[0004] TARA typically includes the process of involving asset identification, threat scenario identification, impact assessment, attack path analysis, attack feasibility assessment, risk determination, and risk management judgment. Summary of the Invention

[0005] Exemplary implementations matching this disclosure can perform vehicle-related threat analysis and risk assessment in a rapid, efficient, and error-free manner without relying on subjective opinions.

[0006] According to an exemplary embodiment, a system is provided. The system may include: a storage device storing computer-executable instructions; and at least one processor communicatively connected to the storage device, the at least one processor being configured to execute the instructions to perform the following actions: acquiring vehicle architecture information of multiple components in a vehicle and specifying multiple connections between the multiple components, wherein the multiple components may include at least one component corresponding to an asset and at least one component corresponding to an entry point; generating a graph having multiple components and multiple connections; identifying, based on the graph, a path from the entry point to the asset that passes through at least one of the multiple connections; acquiring an attack feasibility score for the path; acquiring impact assessment data for the path; acquiring a risk level for the path based on the attack feasibility score and the impact assessment data for the path; and acquiring a mitigation strategy for the path based on the risk level for the path.

[0007] According to an exemplary implementation, the multiple constituent elements may include multiple constituent elements corresponding to multiple assets, and at least one processor may be configured to identify all paths from an entry point to each of the multiple assets; or the multiple constituent elements may include multiple constituent elements corresponding to multiple entry points, and at least one processor may be configured to identify all paths from each of the multiple entry points to each of the multiple assets; or the multiple constituent elements may include multiple constituent elements corresponding to multiple assets and multiple constituent elements corresponding to multiple entry points, and at least one processor may be configured to identify all paths from each of the multiple entry points to each of the multiple assets.

[0008] According to an exemplary implementation, multiple connections can be associated with multiple weights representing the difficulty for an attacker to traverse the corresponding connections.

[0009] According to an exemplary implementation, at least one processor can be configured to use a path search algorithm to identify a path from the entry point to the asset based on a graph.

[0010] According to an exemplary implementation, at least one processor can be configured to obtain an attack feasibility score for a path by: determining an individual attack feasibility score associated with each connection within the path; and summing up all individual attack feasibility scores associated with all connections within the path.

[0011] According to an exemplary implementation, at least one processor can be configured based on the following formula, namely, AS Path =SUM(MAX(AS) ConnectionThe algorithm is calculated as follows: (Number of connections / Maximum number of connections) × summating all individual attack feasibility scores related to all connections within the path. Path AS can represent a path-related attack feasibility score. Connection It can represent an individual attack feasibility score associated with each connection within the path, the number of connections can represent the total number of connections within the path, and the maximum number of connections can represent the maximum number of connections within the path among all identified paths.

[0012] According to an exemplary implementation, at least one processor may be configured to: determine individual mitigation strategies for each connection within a path based on a risk level determined according to each individual attack feasibility score, and combine all individual mitigation strategies associated with all connections within the path, thereby obtaining a mitigation strategy for the path based on the risk level of the path.

[0013] According to an exemplary implementation, one or more of the following can be obtained from the user: attack feasibility score, impact assessment data, risk level, and mitigation strategy.

[0014] According to an exemplary implementation, a method is provided. The method may include: acquiring vehicle architecture information of multiple components in a vehicle and specifying multiple connections between the multiple components, wherein the multiple components may include at least one component corresponding to an asset and at least one component corresponding to an entry point; generating a graph having the multiple components and multiple connections; identifying, based on the graph, a path from the entry point to the asset that passes through at least one of the multiple connections; acquiring an attack feasibility score for the path; acquiring impact assessment data for the path; acquiring a risk level for the path based on the attack feasibility score and the impact assessment data; and acquiring a mitigation strategy for the path based on the risk level.

[0015] According to an exemplary implementation, the multiple constituent elements may include multiple constituent elements corresponding to multiple assets, and the method may include identifying all paths from an entry point to each of the multiple assets; or the multiple constituent elements may include multiple constituent elements corresponding to multiple entry points, and the method may include identifying all paths from each of the multiple entry points to each of the multiple assets; or the multiple constituent elements may include multiple constituent elements corresponding to multiple assets and multiple constituent elements corresponding to multiple entry points, and the method may include identifying all paths from each of the multiple entry points to each of the multiple assets.

[0016] According to an exemplary implementation, multiple connections can be associated with multiple weights representing the difficulty for an attacker to traverse the corresponding connections.

[0017] According to an exemplary implementation, a path search algorithm can be used to identify the path from the entry point to the asset based on a graph.

[0018] According to an exemplary implementation, obtaining an attack feasibility score for a path may include: determining an individual attack feasibility score associated with each connection within the path; and summing up all individual attack feasibility scores associated with all connections within the path.

[0019] According to an exemplary implementation, all individual attack feasibility scores associated with all connections within the path can be based on the following formula, i.e., AS Path =SUM(MAX(AS) Connection The sum of the sum of the number of connections and the maximum number of connections is calculated as follows: AS Path AS can represent a path-related attack feasibility score. Connection It can represent an individual attack feasibility score associated with each connection within the path, the number of connections can represent the total number of connections within the path, and the maximum number of connections can represent the maximum number of connections within the path among all identified paths.

[0020] According to an exemplary implementation, obtaining a path mitigation strategy based on the risk level of the path may include: determining an individual mitigation strategy for each connection within the path based on the risk level determined according to each individual attack feasibility score; and combining all individual mitigation strategies associated with all connections within the path.

[0021] According to an exemplary implementation, one or more of the following can be obtained from the user: attack feasibility score, impact assessment data, risk level, and mitigation strategy.

[0022] According to an exemplary embodiment, a non-transitory computer-readable recording medium is provided. The non-transitory computer-readable recording medium may record instructions executable by at least one processor to cause the at least one processor to perform a method, the method comprising: acquiring vehicle architecture information of a plurality of constituent elements in a vehicle and specifying a plurality of connections between the plurality of constituent elements, wherein the plurality of constituent elements may include at least one constituent element corresponding to an asset and at least one constituent element corresponding to an entry point; generating a graph having the plurality of constituent elements and the plurality of connections; identifying, based on the graph, a path from the entry point to the asset that passes through at least one of the plurality of connections; acquiring an attack feasibility score for the path; acquiring impact assessment data for the path; acquiring a risk level for the path based on the attack feasibility score and the impact assessment data; and acquiring a mitigation strategy for the path based on the risk level.

[0023] According to an exemplary implementation, the multiple constituent elements may include multiple constituent elements corresponding to multiple assets, and the method may include identifying all paths from an entry point to each of the multiple assets; or the multiple constituent elements may include multiple constituent elements corresponding to multiple entry points, and the method may include identifying all paths from each of the multiple entry points to each of the multiple assets; or the multiple constituent elements may include multiple constituent elements corresponding to multiple assets and multiple constituent elements corresponding to multiple entry points, and the method may include identifying all paths from each of the multiple entry points to each of the multiple assets.

[0024] According to an exemplary implementation, multiple connections can be associated with multiple weights representing the difficulty for an attacker to traverse the corresponding connections.

[0025] According to an exemplary implementation, a path search algorithm can be used to identify the path from the entry point to the asset based on a graph.

[0026] According to an exemplary implementation, obtaining an attack feasibility score for a path may include: determining an individual attack feasibility score associated with each connection within the path; and summing up all individual attack feasibility scores associated with all connections within the path.

[0027] According to an exemplary implementation, all individual attack feasibility scores associated with all connections within the path can be based on the following formula, i.e., AS Path =SUM(MAX(AS) Connection The sum of the sum of the number of connections and the maximum number of connections is calculated as follows: AS Path AS can represent a path-related attack feasibility score. Connection It can represent an individual attack feasibility score associated with each connection within the path, the number of connections can represent the total number of connections within the path, and the maximum number of connections can represent the maximum number of connections within the path among all identified paths.

[0028] According to an exemplary implementation, obtaining a path mitigation strategy based on the risk level of the path may include: determining an individual mitigation strategy for each connection within the path based on the risk level determined according to each individual attack feasibility score; and combining all individual mitigation strategies associated with all connections within the path. According to an exemplary implementation, one or more of the following may be obtained from the user: attack feasibility score, impact assessment data, risk level, and mitigation strategy.

[0029] Further solutions are described in part in the following description, and will become apparent in part from the description, or may be implemented by practicing the embodiments presented in this disclosure. Attached Figure Description

[0030] Hereinafter, the features, advantages and importance of preferred embodiments of the present disclosure will be described with reference to the accompanying drawings, in which the same reference numerals denote the same elements.

[0031] Figure 1 A flowchart illustrating an exemplary method for enhancing threat analysis and risk assessment, with one or more exemplary implementations.

[0032] Figure 2 Exemplary diagrams illustrating one or more exemplary implementations.

[0033] Figure 3 A flowchart illustrating an exemplary method for determining attack feasibility scoring in more than one exemplary implementation.

[0034] Figure 4 A flowchart illustrating an exemplary method for determining a mitigation strategy according to one or more exemplary implementations.

[0035] Figure 5 A block diagram illustrating exemplary constituent elements in a system with more than one exemplary implementation. Detailed Implementation

[0036] The following detailed description of preferred embodiments is with reference to the accompanying drawings. The above disclosure provides examples and descriptions, but is not intended to be exhaustive, nor is it intended to limit implementations to the exact forms disclosed. Modifications and variations can be made based on the above disclosure, or can be obtained through implementation. Furthermore, one or more features or constituent elements of one embodiment can be incorporated into another embodiment (or one or more features of another embodiment) or combined with another embodiment (or one or more features of another embodiment). Moreover, it is understood that in the flowcharts and descriptions of the actions provided below, one or more actions may be omitted, one or more actions may be added, one or more actions may be performed simultaneously (at least partially), and the order of one or more actions may be changed.

[0037] Even if a specific combination of features is listed in the claims and / or disclosed in this specification, such combination is not intended to limit the disclosure of possible implementations. In fact, many features can be combined in ways not specifically listed in the claims and / or not specifically disclosed in this specification. Each dependent claim listed below may be directly dependent on only one claim, but the disclosure of possible implementations includes each dependent claim combined with all other claims in the set of claims.

[0038] Unless otherwise explicitly stated, elements, actions, or instructions used in this specification should not be construed as essential or necessary. Furthermore, when used in this specification, the articles “a” and “an” refer to more than one item and can be used interchangeably with “more than one.” When referring to only one item, the term “one” or similar terms is used. Additionally, when used in this specification, the terms “has,” “have,” “having,” “include,” “including,” or similar terms imply open-ended usage. Moreover, unless otherwise explicitly stated, the phrase “based on” means “at least partially based on.” Furthermore, expressions such as “[A] and / or [B],” “at least one of [A] and [B],” or “at least one of [A] or [B]” should be understood as referring to only A, only B, or including both A and B.

[0039] When configured to perform the implementation of multiple actions, the execution of multiple instructions, etc., the expression "at least one processor" should be understood as a single processor performing the implementation of multiple actions, etc., or each of a plurality of processors performing the implementation of at least some (but not necessarily all) of the multiple actions, etc.

[0040] Throughout this specification, references to "one embodiment," "implementation," "non-limiting preferred embodiment," or the like refer to a specific feature, structure, or characteristic described in connection with the illustrated embodiment that is included in at least one embodiment of the solution. Therefore, the phrases "in one embodiment," "in an embodiment," "in a non-limiting preferred embodiment," and the like throughout this specification may all refer to the same embodiment, but are not necessarily required to refer to the same embodiment.

[0041] Furthermore, the features, advantages, and characteristics described in this disclosure can be combined in any suitable manner in more than one exemplary embodiment. Those skilled in the art, in view of the description herein, will recognize that this disclosure can be implemented without any of the specific features or advantages of a particular embodiment. In other instances, further features and advantages that are not sometimes present in all embodiments of this disclosure may be recognized in certain specific embodiments.

[0042] Furthermore, the term "vehicle" as used in this specification refers to any suitable type of vehicle capable of implementing the exemplary embodiments of this disclosure. For example, "vehicle" can refer to a powered vehicle, such as a passenger car, truck, bus, motorcycle, or any other suitable type of automobile powered by an engine, motor, or other mechanical means. Alternatively or further, without departing from the scope of this disclosure, "vehicle" as used in this specification can refer to a bicycle, skateboard, and any other suitable type of unpowered vehicle.

[0043] As mentioned above, threat analysis and risk assessment (TARA) has been proposed and outlined to improve security in recent vehicles. TARA can include processes involving asset identification, threat scenario identification, impact assessment, attack path analysis, attack feasibility assessment, risk determination, and risk treatment decisions.

[0044] Asset identification can involve the identification of physical components, data, and similar assets within a system (vehicle) that needs to be protected, as well as the identification of interaction points such as interfaces and similar objects that attackers can interact with to access and exploit assets.

[0045] Threat scenario identification can involve identifying scenarios where attackers can exploit assets through the analysis of data and command flows in the system, potential attack paths, attack techniques, and similar entities.

[0046] Impact assessment can involve evaluating and determining the potential impact on the security of systems related to various scenarios. Here, security can include various aspects such as money, operation, privacy, and similar items.

[0047] Attack path analysis can involve the identification and analysis of potential attack paths related to various scenarios from the entry point to the asset. Note that attack path analysis can be detailed and fully documented regarding the methods and tools used to trace the path from the entry point to the asset, ensuring transparency and repeatability when evaluating the methods an attacker might use to traverse the system. Furthermore, attack path analysis can be performed automatically using methods such as attack tree analysis, or manually based on the analyst's experience.

[0048] Attack feasibility assessment can involve evaluating and determining the feasibility (probability) of various scenarios based on factors such as the time, expertise, system knowledge, equipment, and similar elements that an attacker might need to normally exploit an asset.

[0049] Risk assessment can involve determining and establishing risk levels for various scenarios based on the established impacts and feasibility. Risk levels can be determined using tools such as risk matrices that categorize risks into high, medium, low, and similar levels.

[0050] Risk management decisions can involve identifying and judging actions (countermeasures) to mitigate, transfer, accept, or avoid risks based on risk-based risk levels.

[0051] In this regard, the aforementioned process in the related technology may have at least the following disadvantages.

[0052] Threat scenario identification and other processes can be performed through lengthy and redundant manual procedures. These procedures require an understanding of assets, their scope, their interactions, and how an attacker could leverage intermediate assets before reaching the target asset from the entry point in the most feasible way. In this regard, the complex connections between system components, the increased complexity of vehicles and their functions, the sheer volume of information to process, and the numerous potential attack paths make such manual processes inefficient, time-consuming, and prone to errors. Furthermore, the resulting analysis may be unintentionally redundant due to the sheer volume of information and potential attack paths, and / or may need to be repeated due to updates related to the input information, leading to further inefficiency.

[0053] Furthermore, processes such as attack feasibility assessment, risk determination, and risk management decisions can be based on the analyst's subjective insights and experience. Even when non-subjective elements related to attack feasibility assessment (Common Vulnerability Scoring System (CVSS), attack capabilities, and similar metrics) can be utilized by the analyst, the resulting assessment remains subjective. When analyzed by different analysts for the same attack path, this can lead to variations and inconsistencies in feasibility assessments, risk levels, and proposed countermeasures. Alternative approaches may involve using publicly available vulnerability databases, such as Common Vulnerabilities and Exposures (CVE) databases, to provide inferences related to feasibility / probability. However, such methods are sometimes unsuitable for closed-source or proprietary systems where detailed vulnerability information is not publicly available. TARA can be performed at various stages of the software development lifecycle; therefore, inconsistencies and the subjective nature of the results can cause problems when comparing or merging different outcomes.

[0054] Therefore, there is a need for a system that can address more than one of the aforementioned drawbacks and perform threat analysis and risk assessment on vehicles.

[0055] It is assumed that the features, advantages, and importance of the exemplary embodiments described in this specification are only a part of this disclosure and are not intended to be exhaustive or to limit the scope of this disclosure. Further descriptions relating to the features, constituent elements, configurations, operations, and implementations of the exemplary embodiments of this disclosure will be provided below.

[0056] The following is for reference Figures 1-4 Some exemplary actions that can be performed through the Threat and Risk Analysis (TRA) system disclosed herein are described.

[0057] A TRA system may include a device, system, platform, module, or similar entity that can be configured to enhance threat analysis and risk assessment within a vehicle. According to an exemplary embodiment, the TRA system may be integrated into the vehicle or may be detached from the vehicle itself. Hereinafter, reference will be made to... Figure 5 Some exemplary components that may be included in a TRA system with more than one exemplary implementation are described.

[0058] Figure 1 The flowchart illustrates an exemplary method 100 for enhancing threat analysis and risk assessment, representing one or more exemplary implementations. One or more actions in method 100 may be performed by at least one processor of the TRA system (e.g., processor 512).

[0059] like Figure 1 As shown, in action S110, at least one processor can be configured to acquire vehicle architecture information. The vehicle architecture information may include multiple components of the vehicle and information specifying multiple connections between the multiple components.

[0060] Multiple components can include any type of components in a vehicle, such as physical components (electronic control units (ECUs), systems on chips (SoCs), sensors, physical data storage media, etc.), software components (software modules, applications, databases, specific data within databases, etc.), and similar components.

[0061] Furthermore, the multiple constituent elements may include at least one constituent element corresponding to an asset and at least one constituent element corresponding to an entry point. An asset may refer to a constituent element within a vehicle that needs to be protected against attackers, such as the driver's personal information / data stored in a database. An entry point may refer to a constituent element within a vehicle that an attacker can first access to exploit assets from outside the vehicle, such as an application / software connected to the internet. According to an exemplary embodiment, the multiple constituent elements may include multiple constituent elements corresponding to multiple entry points. According to an exemplary embodiment, the multiple constituent elements may include multiple constituent elements corresponding to multiple assets.

[0062] Furthermore, according to an exemplary implementation, the multiple constituent elements may include at least one constituent element corresponding to an intermediate constituent element. An intermediate constituent element may refer to a constituent element within a vehicle from which an attacker can access, traverse, and exploit the asset. In other words, an intermediate constituent element may be located between the entry point and the asset on the attack path. Note that a constituent element corresponding to an asset may also correspond to an intermediate constituent element associated with other assets. According to an exemplary implementation, the multiple constituent elements may include multiple constituent elements corresponding to multiple intermediate constituent elements.

[0063] According to an exemplary implementation, vehicle architecture information can specify all constituent elements within the vehicle.

[0064] Multiple connections can include any kind of connection (i.e., basic connection) between any two components within the vehicle, such as interfaces (physical, logical, etc.) and similar connections. Multiple connections are also associated with information specific to a connection, such as the type of data sent through the connection, the direction of data sent through the connection, the interaction between the two components using the connection, and similar information, and this information can be specified.

[0065] In this regard, each of the multiple connections is either undirected or bidirectional, which can indicate whether data and / or attacks can move unidirectionally or bidirectionally between the constituent elements.

[0066] Furthermore, according to the exemplary implementation, multiple connections can be associated with multiple weights. A weight can represent the difficulty for an attacker to traverse the corresponding connections from one component to another. Therefore, different connections can be associated with different weights to represent the differences in the difficulty for an attacker to traverse such connections, thereby simulating the complexity of real-world attacks.

[0067] According to an exemplary implementation, vehicle architecture information can specify all connections between multiple constituent elements.

[0068] According to an exemplary implementation, at least one processor can be configured to obtain vehicle architecture information by analyzing information associated with the vehicle's architecture in order to identify multiple components and multiple connections.

[0069] According to an exemplary implementation, at least one processor can be configured to acquire vehicle architecture information by receiving vehicle architecture information from a user (e.g., an analyst, developer, etc.). For example, the user can provide information such as system / vehicle architecture, entry points, assets, various associated security measures, and similar information to the TRA system. The method then proceeds to action S120.

[0070] In action S120, at least one processor can be configured to generate a diagram that includes multiple constituent elements and multiple connections.

[0071] Figure 2 Exemplary diagrams illustrating more than one exemplary implementation. (e.g.) Figure 2 As shown, the chart may include multiple components, each having one component corresponding to entry point 210, one component corresponding to asset 220, and three components corresponding to intermediate components 232, 234, and 236. Furthermore, the chart may include multiple connections A, B, C, D, E, F, and G between these components. Here, connections A, B, C, D, and E may be bidirectional, while connections F and G may be non-directional.

[0072] Understandable, Figure 2 The configuration shown is simplified for illustrative purposes and is by no means intended to limit the scope of this disclosure. For example, the number of constituent elements (entry point, asset, and intermediate) and connections can be arbitrary, and connections can be between any two constituent elements, etc. The method then proceeds to action S130.

[0073] In action S130, at least one processor may be configured to identify, based on a graph, a path from the entry point to the asset that passes through at least one of a plurality of connections. According to an exemplary implementation, at least one processor may be configured to identify, based on a graph, all paths from the entry point to the asset that pass through all combinations of connections.

[0074] For example, refer to Figure 2At least one processor can be configured to identify the following paths from entry point 210 to asset 220: a first path passing through connection A, connection B, and connection C (passing through intermediate components 232 and 234); a second path passing through connection D and connection E (passing through intermediate component 236); a third path passing through connection A, connection F, and connection E (passing through intermediate components 232 and 236); a fourth path passing through connection D, connection G, and connection C (passing through intermediate components 236 and 234); and a fifth path passing through connection A, connection F, connection G, and connection C (passing through intermediate components 232, 236, and 234).

[0075] Note that in Figure 2 In the example, path F and path G are non-directional paths from intermediate component 232 to intermediate component 236 and from intermediate component 236 to intermediate component 234, respectively. Therefore, paths passing through connections D, F, B, and C, and paths passing through connections A, B, G, and E, are sometimes impossible. Consequently, such paths may not be recognized during action S130.

[0076] According to an exemplary implementation, when the multiple constituent elements include multiple constituent elements corresponding to multiple assets and one constituent element corresponding to an entry point, at least one processor can identify all paths from the entry point to each of the multiple assets. Similarly, when the multiple constituent elements include one constituent element corresponding to an asset and multiple constituent elements corresponding to multiple entry points, at least one processor can identify all paths from each of the multiple entry points to the asset. Furthermore, when the multiple constituent elements include multiple constituent elements corresponding to multiple assets and multiple constituent elements corresponding to multiple entry points, at least one processor can identify all paths from each of the multiple entry points to each of the multiple assets.

[0077] According to an exemplary implementation, at least one processor can be configured to use a pathfinding algorithm to identify paths from an entry point to an asset based on a graph. Pathfinding algorithms may include, for example, Dijkstra's algorithm, Depth-First Search (DFS), Breadth-First Search (BFS), and similar algorithms. Specifically, for example, Dijkstra's algorithm can be used to identify the shortest and / or easiest (i.e., weight-based, etc.) path from the entry point to the asset; on the other hand, DFS and / or BFS can be used to identify all conceivable paths from any number of entry points to any number of assets, ensuring that all paths, including less direct / more complex paths, are identified for analysis.

[0078] According to an exemplary implementation, at least one processor may be configured to identify multiple paths from an entry point to an asset, multiple paths from multiple entry points to an asset, multiple paths from an entry point to multiple assets, and / or multiple paths from multiple entry points to multiple assets. The method then proceeds to action S140.

[0079] In action S140, at least one processor may be configured to acquire an attack feasibility score for a path (i.e., a path identified during action S130). The attack feasibility score can represent the feasibility (probability) of an attacker using the identified path to exploit an asset.

[0080] Understandably, if multiple paths are identified during action S130, at least one processor can obtain an attack feasibility score for each of the multiple paths.

[0081] For example, refer to Figure 2At least one processor can be configured to acquire an attack feasibility score related to a first path from entry point 210 to asset 220 via connections A, B, and C (passing intermediate components 232 and 234); an attack feasibility score related to a second path from entry point 210 to asset 220 via connections D and E (passing intermediate component 236); and an attack feasibility score related to a second path from entry point 210 to asset 220 via connections A, F, and E (passing intermediate components 234). The attack feasibility score related to the third path (232 and intermediate component 236), the attack feasibility score related to the fourth path (through intermediate component 236 and intermediate component 234) from entry point 210 to asset 220 via connection D, connection G and connection C, and the attack feasibility score related to the fifth path (through intermediate component 232, intermediate component 236 and intermediate component 234) from entry point 210 to asset 220 via connection A, connection F, connection G and connection C.

[0082] According to an exemplary implementation, an attack feasibility score can be obtained by automatically determining the attack feasibility score based on an identified path. For example, the system can utilize an artificial intelligence (AI) / machine learning (ML) model trained on past data associated with the attack feasibility score and multiple paths to analyze and determine the attack feasibility score associated with attacks via each of the identified multiple paths. According to an exemplary implementation, an attack feasibility score can be obtained by receiving the attack feasibility score from a user (e.g., an analyst). For example, a user can analyze and determine the attack feasibility score associated with attacks via each of the identified multiple paths (i.e., based on the identified paths) and provide such attack feasibility scores to the system.

[0083] The following is for reference Figure 3 An example of the action to obtain an attack feasibility score is described. Next, the method proceeds to action S150.

[0084] In action S150, at least one processor may be configured to acquire impact assessment data of the path (i.e., the path identified during action S130). The impact assessment data may include information associated with potential impacts that could result from an attack via the identified path (or each of the identified paths). Moreover, potential impacts may include impacts on system security, which may include security related to money, operations, privacy, and similar matters.

[0085] Understandably, if multiple paths are identified during action S130, at least one processor can acquire impact assessment data for each of the multiple paths.

[0086] According to an exemplary implementation, impact assessment data can be obtained by automatically determining impact assessment data based on identified paths. For example, the system can utilize an artificial intelligence (AI) / machine learning (ML) model trained based on past data associated with the impact assessment and multiple paths to analyze and determine the potential impacts that may result as a result of an attack via each of the identified multiple paths. According to an exemplary implementation, impact assessment data can be obtained by receiving impact assessment data from a user (e.g., an analyst). For example, the user analyzes and determines the potential impacts that may result as a result of an attack via each of the identified multiple paths (i.e., based on the identified paths) and provides such potential impacts to the system. The method then proceeds to action S160.

[0087] In action S160, at least one processor may be configured to obtain the risk level of a path (i.e., the path identified during action S130) based on path attack feasibility scoring and path impact assessment data. The risk level may represent the degree of risk associated with the identified path (or each of the multiple identified paths).

[0088] Understandably, if multiple paths are identified during action S130, at least one processor can acquire a risk level for each of the multiple paths based on individual attack feasibility scores and impact assessment data.

[0089] According to an exemplary implementation, the risk level can be obtained automatically based on an acquired attack feasibility score and acquired impact assessment data. For example, the system can utilize an artificial intelligence (AI) / machine learning (ML) model trained on past data correlated with the risk level, impact assessment, and attack feasibility score to analyze and determine the risk level associated with attacks via each of a plurality of identified paths. According to an exemplary implementation, the risk level can be obtained by receiving a risk level from a user (e.g., an analyst). For example, a user can analyze and determine the risk level associated with attacks via each of a plurality of identified paths (i.e., based on the acquired attack feasibility score and acquired impact assessment data) and provide such risk levels to the system.

[0090] According to the exemplary implementation, the risk level is not limiting; for example, it can be obtained using any suitable tool such as a risk matrix that classifies risk levels into high risk, medium risk, low risk, and similar levels. For example, a table (2D matrix) can be used, where columns can represent various types of damage categories, such as security (i.e., security as specified in more than one technical standard), monetary impact, operational, privacy, and similar damage categories, and rows can represent various levels of risk, such as significant, large, medium, negligible, and similar levels. In this regard, the inputs to the table can include descriptions of attack scenarios under the corresponding damage category and risk level. For example, security damage type and medium risk level can correspond to inputs describing attack scenarios involving minor and moderate damage; on the other hand, operational damage type and significant risk level can correspond to inputs describing attack scenarios involving loss or impairment of core vehicle functions. The method then proceeds to action S170.

[0091] In action S170, at least one processor can be configured to acquire mitigation strategies for a path (i.e., the path identified during action S130) based on the path's risk level. Mitigation strategies can refer to strategies for mitigating, evading, controlling, or similar actions taken by an attacker using a path to exploit assets.

[0092] Understandably, if multiple paths are identified during action S130, at least one processor can acquire a mitigation strategy for each of the multiple paths based on each risk level.

[0093] For example, refer to Figure 2 At least one processor can be configured to acquire a mitigation strategy associated with a first path from entry point 210 to asset 220 via connections A, B, and C (via intermediate components 232 and 234), a mitigation strategy associated with a second path from entry point 210 to asset 220 via connections D and E (via intermediate component 236), and a mitigation strategy associated with a second path from entry point 210 to asset 220 via connections A, F, and E (via intermediate components 234). The mitigation strategies related to the third path (of element 232 and intermediate element 236), the mitigation strategies related to the fourth path (of element 236 and intermediate element 234) from entry point 210 to asset 220 via connection D, connection G and connection C, and the mitigation strategies related to the fifth path (of element 232, intermediate element 236 and intermediate element 234) from entry point 210 to asset 220 via connection A, connection F, connection G and connection C.

[0094] According to an exemplary implementation, mitigation strategies can be acquired based on any further information associated with the attack mitigation strategy. For example, mitigation strategies can also be acquired based on information associated with industry best practices for the types of connections present in the attack path, expert knowledge, past data, and similar information. In a further example, different mitigation strategies can be acquired and utilized for different types of connections (e.g., Bluetooth versus CAN (Controller Area Network) versus Wi-Fi).

[0095] According to an exemplary implementation, mitigation strategies can be obtained automatically by determining mitigation strategies based on the risk level of a path. For example, the system can utilize an artificial intelligence (AI) / machine learning (ML) model trained on past data associated with mitigation strategies and risk levels to analyze and determine mitigation strategies associated with attacks via each of a plurality of identified paths, corresponding to the risk level. According to an exemplary implementation, mitigation strategies can be obtained by receiving mitigation strategies from a user (e.g., an analyst). For example, a user can analyze and determine mitigation strategies associated with attacks via each of a plurality of identified paths (i.e., risk level-based) and provide such mitigation strategies to the system.

[0096] According to an exemplary implementation, mitigation strategies can be obtained for paths with risk levels exceeding a predetermined threshold. For example, if the predetermined threshold is 3, and on the other hand, the first path has a risk level of 2 and the second path has a risk level of 5, a mitigation strategy can be obtained for the second path with a risk level exceeding the threshold, while a mitigation strategy may not be obtained for the first path with a risk level below the threshold.

[0097] According to exemplary implementations, for example, more stringent mitigation may be obtained for higher risk levels, while simpler mitigation may be obtained for lower risk levels, or no mitigation may be obtained at all.

[0098] The following is for reference Figure 4 Examples of actions taken to acquire mitigation strategies are documented.

[0099] When action S170 is performed, method 100 may end or terminate. Alternatively, method 100 may return to action S110, whereby at least one processor may be configured to repeatedly perform (in action S110) the acquisition of vehicle architecture information, (in action S120) the generation of diagrams, (in action S130) the identification of paths, (in action S140) the acquisition of attack feasibility scores, (in action S150) the acquisition of impact assessment data, (in action S160) the acquisition of risk levels, and (in action S170) the acquisition of mitigation strategies for at least a predetermined amount of time.

[0100] Therefore, the above configuration enables vehicle-related threat analysis and risk assessment to be conducted quickly, efficiently, and without relying on subjective opinions.

[0101] In particular, the use of charts makes it easy and simple to identify all possible attack paths from all entry points to all vulnerable assets. Then, the most feasible attack paths can be identified quickly, efficiently and without errors based on factors such as attack feasibility scores, connection weights and similar elements.

[0102] Moreover, by automating the above processes, the threat analysis and risk assessment are rationalized, manual operations and subjective opinions are reduced, and the consistency of results is ensured.

[0103] In addition, according to the exemplary implementation, all the above-described actions of method 100 can be performed automatically by the system (i.e., the TRA system). According to the exemplary implementation, one or more of the above-described actions of method 100 can be performed by a user (e.g., an analyst, developer, etc.). For example, the acquisition of vehicle architecture information (in action S110), the generation of diagrams (in action S120), and the identification of paths (in action S130) can be performed automatically by the system. On the other hand, one or more of the following actions can be performed by a user: the acquisition of attack feasibility score (in action S140), the acquisition of impact assessment data (in action S150), the acquisition of risk level (in action S160), and the acquisition of mitigation strategy (in action S170). (That is, here, the system can receive the above parameters from the user.) In other words, according to the exemplary implementation, one or more of the following can be obtained (received) from the user: attack feasibility score, impact assessment data, risk level, and mitigation strategy.

[0104] Figure 3This is a flowchart illustrating an exemplary method 300 for obtaining an attack feasibility score through one or more exemplary implementations. One or more actions of method 300 may be part of action S140 in method 100 and may be performed by at least one processor (e.g., processor 512) of the TRA system.

[0105] like Figure 3 As shown, in action S310, at least one processor can be configured to determine an individual attack feasibility score associated with each connection within the path. Here, the path may refer to the path identified during action S130 in method 100.

[0106] For example, refer to Figure 2 At least one processor can be configured to determine a separate attack feasibility score associated with each of the first paths (connections A, B, and C, from entry point 210 to asset 220, via connection A, connection B, and connection C, via intermediate components 232 and 234)).

[0107] According to an exemplary implementation, a separate attack feasibility score can be determined, for example, based on a common vulnerability assessment system (CVSS) as specified in one or more technical standards of the International Organization for Standardization (ISO), attack capabilities, attack vectors, and similar security assessment methods.

[0108] According to an exemplary implementation, the individual attack feasibility score can also be proportionally changed based on the weights associated with the corresponding connections. The difficulty of traversing connections can affect the probability of an attack; therefore, this proportional change can improve accuracy and facilitate the determination of the individual attack feasibility score. Next, the method proceeds to action S320.

[0109] In action S320, at least one processor can be configured to aggregate all individual attack feasibility scores associated with all connections within the path.

[0110] For example, refer to Figure 2 At least one processor can be configured to summarize the individual attack feasibility scores for the first path (from entry point 210 to asset 220, through connection A, connection B, and connection C (through intermediate components 232 and 234)) of connection A, connection B, and connection C.

[0111] According to an exemplary implementation, at least one processor can be configured based on the following formula, namely, AS Path =SUM(MAX(AS) ConnectionThe sum of all individual attack feasibility scores related to all connections within the path is calculated as follows: (Number of connections / Maximum number of connections).

[0112] Here, AS Path This can represent a path-related attack feasibility score (i.e., a aggregated individual attack feasibility score), AS Connection It can represent the individual attack feasibility score associated with each connection within the path (determined during action S310 using security evaluation methods such as Common Vulnerability Evaluation System (CVSS), attack capabilities, and attack vectors). The number of connections can represent the total number of connections within the path, and the maximum number of connections can represent the maximum number of connections within the path among all identified paths (all paths identified during action S130).

[0113] For example, refer to Figure 2 When summing up all individual attack feasibility scores related to all connections within the first path (from entry point 210 to asset 220, passing through connection A, connection B, and connection C (passing through intermediate components 232 and 234)), AS Path AS can represent an attack feasibility score related to the first path. Connection This represents a separate attack feasibility score associated with each of connections A, B, and C within the first path. The number of connections can correspond to 3, representing the total number of connections A, B, and C within the first path. Here, the fifth path can be identified during action S130 as the path with the largest number of connections (connections A, F, G, and C) among all identified first, second, third, fourth, and fifth paths. Therefore, the maximum number of connections can correspond to 4, representing the largest number of connections within all identified paths.

[0114] The maximum number of connections can serve as a benchmark for normalizing attack feasibility scores across different threat scenarios, thereby ensuring consistent evaluation across different levels of complexity in the architecture.

[0115] According to an exemplary implementation, one or more actions in method 300 can be performed automatically by the system. According to an exemplary implementation, one or more actions in method 300 can be performed by a user (e.g., an analyst), whereby the system can receive corresponding parameters from the user. For example, the user can determine individual attack feasibility scores in the same manner as described above regarding action S310. The user can then provide the determined individual attack feasibility scores to the system, whereby the system can then aggregate all individual attack feasibility scores in the same manner as described above regarding action S320. In another example, the user can determine individual attack feasibility scores in the same manner as described above regarding action S310, and aggregate all individual attack feasibility scores in the same manner as described above regarding action S320. The user can then provide the aggregated individual attack feasibility scores to the system.

[0116] Therefore, the above calculations can incorporate both the complexity of the scenario and the relative difficulty of each connection, providing a comprehensive evaluation of the feasibility of attacks across different paths.

[0117] Moreover, the above formula can be adapted to various security evaluation methods, such as attack capabilities, as specified in more than one technical standard of ISO. As a result, the above process ensures that the path-related attack feasibility score (i.e., the aggregated individual attack feasibility score) follows the criteria provided by more than one technical standard and accurately reflects the cumulative risks associated with each connection.

[0118] The above formula is provided as an example, and it is understood that the invention is not limited thereto and may include any kind of formula that summarizes all individual attack feasibility scores.

[0119] Figure 4 The flowchart illustrates an exemplary method 400 for acquiring a mitigation strategy with one or more exemplary implementations. One or more actions of method 400 may be part of action S170 in method 100 and may be performed by at least one processor (e.g., processor 512) of the TRA system.

[0120] like Figure 4 As shown, in action S410, at least one processor can be configured to determine individual mitigation strategies associated with each connection within the path. The individual mitigation strategies can be determined based on individual risk levels (which may be determined based on individual attack feasibility scores). Here, the path can refer to the path identified during action S130 of method 100.

[0121] For example, refer to Figure 2At least one processor can be configured to determine a separate mitigation strategy associated with each of the first paths (from entry point 210 to asset 220, passing through connection A, connection B, and connection C, passing through intermediate component 232 and intermediate component 234)). Here, the separate mitigation strategy associated with connection A can be determined based on a risk level that can be determined based on a separate attack feasibility score for connection A, the separate mitigation strategy associated with connection B can be determined based on a risk level that can be determined based on a separate attack feasibility score for connection B, and the separate mitigation strategy associated with connection C can be determined based on a risk level that can be determined based on a separate attack feasibility score for connection C.

[0122] According to an exemplary implementation, individual mitigation strategies can be determined using an artificial intelligence (AI) / machine learning (ML) model. For example, the AI / ML model can be trained based on previous records of mitigation strategies applied to various connections between various components at various risk levels. As a result, the AI / ML model can be used to determine an appropriate mitigation strategy for the current connection at the current risk level. The method then proceeds to action S420.

[0123] In action S420, at least one processor can be configured to combine all individual mitigation strategies associated with all connections within the path. Individual mitigation strategies can be combined to form a holistic set of path-guided strategies. Such a holistic set of path-guided strategies can represent or indicate a comprehensive threat scenario.

[0124] According to an exemplary implementation, one or more actions in method 400 can be performed automatically by the system. According to an exemplary implementation, one or more actions in method 400 can be performed by a user (e.g., an analyst), whereby the system receives corresponding parameters from the user. For example, the user can determine individual mitigation strategies in the same manner as described above regarding action S410. The user can then provide the determined individual mitigation strategies to the system, whereby the system can then aggregate all individual mitigation strategies in the same manner as described above regarding action S420. In another example, the user can determine individual mitigation strategies in the same manner as described above regarding action S410, and aggregate all individual mitigation strategies in the same manner as described above regarding action S420. The user can then provide the aggregated individual mitigation strategies to the system.

[0125] Therefore, the above process can simplify the determination of the overall feasibility of the attack and enable the comparison of mitigation strategies that take into account the problems identified within the attack path by constructing an overall feasibility and mitigation strategy based on the individual feasibility and mitigation strategies related to each basic connection.

[0126] Moreover, the overall feasibility and mitigation strategy of the attack is constructed based on the individual feasibility and mitigation strategies related to each basic connection. Therefore, the overall feasibility and mitigation strategy can be decomposed into feasibility and mitigation strategies related to each basic connection.

[0127] In analyst-specific implementations, when determining attack feasibility assessments or providing recommended strategies, the decomposition of basic connections allows analysts to focus on smaller-scale problems. Each analyst's problem becomes more focused and inherent; therefore, this process reduces subjective factors in the intervention results, leading to more consistent and objective evaluations, thereby further improving the quality of analysis and evaluation. Moreover, this process limits the influence of individual perceptions related to potential attacks on basic connections. Furthermore, when determining feasibility and mitigation strategies, based on the domains of expertise of various analysts, it allows them to focus on the specific parts of the system (connections) they are most familiar with. This facilitates collaboration among analysts from different backgrounds, rather than requiring a single analyst to analyze the entire end-to-end attack scenario and demanding knowledge from multiple domains of expertise.

[0128] In addition, the decomposition of basic connections allows threat analysis and risk assessment to be performed on a modular basis. Such modularity enables the incorporation of new information with a broader scope, and the reuse of specific existing information from previous threat analyses and risk assessments. It allows for individual threat analyses and risk assessments, as well as the merging of multiple threat analyses and risk assessments into a larger framework (e.g., system-level threat analysis and risk assessment). Furthermore, modularity allows for the comparison of results from threat analyses and risk assessments conducted at different times or by different teams, and facilitates the easy regeneration of processes when updated input information is received at a later point in time. This flexibility enhances the efficiency, adaptability, and traceability of threat analysis and risk assessment, enabling more comprehensive threat assessments across various system levels.

[0129] Figure 5 This is a block diagram illustrating exemplary components of system 510, which represents one or more exemplary implementations. System 510 may correspond to the TRA system; therefore, unless otherwise explicitly stated, features associated with the TRA system and system 510 may be applied in the same way to each other.

[0130] like Figure 5As shown, system 510 may include at least one bus 511, at least one processor 512, at least one memory 513, at least one storage component 514, at least one input component 515, at least one output component 516, and at least one communication interface 517.

[0131] Assuming that, without departing from the scope of this disclosure, system 510 may include more than Figure 5 The components shown may have more or fewer components. For example, in one embodiment, system 510 may include multiple storage components 514, input components 515 and output components 516 may be implemented as transceiver components, memory 513 and storage components 514 may be implemented as storage memory, etc.

[0132] Bus 511 can be configured to facilitate or enable communication between the components of system 510. Specifically, bus 511 can communicatively connect the components and provide means for the movement and flow of data for control signals between the components. Bus 511 may include one or more of the following buses that can be implemented in system 510 to enable real-time (or near-real-time) communication and cooperation between the components within system 510: internal bus, address bus, data bus, control bus, Controller Area Network (CAN) bus, Ethernet bus, Peripheral Component Interconnect Express (PCIe) bus, and any other suitable type of bus.

[0133] Processor 512 can be implemented in hardware, firmware, or a combination of hardware and software, and can be configured to perform real-time (or near-real-time) data processing and control of control system 510. Processor 512 may include one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), Neural Processing Unit (NPU), Tensor Processing Unit (TPU), Accelerated Processing Unit (APU), microprocessor, microcontroller, Digital Signal Processor (DSP), Field-Programmable Gate Array (FPGA), Application-Specific Integrated Circuit (ASIC), and / or other types of processing or computing components that can be implemented in system 510. In some implementations, processor 512 may be programmed to perform more than one action described in this specification. Furthermore, processor 512 may include multiple processing units, each dedicated to performing a specific action.

[0134] Memory 513 may include temporary data, runtime variables, program instructions, and one or more media for storing buffers required for the operation of control system 510. Memory 513 may include one or more of the following types of memory that can be implemented in system 510 to store information and / or instructions for use by processor 512: flash memory, read-only memory (ROM), random-access memory (RAM), dynamic or static storage devices (e.g., flash memory, magnetic storage, and / or optical storage), or any other suitable type of memory.

[0135] Storage component 514 can be configured to store non-volatile data such as firmware, configuration settings, calibration data, information, and / or software associated with the operation and use of system 510. For example, storage component 514 may include hard disks (e.g., magnetic disks, optical disks, magneto-optical disks, and / or solid-state drives), compact optical disks (CDs), digital versatile optical disks (DVDs), floppy disks, cartridges, magnetic tapes, and / or other types of non-transitory computer-readable media, and include corresponding drives.

[0136] According to an exemplary embodiment, storage element 514 may be configured to store computer-readable or computer-executable instructions that implement one or more operations of system 510. Storage element 514 may provide the stored information to memory 513 for execution by processor 512.

[0137] Input element 515 may include one or more input elements (e.g., touchscreen display, keyboard, keypad, mouse, button, switch, and / or microphone) that allow system 510 to receive information via user input. Output element 516 may include one or more output elements (e.g., display, speaker, navigation device, one or more light-emitting diodes (LEDs)). According to an exemplary embodiment, input element 515 and / or output element 516 may be arbitrarily selected and may be removed from system 510.

[0138] At least one communication interface 517 may include a transceiver (e.g., a transceiver and / or a separate receiver and transceiver) that enables the system 510 to communicate with other components (e.g., ECU, user equipment, etc.) via a wired connection, a wireless connection, or a combination of wired and wireless connections. For example, the communication interface 517 may include a Controller Area Network (CAN) bus interface, an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, a Wi-Fi interface, a cellular network interface, or a similar interface.

[0139] According to one or more embodiments, the communication interface 517 may include at least one input / output (I / O) interface, at least one network interface, at least one storage interface, or a similar interface that enables the components 512-516 to communicate with other components. Furthermore, the communication interface 517 may include one or more application programming interfaces (APIs) that enable the system 510 (or one or more components included in the system 510) to communicate with one or more software applications (e.g., software applications deployed in the ECU).

[0140] Computer-executable instructions (e.g., software instructions, etc.) may be read into memory 513 and / or memory component 514 via communication interface 517 from other computer-readable media or from other devices (e.g., remote servers, external storage, etc.). When executed, the computer-executable instructions stored in memory 513 and / or memory component 514 may cause processor 512 to execute one or more processes described herein. Further or alternatively, hard-wired circuitry may be used in place of or in combination with software instructions to execute one or more processes described herein. Therefore, the implementation described herein is not limited to any specific combination of hardware circuitry and software.

[0141] It is assumed that the features, advantages, and importance of the exemplary embodiments described above in this specification are only a part of this disclosure and are not intended to be exhaustive or to limit the scope of this disclosure. Further descriptions of the features, constituent elements, configurations, operations, and implementations of exemplary embodiments of this disclosure, as well as the associated technical advantages and importance, will be provided below.

[0142] It is understood that the specific order or hierarchy of function blocks in the process / flowcharts disclosed in this specification is an example of an exemplary method. It is understood that the specific order or hierarchy of function blocks in the process / flowcharts can be reconfigured based on design preferences. Furthermore, some function blocks can be combined or omitted. The appended method claims present the elements of various function blocks in a sample order and are not intended to limit the specific order or hierarchy presented.

[0143] Some implementations may involve systems, methods, and / or computer-readable media at any level of detail of any conceivable technology. Furthermore, as described above in this specification, one or more of the aforementioned constituent elements may be implemented as instructions stored in a computer-readable medium and executable by at least one processor (and / or may include at least one processor). The computer-readable medium may include a computer-readable non-transitory storage medium (or media(s)) having computer-readable program instructions for causing a processor (or processor(s)) to perform actions.

[0144] A computer-readable storage medium can be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof, but is not limited thereto. A non-exhaustive list of more specific examples related to computer-readable storage media includes: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile optical disc (DVD), memory sticks, floppy disks, punched cards containing instructions, or devices with mechanically encoded structures in slots, and any suitable combinations thereof. As used in this specification, computer-readable storage media should not be construed as temporary signals such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses passing through fiber optic cables), or electrical signals transmitted through wires.

[0145] The computer-readable program instructions described in this specification can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded to external computers or external storage devices via networks such as the Internet, local area networks, wide area networks, and / or wireless networks. The network may include copper cables, optical fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. Network adapter cards or network interfaces within each computing / processing device receive and transmit the computer-readable program instructions from the network for storage on the computer-readable storage media within the respective computing / processing device.

[0146] Computer-readable program code / instructions that perform actions can be any of the following: assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages. These programming languages ​​include object-oriented programming languages ​​such as Smalltalk, C++, or similar languages, as well as procedural programming languages ​​such as "C" or similar languages. Computer-readable program instructions can execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can connect to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or (for example, via the internet using an internet service provider) connect to an external computer. In some implementations, for example, electronic circuits including programmable logic circuits, field-programmable gate arrays (FPGAs) or programmable logic arrays (PLAs) can be personalized to execute computer-readable program instructions by utilizing state information of computer-readable program instructions to perform schemes or actions.

[0147] The computer-readable program instructions can be provided to a processor of a SoC, a general-purpose computer, a special-purpose computer, or other programmable data processing device to generate a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing device, create parts that implement the functions / behaviors specified in or in the functional blocks (or multiple functional blocks) of a flowchart and / or block diagram. The computer-readable program instructions can also be stored in a computer-readable storage medium that can instruct a computer, programmable data processing device, and / or other device to function in a particular manner, such that the computer-readable storage medium containing the instructions has an article of manufacture comprising instructions that implement the functions / behaviors specified in or in the functional blocks (or multiple functional blocks) of a flowchart and / or block diagram.

[0148] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device, and perform a series of action steps on the computer, other programmable apparatus or other device to generate a computer-implemented process, the result of which the instructions executed on the computer, other programmable apparatus or other device implement the functions / behaviors specified in the function blocks of the flowchart and / or block diagram or in the function blocks(s).

[0149] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and action of various implementations of systems, methods, and computer-readable media. In this regard, each functional block in a flowchart or block diagram may represent a module, segment, or portion of instructions having one or more executable instructions that implement the specified logical function. Methods, computer systems, and computer-readable media may include further functional blocks, fewer functional blocks, different functional blocks, or functional blocks configured differently compared to those depicted in the figures. In some alternative implementations, the functions described in the functional blocks may occur independently of the order shown in the figures. For example, two consecutively shown functional blocks may be executed practically or substantially simultaneously, or functional blocks may sometimes be executed in reverse order according to their associated functions. It should also be noted that the functional blocks of the block diagrams and / or flowcharts, and combinations of functional blocks in the block diagrams and / or flowcharts, can be implemented by a system based on dedicated hardware that performs the specified functions or actions or executes a combination of dedicated hardware and computer instructions.

[0150] It is evident that the systems and / or methods described in this specification can be implemented in various forms, including hardware, firmware, or a combination of hardware and software. The actual dedicated control hardware or software code used to implement the system and / or method is not a limitation on the implementation. Therefore, it is understood that the operation and behavior of the system and / or method are not described in this specification with reference to specific software code, and software and hardware can be designed to implement the system and / or method based on the description in this specification.

[0151] Alternatively, the computer program product including the computer program of the above embodiments may be stored in a storage medium or distributed through a communication line.

Claims

1. A system for enhancing threat analysis and risk assessment, comprising: Storage memory, which stores computer-executable instructions; and At least one processor is communicatively connected to the storage device. The at least one processor is configured to execute the instructions to perform the following actions: Obtain vehicle architecture information that includes multiple constituent elements of the vehicle and specifies multiple connections between these constituent elements, wherein... The plurality of constituent elements have at least one constituent element corresponding to the asset and at least one constituent element corresponding to the entry point; Generate a diagram that includes the multiple constituent elements and the multiple connections; Based on the chart, the path from the entry point to the asset that passes through at least one of the multiple connections is identified. Obtain an attack feasibility score for the stated path; Obtain the impact assessment data of the path; The risk level of the path is obtained based on the attack feasibility score of the path and the impact evaluation data of the path. as well as The mitigation strategy for the path is obtained based on the risk level of the path.

2. The system according to claim 1, wherein, The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of assets, and the at least one processor is configured to identify all paths from the entry point to each of the plurality of assets; or The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of entry points, and the at least one processor is configured to identify all paths from each of the plurality of entry points to the asset; or The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of assets and a plurality of constituent elements corresponding to a plurality of entry points, and the at least one processor is configured to identify all paths from each of the plurality of entry points to each of the plurality of assets.

3. The system according to claim 1 or 2, wherein, The multiple connections are associated with multiple weights representing the difficulty for an attacker to traverse the corresponding connections.

4. The system according to any one of claims 1 to 3, wherein, The at least one processor is configured to use a path search algorithm to identify the path from the entry point to the asset based on the graph.

5. The system according to any one of claims 1 to 4, wherein, The at least one processor is configured to obtain the attack feasibility score of the path by: determining an individual attack feasibility score associated with each connection within the path; and summing all individual attack feasibility scores associated with all connections within the path.

6. The system according to claim 5, wherein, The at least one processor is configured based on the following formula, namely, AS Path =SUM(MAX(AS) Connection () × Number of connections / Maximum number of connections This will aggregate all individual attack feasibility scores related to all connections within the stated path. The AS Path The AS represents the attack feasibility score associated with the path. Connection The individual attack feasibility score is represented by each connection within the path, where the number of connections represents the total number of connections within the path, and the maximum number of connections represents the largest number of connections within all identified paths.

7. The system according to claim 5 or 6, wherein, The at least one processor is configured to: determine individual mitigation strategies for each connection within the path based on a risk level determined according to each individual attack feasibility score, and combine all individual mitigation strategies associated with all connections within the path, thereby obtaining the mitigation strategy for the path based on the risk level of the path.

8. The system according to any one of claims 1 to 7, wherein, Obtain one or more of the following from the user: the attack feasibility score, the impact assessment data, the risk level, and the mitigation strategy.

9. A method for enhancing threat analysis and risk assessment, comprising: Obtain vehicle architecture information that includes multiple constituent elements in a vehicle and specifies multiple connections between the multiple constituent elements, wherein the multiple constituent elements have at least one constituent element corresponding to an asset and at least one constituent element corresponding to an entry point. Generate a diagram that includes the multiple constituent elements and the multiple connections; Based on the chart, the path from the entry point to the asset that passes through at least one of the multiple connections is identified. Obtain an attack feasibility score for the stated path; Obtain the impact assessment data of the path; The risk level of the path is obtained based on the attack feasibility score of the path and the impact assessment data of the path; and The mitigation strategy for the path is obtained based on the risk level of the path.

10. The method of claim 9, comprising: The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of assets, and the method includes identifying all paths from the entry point to each of the plurality of assets; or The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of entry points, and the method includes identifying all paths from each of the plurality of entry points to the asset; or The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of assets and a plurality of constituent elements corresponding to a plurality of entry points, and the method identifies all paths from each of the plurality of entry points to each of the plurality of assets.

11. The method according to claim 9 or 10, wherein, The multiple connections are associated with multiple weights representing the difficulty for an attacker to traverse the corresponding connections.

12. The method according to any one of claims 9 to 11, wherein, Using a path search algorithm, the path from the entry point to the asset is identified based on the graph.

13. The method according to any one of claims 9 to 12, wherein, The acquisition of the attack feasibility score of the path includes: determining an individual attack feasibility score associated with each connection within the path; and summing all individual attack feasibility scores associated with all connections within the path.

14. The method according to claim 13, wherein, The individual attack feasibility score associated with all connections within the path is based on the following formula, namely, AS Path =SUM(MAX(AS) Connection () × Number of connections / Maximum number of connections And were compiled, The AS Path The AS represents the attack feasibility score associated with the path. Connection The individual attack feasibility score is represented by each connection within the path, where the number of connections represents the total number of connections within the path, and the maximum number of connections represents the largest number of connections within all identified paths.

15. The method according to claim 13 or 14, wherein, The acquisition of the mitigation strategy for the path based on the risk level of the path includes: determining individual mitigation strategies for each connection within the path based on the risk level determined according to each individual attack feasibility score; and combining all individual mitigation strategies associated with all connections within the path.

16. The method according to any one of claims 9 to 15, wherein, Obtain one or more of the following from the user: the attack feasibility score, the impact assessment data, the risk level, and the mitigation strategy.

17. A computer program product comprising a non-transitory computer-readable recording medium having instructions executable by at least one processor to cause said at least one processor to perform a method, wherein, The computer program product includes a computer program that causes the processor to execute the method, the method comprising: Obtain vehicle architecture information that includes multiple constituent elements in a vehicle and specifies multiple connections between the multiple constituent elements, wherein the multiple constituent elements have at least one constituent element corresponding to an asset and at least one constituent element corresponding to an entry point. Generate a diagram that includes the multiple constituent elements and the multiple connections; Based on the chart, the path from the entry point to the asset that passes through at least one of the multiple connections is identified. Obtain an attack feasibility score for the stated path; Obtain the impact assessment data of the path; The risk level of the path is obtained based on the attack feasibility score of the path and the impact assessment data of the path; and The mitigation strategy for the path is obtained based on the risk level of the path.

18. The computer program product according to claim 17, wherein, The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of assets, and the method includes identifying all paths from the entry point to each of the plurality of assets; or The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of entry points, and the method includes identifying all paths from each of the plurality of entry points to the asset; or The plurality of constituent elements have a plurality of constituent elements corresponding to a plurality of assets and a plurality of constituent elements corresponding to a plurality of entry points, and the method identifies all paths from each of the plurality of entry points to each of the plurality of assets.

19. The computer program product according to claim 17 or 18, wherein, The multiple connections are associated with multiple weights representing the difficulty for an attacker to traverse the corresponding connections.

20. The computer program product according to any one of claims 17 to 19, wherein, Using a path search algorithm, the path from the entry point to the asset is identified based on the graph.

21. The computer program product according to any one of claims 17 to 20, wherein, The acquisition of the attack feasibility score of the path includes: determining an individual attack feasibility score associated with each connection within the path; and summing all individual attack feasibility scores associated with all connections within the path.

22. The computer program product according to claim 21, wherein, The individual attack feasibility score associated with all connections within the path is based on the following formula, namely, AS Path =SUM(MAX(AS) Connection () × Number of connections / Maximum number of connections And were compiled, The AS Path The AS represents the attack feasibility score associated with the path. Connection The individual attack feasibility score is represented by each connection within the path, where the number of connections represents the total number of connections within the path, and the maximum number of connections represents the largest number of connections within all identified paths.

23. The computer program product according to claim 21 or 22, wherein, The acquisition of the mitigation strategy for the path based on the risk level of the path includes: determining individual mitigation strategies for each connection within the path based on the risk level determined according to each individual attack feasibility score; and combining all individual mitigation strategies associated with all connections within the path.

24. The computer program product according to any one of claims 17 to 23, wherein, Obtain one or more of the following from the user: the attack feasibility score, the impact assessment data, the risk level, and the mitigation strategy.