Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles

Urban mobility is in the midst of a revolution, driven by the convergence of technologies such as artificial intelligence, on-demand ride services, and Internet-connected and self-driving vehicles. Technological advancements often lead to new hazards. Coupled with the increased levels of automation...

Full description

Bibliographic Details
Main Authors: Lee, Chee Wei, Madnick, Stuart
Other Authors: Massachusetts Institute of Technology. Engineering Systems Division
Format: Article
Published: Multidisciplinary Digital Publishing Institute 2022
Online Access:https://hdl.handle.net/1721.1/133165.2
_version_ 1811091899174354944
author Lee, Chee Wei
Madnick, Stuart
author2 Massachusetts Institute of Technology. Engineering Systems Division
author_facet Massachusetts Institute of Technology. Engineering Systems Division
Lee, Chee Wei
Madnick, Stuart
author_sort Lee, Chee Wei
collection MIT
description Urban mobility is in the midst of a revolution, driven by the convergence of technologies such as artificial intelligence, on-demand ride services, and Internet-connected and self-driving vehicles. Technological advancements often lead to new hazards. Coupled with the increased levels of automation and connectivity in the new generation of autonomous vehicles, cybersecurity is emerging as a key threat affecting these vehicles. Traditional hazard analysis methods treat safety and security in isolation and are limited in their ability to account for interactions among organizational, sociotechnical, human, and technical components. In response to these challenges, the cybersafety method, based on System Theoretic Process Analysis (STPA and STPA-Sec), was developed to meet the growing need to holistically analyze complex sociotechnical systems. We applied cybersafety to coanalyze safety and security hazards, as well as identify mitigation requirements. The results were compared with another promising method known as Combined Harm Analysis of Safety and Security for Information Systems (CHASSIS). Both methods were applied to the Mobility-as-a-Service (MaaS) and Internet of Vehicles (IoV) use cases, focusing on over-the-air software updates feature. Overall, cybersafety identified additional hazards and more effective requirements compared to CHASSIS. In particular, cybersafety demonstrated the ability to identify hazards due to unsafe/unsecure interactions among sociotechnical components. This research also suggested using CHASSIS methods for information lifecycle analysis to complement and generate additional considerations for cybersafety. Finally, results from both methods were backtested against a past cyber hack on a vehicular system, and we found that recommendations from cybersafety were likely to mitigate the risks of the incident.
first_indexed 2024-09-23T15:09:46Z
format Article
id mit-1721.1/133165.2
institution Massachusetts Institute of Technology
last_indexed 2024-09-23T15:09:46Z
publishDate 2022
publisher Multidisciplinary Digital Publishing Institute
record_format dspace
spelling mit-1721.1/133165.22024-02-23T21:09:05Z Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles Lee, Chee Wei Madnick, Stuart Massachusetts Institute of Technology. Engineering Systems Division Sloan School of Management Massachusetts Institute of Technology. Institute for Data, Systems, and Society Urban mobility is in the midst of a revolution, driven by the convergence of technologies such as artificial intelligence, on-demand ride services, and Internet-connected and self-driving vehicles. Technological advancements often lead to new hazards. Coupled with the increased levels of automation and connectivity in the new generation of autonomous vehicles, cybersecurity is emerging as a key threat affecting these vehicles. Traditional hazard analysis methods treat safety and security in isolation and are limited in their ability to account for interactions among organizational, sociotechnical, human, and technical components. In response to these challenges, the cybersafety method, based on System Theoretic Process Analysis (STPA and STPA-Sec), was developed to meet the growing need to holistically analyze complex sociotechnical systems. We applied cybersafety to coanalyze safety and security hazards, as well as identify mitigation requirements. The results were compared with another promising method known as Combined Harm Analysis of Safety and Security for Information Systems (CHASSIS). Both methods were applied to the Mobility-as-a-Service (MaaS) and Internet of Vehicles (IoV) use cases, focusing on over-the-air software updates feature. Overall, cybersafety identified additional hazards and more effective requirements compared to CHASSIS. In particular, cybersafety demonstrated the ability to identify hazards due to unsafe/unsecure interactions among sociotechnical components. This research also suggested using CHASSIS methods for information lifecycle analysis to complement and generate additional considerations for cybersafety. Finally, results from both methods were backtested against a past cyber hack on a vehicular system, and we found that recommendations from cybersafety were likely to mitigate the risks of the incident. 2022-01-20T15:47:25Z 2021-10-27T17:01:21Z 2022-01-20T15:47:25Z 2021-05 2021-05 2021-05-24T15:07:16Z Article http://purl.org/eprint/type/JournalArticle 2079-9292 https://hdl.handle.net/1721.1/133165.2 Electronics 10 (10): 1220 (2021) http://dx.doi.org/10.3390/electronics10101220 Electronics Creative Commons Attribution https://creativecommons.org/licenses/by/4.0/ application/octet-stream Multidisciplinary Digital Publishing Institute Multidisciplinary Digital Publishing Institute
spellingShingle Lee, Chee Wei
Madnick, Stuart
Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles
title Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles
title_full Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles
title_fullStr Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles
title_full_unstemmed Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles
title_short Cybersafety Approach to Cybersecurity Analysis and Mitigation for Mobility-as-a-Service and Internet of Vehicles
title_sort cybersafety approach to cybersecurity analysis and mitigation for mobility as a service and internet of vehicles
url https://hdl.handle.net/1721.1/133165.2
work_keys_str_mv AT leecheewei cybersafetyapproachtocybersecurityanalysisandmitigationformobilityasaserviceandinternetofvehicles
AT madnickstuart cybersafetyapproachtocybersecurityanalysisandmitigationformobilityasaserviceandinternetofvehicles