Security and Privacy in New Computing Environments. Second EAI International Conference, SPNCE 2019, Tianjin, China, April 13–14, 2019, Proceedings

Research Article

Study on Incident Response System of Automotive Cybersecurity

Download
232 downloads
  • @INPROCEEDINGS{10.1007/978-3-030-21373-2_16,
        author={Yanan Zhang and Peiji Shi and Yangyang Liu and Shengqiang Han and Baoying Mu and Jia Zheng},
        title={Study on Incident Response System of Automotive Cybersecurity},
        proceedings={Security and Privacy in New Computing Environments. Second EAI International Conference, SPNCE 2019, Tianjin, China, April 13--14, 2019, Proceedings},
        proceedings_a={SPNCE},
        year={2019},
        month={6},
        keywords={Automotive cybersecurity Incident response Evaluation system Questionnaire},
        doi={10.1007/978-3-030-21373-2_16}
    }
    
  • Yanan Zhang
    Peiji Shi
    Yangyang Liu
    Shengqiang Han
    Baoying Mu
    Jia Zheng
    Year: 2019
    Study on Incident Response System of Automotive Cybersecurity
    SPNCE
    Springer
    DOI: 10.1007/978-3-030-21373-2_16
Yanan Zhang1, Peiji Shi1,*, Yangyang Liu1, Shengqiang Han1, Baoying Mu1, Jia Zheng1
  • 1: China Automotive Technology and Research Center Co. Ltd.
*Contact email: spj_2004@126.com

Abstract

With the development of Intelligent Connected Vehicles, a large number of automobile cybersecurity incidents also occur. Scientific and reasonable incident response system is the key technology to ensure the successful handling of cybersecurity incidents. From the point of view of management, referring to the construction of incident response system in IT industry and combining with the characteristics of automobile cybersecurity, this paper puts forward the framework of incident response system for automobile cybersecurity. The framework includes five aspects: plan and prepare, detection and reporting, assessment and decision, responses and lessons learnt. Emphasis is laid on the formulation and updating of management policy, the establishment of incident response team, incident coordination mechanism and so on. Then, based on the method of questionnaire survey, the evaluation method of incident response capability is put forward. The research method makes up for the blank of automobile industry in cybersecurity incident response, and has an important positive role in reducing the adverse impact of security incidents.