Vehicle-Level Security Controls
In Chapter 3, we discussed the different types of cybersecurity threats in automotive systems and how they relate to the vehicle’s E/E architecture. Instead of jumping straight into technical solutions, we emphasized the importance of a systematic engineering approach to identifying and managing risks. Now, in this chapter, we will shift our focus to technical solutions to minimize cybersecurity risks through a defense-in-depth strategy. It is sometimes possible to eliminate a risk by removing a risky feature from the product’s design. Most of the time, we must find ways to manage the risks using appropriate cybersecurity controls. As we will see in this chapter, introducing cybersecurity controls can lead to increased costs from added components as well as impact the system’s performance. Furthermore, with each design modification, the vehicle risk profile is impacted, sometimes negatively, due to the potential for misconfiguration...