A method for automatically collecting product-related cybersecurity information
Type of work: Master thesis (External - Webasto)
Technical Background:
To manage upcoming vulnerabilities concerning products of Webasto, a continuous monitoring and collection of Cybersecurity Information is mandatory. Cybersecurity information means all information available concerning the security of electronic components, such as vulnerability discription.
Task Description:
The following research questions shall be answered:
What are the right methods to gather Cybersecrurity information and what would be good sources of those information related to company products?
How can the importance of such information being judged in relation to company products? How to attack company products? What is the impact of these attacks?
How can this process structurize, organize, collect and share information in order to gain maximal effectiveness? Which threat groups exist?
Which methodology is suitable for collecting and storing Cyber Security information?
What sources are already available in the automotive market or should be used other sources from different industries to gather this information?
A prototypical data model should to be developed for this purpose. The model shall be populated with some example data. This task could be realized in software or in a paper description. Software would be prefered.
Possible work steps:
- Understanding the context of this work. State of the art of vulneribility assessment.
- Collecting and evaluating potential information sources of vulnerabilities
- Concept for process of matching vulnerabilities with products
- Creating a data model to store vulnerability information.
- Working prototype.
- Evaluation of own solution.
Literature and Resources:
- Kotenko, Igor V., Olga Polubelova, and Igor Saenko. "Data Repository for Security Information and Event Management in Service Infrastructures." SECRYPT 24 (2012): 308.
- Kotenko, Igor, et al. "An ontology-based storage of security information." Information Technology and Control 47.4 (2018): 655-667.
- Cook, Allan, et al. "The industrial control system cyber defence triage process." Computers & Security 70 (2017): 467-481.
- ISO 21434 Automotive Cybersecurity Standard
Supervisor: Timo Bruderek (Webasto)
Reviewer: Dr. Thomas Mundt (thomas.mundt@uni-rostock.de)
Prerequisites: Basic skills in the area of security are advantageous.
