A method for automatically collecting product-related cybersecurity information

Type of work: Master thesis (External - Webasto)

Technical Background:

To manage upcoming vulnerabilities concerning products of Webasto, a continuous monitoring and collection of Cybersecurity Information is mandatory. Cybersecurity information means all information available concerning the security of electronic components, such as vulnerability discription.

Task Description:

The following research questions shall be answered:

  • What are the right methods to gather Cybersecrurity information and what would be good sources of those information related to company products?

  • How can the importance of such information being judged in relation to company products? How to attack company products? What is the impact of these attacks?

  • How can this process structurize, organize, collect and share information in order to gain maximal effectiveness? Which threat groups exist?

  • Which methodology is suitable for collecting and storing Cyber Security information?

  • What sources are already available in the automotive market or should be used other sources from different industries to gather this information?

A prototypical data model should to be developed for this purpose. The model shall be populated with some example data. This task could be realized in software or in a paper description. Software would be prefered.

Possible work steps:

  • Understanding the context of this work. State of the art of vulneribility assessment.
  • Collecting and evaluating potential information sources of vulnerabilities
  • Concept for process of matching vulnerabilities with products
  • Creating a data model to store vulnerability information.
  • Working prototype.
  • Evaluation of own solution.

Literature and Resources:

  • Kotenko, Igor V., Olga Polubelova, and Igor Saenko. "Data Repository for Security Information and Event Management in Service Infrastructures." SECRYPT 24 (2012): 308.
  • Kotenko, Igor, et al. "An ontology-based storage of security information." Information Technology and Control 47.4 (2018): 655-667.
  • Cook, Allan, et al. "The industrial control system cyber defence triage process." Computers & Security 70 (2017): 467-481.
  • ISO 21434 Automotive Cybersecurity Standard

Supervisor: Timo Bruderek (Webasto)

Reviewer: Dr. Thomas Mundt (thomas.mundt@uni-rostock.de)

Prerequisites: Basic skills in the area of security are advantageous.