摘要
本文以一款集成式机械式自动变速器(Automated Manual Transmission,AMT)为研究对象,系统开展威胁分析与风险评估(Threat Analysis and Risk Assessment,TARA)。在识别出控制器局域网(Controller Area Network,CAN)报文、固件、密钥等 8 项核心安全资产的基础上,分析潜在危害场景,从安全、财产、操作性及隐私四个维度量化危害等级。针对各危害场景,反向分析可能的攻击行为以构建威胁场景,从时间、专业知识、产品知识、机会窗口与设备五个维度综合评估攻击可行性。最后,综合危害等级与攻击可行性,通过风险矩阵确定各个威胁场景的风险等级,进而提出降低、转移或保留等处置策略。
Abstract
This paper conducts threat analysis and risk assessment for an integrated Automated Manual Transmission (AMT). Based on the identification of eight core security assets, including Controller Area Network (CAN) messages, firmware, etc. potential damage scenarios are analyzed, and the impact rating is quantified from four dimensions: safety, property, operability, and privacy. For each damage scenario, possible attack path are reversely analyzed to construct threat scenarios, and the attack feasibility is comprehensively evaluated from five dimensions: time, expertise, product knowledge, window of opportunity, and equipment. Finally, by combining hazard levels and attack feasibility, the risk matrix is adopted to determine the risk level of each threat scenario, and corresponding treatment strategies such as reduction, transfer, or retention are proposed.
关键词
机械式自动变速器 /
信息安全 /
威胁分析与风险评估 /
ISO/SAE 21434
Key words
AMT /
cybersecurity /
TARA /
ISO/SAE 21434
刘 丹, 李佳豪, 冀帆帆, 王 宇, 周 帅.
商用车 AMT 信息安全 TARA 分析[J]. 汽车电器. 2026, 1(8): 39-41
Liu Dan , Li Jiahao , Ji Fanfan , Wang Yu , Zhou Shuai.
Cybersecurity TARA Analysis for Commercial Vehicle AMT[J]. AUTO ELECTRIC PARTS. 2026, 1(8): 39-41
{{custom_sec.title}}
{{custom_sec.title}}
{{custom_sec.content}}
参考文献
[1] 刘丹 , 李佳豪 , 王宇 , 等 . 商用车 AMT 信息安全纵深防御体系研究 [J]. 重型汽车,2026(2):20-22.
[2] ISO/SAE 21434—2021 Road Vehicles Cybersecurity Management System[S].
[3] 刘煜 , 种晶 , 张永帅 , 等 . 汽车诊断系统信息安全 TARA分析及测试评价研究 [J]. 汽车电器,2024(8):82-86.
[4] 周佳 . 智能网联汽车网络安全防御技术研究 [D]. 长沙 : 湖南大学,2021.
[5] 魏洪乾,时培成,张幽彤 . 汽车信息安全:面向总线网络的伪造攻击检测技术 [J]. 机械工程学报,2024,60(10):476-486.