ASSESSMENT OF CYBER RISKS IN VEHICLES BASED ON ATTACK SURFACE ANALYSIS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1277Keywords:
CAN bus; vulnerability; threat; automobile; cybersecurity; attack.Abstract
The article examines the problem of analyzing cyber threats in modern vehicles, which are increasingly becoming complex cyber-physical systems with a large number of electronic control units, internal networks, wireless interfaces, sensors, diagnostic ports, infotainment modules, and external digital services. It is substantiated that vehicle security cannot be limited solely to the study of the CAN bus, since the actual attack surface includes a much broader set of interaction channels with the environment and the user. Particular attention is paid to the threat modeling approach, which enables the systematic identification of entry points, the determination of input signal receivers, the analysis of trust boundaries between components, and the identification of potential attack propagation paths within the automotive architecture. The paper systematizes the main groups of threats, including threats related to remote communication interfaces, Wi-Fi, Bluetooth, cellular communication, keyless entry systems, TPMS, USB ports, OBD-II, infotainment systems, diagnostic mechanisms, and internal vehicle networks. It is shown that the most critical scenarios are those in which an external channel can be used to access the internal systems of a vehicle or to influence electronic control units. The risks of violating confidentiality, integrity, and availability are considered separately, including location tracking, data spoofing, malware installation, blocking vehicle functions, and manipulating messages within the internal network. It is proposed to consider the threat model as a dynamic document that should be updated throughout the entire vehicle life cycle, taking into account changes in software, architecture, and external services. The practical significance of the study lies in the formation of a structured approach to identifying, classifying, and prioritizing risks, which can be used during the auditing, testing, and design of secure automotive systems.
Downloads
References
Kifor, C. V., & Popescu, A. (2024). Automotive cybersecurity: A survey on frameworks, standards, and testing and monitoring technologies. Sensors, 24(18), Article 6139. https://doi.org/10.3390/s24186139
Ebrahimi, M., Striessnig, C., Castella Triginer, J., & Schmittner, C. (2022). Identification and verification of attack-tree threat models in connected vehicles. In SAE 2022 Intelligent and Connected Vehicles Symposium. SAE Technical Paper 2022-01-7087. https://doi.org/10.4271/2022-01-7087
International Organization for Standardization. (2021). ISO/SAE 21434:2021: Road vehicles–Cybersecurity engineering. ISO. https://www.iso.org/standard/70918.html
United Nations Economic Commission for Europe. (2021). UN Regulation No. 155: Cyber security and cyber security management system. UNECE. https://unece.org/transport/documents/2021/03/standards/un-regulation-no-155-cyber-security-and-cyber-security
Häckel, T., Meyer, P., Stahlbock, L., Langer, F., Eckhardt, S. A., Korf, F., & Schmidt, T. C. (2023). A multilayered security infrastructure for connected vehicles: First lessons from the field (arXiv:2310.10336). arXiv. https://doi.org/10.48550/arXiv.2310.10336
Yousseef, A., Satam, S., Latibari, B. S., Pacheco, J., Salehi, S., Hariri, S., & Satam, P. (2024). Autonomous vehicle security: A deep dive into threat modeling (arXiv:2412.15348). arXiv. https://doi.org/10.48550/arXiv.2412.15348
Shah, U. M., Minhas, D. M., Kifayat, K., Shah, K. A., & Frey, G. (2025). Threat modeling and attacks on digital twins of vehicles: A systematic literature review. Smart Cities, 8(5), Article 142. https://doi.org/10.3390/smartcities8050142
IBM. (n.d.). What is an attack surface? IBM Think. Retrieved June 17, 2026, from https://www.ibm.com/think/topics/attack-surface
OWASP Foundation. (n.d.). Threat modeling. OWASP. Retrieved June 17, 2026, from https://owasp.org/www-community/Threat_Modeling
Moshtari, S., Okutan, A., & Mirakhorli, M. (2021). A grounded theory based approach to characterize software attack surfaces (arXiv:2112.01635). arXiv. https://doi.org/10.48550/arXiv.2112.01635
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Анастасія Журавчак, Даниїл Журавчак, Юрій Журавчак

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.