{"id":"https://openalex.org/W4389306349","doi":"https://doi.org/10.1145/3631204.3631864","title":"From TARA to Test: Automated Automotive Cybersecurity Test Generation Out of Threat Modeling","display_name":"From TARA to Test: Automated Automotive Cybersecurity Test Generation Out of Threat Modeling","publication_year":2023,"publication_date":"2023-12-04","ids":{"openalex":"https://openalex.org/W4389306349","doi":"https://doi.org/10.1145/3631204.3631864"},"language":"en","primary_location":{"id":"doi:10.1145/3631204.3631864","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3631204.3631864","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 7th ACM Computer Science in Cars Symposium","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5037409153","display_name":"Stefan Marksteiner","orcid":"https://orcid.org/0000-0001-8556-1541"},"institutions":[{"id":"https://openalex.org/I82509713","display_name":"M\u00e4lardalen University","ror":"https://ror.org/033vfbz75","country_code":"SE","type":"education","lineage":["https://openalex.org/I82509713"]}],"countries":["SE"],"is_corresponding":true,"raw_author_name":"Stefan F Marksteiner","raw_affiliation_strings":["AVL List GmbH, AT and M\u00e4lardalen University, Sweden"],"raw_orcid":"https://orcid.org/0000-0001-8556-1541","affiliations":[{"raw_affiliation_string":"AVL List GmbH, AT and M\u00e4lardalen University, Sweden","institution_ids":["https://openalex.org/I82509713"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019047546","display_name":"Christoph Schmittner","orcid":"https://orcid.org/0000-0003-4430-6813"},"institutions":[{"id":"https://openalex.org/I132118926","display_name":"Austrian Institute of Technology","ror":"https://ror.org/04knbh022","country_code":"AT","type":"facility","lineage":["https://openalex.org/I132118926"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Christoph Schmittner","raw_affiliation_strings":["AIT Austrian Institute of Technology GmbH, AT"],"raw_orcid":"https://orcid.org/0000-0003-4430-6813","affiliations":[{"raw_affiliation_string":"AIT Austrian Institute of Technology GmbH, AT","institution_ids":["https://openalex.org/I132118926"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086529288","display_name":"Korbinian Christl","orcid":"https://orcid.org/0000-0001-8873-9122"},"institutions":[{"id":"https://openalex.org/I132118926","display_name":"Austrian Institute of Technology","ror":"https://ror.org/04knbh022","country_code":"AT","type":"facility","lineage":["https://openalex.org/I132118926"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Korbinian Christl","raw_affiliation_strings":["AIT Austrian Institute of Technology GmbH, AT"],"raw_orcid":"https://orcid.org/0000-0001-8873-9122","affiliations":[{"raw_affiliation_string":"AIT Austrian Institute of Technology GmbH, AT","institution_ids":["https://openalex.org/I132118926"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052399473","display_name":"Dejan Ni\u010dkovi\u0107","orcid":"https://orcid.org/0000-0001-5468-0396"},"institutions":[{"id":"https://openalex.org/I132118926","display_name":"Austrian Institute of Technology","ror":"https://ror.org/04knbh022","country_code":"AT","type":"facility","lineage":["https://openalex.org/I132118926"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Dejan Nickovic","raw_affiliation_strings":["AIT Austrian Institute of Technology GmbH, AT"],"raw_orcid":"https://orcid.org/0000-0001-5468-0396","affiliations":[{"raw_affiliation_string":"AIT Austrian Institute of Technology GmbH, AT","institution_ids":["https://openalex.org/I132118926"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052013615","display_name":"Mikael Sj\u00f6din","orcid":"https://orcid.org/0000-0001-7586-0409"},"institutions":[{"id":"https://openalex.org/I82509713","display_name":"M\u00e4lardalen University","ror":"https://ror.org/033vfbz75","country_code":"SE","type":"education","lineage":["https://openalex.org/I82509713"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Mikael Sj\u00f6din","raw_affiliation_strings":["M\u00e4lardalen University, SE"],"raw_orcid":"https://orcid.org/0000-0001-7586-0409","affiliations":[{"raw_affiliation_string":"M\u00e4lardalen University, SE","institution_ids":["https://openalex.org/I82509713"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5078919695","display_name":"Marjan Sirjani","orcid":"https://orcid.org/0000-0001-5478-0987"},"institutions":[{"id":"https://openalex.org/I82509713","display_name":"M\u00e4lardalen University","ror":"https://ror.org/033vfbz75","country_code":"SE","type":"education","lineage":["https://openalex.org/I82509713"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Marjan Sirjani","raw_affiliation_strings":["M\u00e4lardalen University, SE"],"raw_orcid":"https://orcid.org/0000-0001-5478-0987","affiliations":[{"raw_affiliation_string":"M\u00e4lardalen University, SE","institution_ids":["https://openalex.org/I82509713"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5037409153"],"corresponding_institution_ids":["https://openalex.org/I82509713"],"apc_list":null,"apc_paid":null,"fwci":0.4484,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.71749006,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"10"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13295","display_name":"Safety Systems Engineering in Autonomy","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/2213","display_name":"Safety, Risk, Reliability and Quality"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9926999807357788,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.7144850492477417},{"id":"https://openalex.org/keywords/automotive-industry","display_name":"Automotive industry","score":0.5912805795669556},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5778920650482178},{"id":"https://openalex.org/keywords/test","display_name":"Test (biology)","score":0.5750395059585571},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5319486260414124},{"id":"https://openalex.org/keywords/model-based-testing","display_name":"Model-based testing","score":0.45810627937316895},{"id":"https://openalex.org/keywords/test-case","display_name":"Test case","score":0.4522162675857544},{"id":"https://openalex.org/keywords/security-testing","display_name":"Security testing","score":0.4300031363964081},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.4231272339820862},{"id":"https://openalex.org/keywords/risk-analysis","display_name":"Risk analysis (engineering)","score":0.405060738325119},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.3356836140155792},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.32817864418029785},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.11148592829704285}],"concepts":[{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.7144850492477417},{"id":"https://openalex.org/C526921623","wikidata":"https://www.wikidata.org/wiki/Q190117","display_name":"Automotive industry","level":2,"score":0.5912805795669556},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5778920650482178},{"id":"https://openalex.org/C2777267654","wikidata":"https://www.wikidata.org/wiki/Q3519023","display_name":"Test (biology)","level":2,"score":0.5750395059585571},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5319486260414124},{"id":"https://openalex.org/C165825675","wikidata":"https://www.wikidata.org/wiki/Q1399743","display_name":"Model-based testing","level":4,"score":0.45810627937316895},{"id":"https://openalex.org/C128942645","wikidata":"https://www.wikidata.org/wiki/Q1568346","display_name":"Test case","level":3,"score":0.4522162675857544},{"id":"https://openalex.org/C195518309","wikidata":"https://www.wikidata.org/wiki/Q13424265","display_name":"Security testing","level":5,"score":0.4300031363964081},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.4231272339820862},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.405060738325119},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.3356836140155792},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.32817864418029785},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.11148592829704285},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C146978453","wikidata":"https://www.wikidata.org/wiki/Q3798668","display_name":"Aerospace engineering","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.0},{"id":"https://openalex.org/C152877465","wikidata":"https://www.wikidata.org/wiki/Q208042","display_name":"Regression analysis","level":2,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3631204.3631864","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3631204.3631864","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 7th ACM Computer Science in Cars Symposium","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/17","display_name":"Partnerships for the goals","score":0.4399999976158142}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W572872720","https://openalex.org/W1521415124","https://openalex.org/W1602380388","https://openalex.org/W1754293565","https://openalex.org/W1994350081","https://openalex.org/W2014151884","https://openalex.org/W2054127354","https://openalex.org/W2083658929","https://openalex.org/W2103787906","https://openalex.org/W2146024157","https://openalex.org/W2694044524","https://openalex.org/W2735780801","https://openalex.org/W2766912013","https://openalex.org/W2767556742","https://openalex.org/W2934182273","https://openalex.org/W2997353660","https://openalex.org/W3006653265","https://openalex.org/W3126968534","https://openalex.org/W3172624954","https://openalex.org/W3180935061","https://openalex.org/W3195685258","https://openalex.org/W3197367695","https://openalex.org/W4250346387","https://openalex.org/W4313413965","https://openalex.org/W6741196130"],"related_works":["https://openalex.org/W1663662652","https://openalex.org/W2127350021","https://openalex.org/W2018145554","https://openalex.org/W4379113489","https://openalex.org/W1598160211","https://openalex.org/W2903616347","https://openalex.org/W2204156854","https://openalex.org/W2246269111","https://openalex.org/W1490395385","https://openalex.org/W2061183036"],"abstract_inverted_index":{"The":[0],"United":[1],"Nations":[2],"Economic":[3],"Commission":[4],"for":[5,47,145],"Europe":[6],"(UNECE)":[7],"demands":[8],"the":[9,20,52,63,81,112,127,170,190,212,215,220,235,239],"management":[10],"of":[11,22,35,54,114,172,214,219,249],"cyber":[12],"security":[13,48],"risks":[14],"in":[15,58,80,96,150,156,234,256],"vehicle":[16],"design":[17],"and":[18,33,83,117,134,177,225,238],"that":[19,90],"effectiveness":[21],"these":[23],"measures":[24,216],"is":[25,124,229],"verified":[26,224],"by":[27,184,205],"testing.":[28],"Generally,":[29],"with":[30,89,208],"rising":[31],"complexity":[32],"openness":[34],"systems":[36],"via":[37],"software-defined":[38],"vehicles,":[39],"verification":[40],"through":[41],"testing":[42,57,66,183],"becomes":[43],"a":[44,97,103,141,151,163,201,230,253],"very":[45],"important":[46],"assurance.":[49],"This":[50,100,148,193],"mandates":[51],"introduction":[53],"industrial-grade":[55],"cybersecurity":[56,65],"automotive":[59,64],"development":[60],"processes.":[61],"Currently,":[62],"procedures":[67],"are":[68],"not":[69],"specified":[70],"or":[71],"automated":[72],"enough":[73],"to":[74,77,86,105,125,189],"be":[75,198,223,262],"able":[76],"deliver":[78],"tests":[79],"amount":[82],"thoroughness":[84],"needed":[85],"keep":[87],"up":[88],"regulation,":[91],"let":[92],"alone":[93],"doing":[94],"so":[95],"cost-efficient":[98],"manner.":[99],"paper":[101],"presents":[102],"methodology":[104],"automatically":[106],"generate":[107],"technology-agnostic":[108],"test":[109,164,195,203,244],"scenarios":[110],"from":[111,140],"results":[113,149],"threat":[115,129],"analysis":[116],"risk":[118],"assessment":[119],"(TARA)":[120],"process.":[121],"Our":[122],"approach":[123],"transfer":[126],"resulting":[128],"models":[130],"into":[131,182,200],"attack":[132,146,191],"trees":[133],"label":[135],"their":[136],"edges":[137],"using":[138],"actions":[139],"domain-specific":[142],"language":[143],"(DSL)":[144],"descriptions.":[147],"labelled":[152,159],"transitions":[153],"system":[154],"(LTS),":[155],"which":[157],"every":[158],"path":[160],"intrinsically":[161],"forms":[162],"scenario.":[165],"In":[166],"addition,":[167],"we":[168],"include":[169],"concept":[171],"Cybersecurity":[173],"Assurance":[174],"Levels":[175],"(CALs)":[176],"Targeted":[178],"Attack":[179],"Feasibility":[180],"(TAF)":[181],"assigning":[185],"them":[186],"as":[187,258],"costs":[188],"path.":[192],"abstract":[194],"scenario":[196],"can":[197,222],"compiled":[199],"concrete":[202],"case":[204],"augmenting":[206],"it":[207,250],"implementation":[209],"details.":[210],"Therefore,":[211],"efficacy":[213],"taken":[217],"because":[218],"TARA":[221,228],"documented.":[226],"As":[227],"de-facto":[231],"mandatory":[232],"step":[233],"UNECE":[236],"regulation":[237],"relevant":[240],"ISO":[241],"standard,":[242],"automatic":[243],"generation":[245],"(also":[246],"mandatory)":[247],"out":[248],"could":[251,261],"mean":[252],"significant":[254],"improvement":[255],"efficiency,":[257],"two":[259],"steps":[260],"done":[263],"at":[264],"once.":[265]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
