A Threat Analysis and Test-based Study of OTA Software Updates for Automobiles
Software plays an important role in the development of modern vehicles,and over-the-air updates is an important alternative that brings convenient and efficient.While there are several advantages of OTA updates,information security threats that introduced must also be considered seriously.Based on the CSTC asset identification,threat scenario identification,attack path analysis and attack feasibility evaluation specification for automotive software OTA updates,comprehensive information security tests were conducted by CSTC.This paper summarizes characteristic information security vulnerabilities of automotive software OTA updates in order to promote the automotive software development.