VWAY

뉴스룸
회사소식


행사 참가㈜브이웨이, Automotive Cybersecurity Europe 2023 참석 및 발표 소식입니다.

(주) 브이웨이는 2023년 11월 27일부터 30일까지 독일의 Leonardo Royal Hotel in Munich에서 열리는 Automotive Cyber Security Europe 행사에 참여합니다. 본 행사는 ISO/SAE 21434와 R155/R156의 대응을 위해 여러가지의 도전 과제들에 대한 의제를 나누고 해결점을 찾기 위해 유럽 및 전세계의 CyberSeucirty 전문가들이 모이는 컨퍼런스입니다.


Automotive Cyber Security Europe 2023 홍보 이미지 — Automotive Cyber Security, Connectivity & SDV Week - Europe 2023 의 일부


특히 자사의 유럽 및 미국 영업 담당자인 Stephen Porter가 어떻게 STPA가 Cybersecurty에 활용될 수 있으며 ISO/SAE 21434에서 수행되는 TARA의 분석을 어떻게 뒷받침 할 수 있는지 발표가 준비되어 있습니다.


Automotive Cyber Security Europe 2023 발표자 소개 — 브이웨이 SVP EMEA Stephen Porter. Wind River·Siemens·Jama Software 등 여러 소프트웨어 기업의 성장에 함께했고 Inovar·ReachOut·Market Potential 을 창업하거나 공동 창업했다는 소개


MAIN STAGE DAY TWO – WEDNESDAY 29th NOVEMBER 2023

12:20 PM HOW STPA IS BEING USED IN AUTOMOTIVE CYBERSECURITY


STPA represents a new paradigm that is being applied in safety analysis and management within our industry - It’s application in cybersecurity, to improve resilience against cyber disruptions through STPA-Sec is new to many. In this presentation we will consider "How STPA is being used in automotive cybersecurity" and we will introduce: -

  • STPA-Sec, what it is and why you should care.

  • How to implement TARA guidelines when using STPA-Sec.

  • Where threat modelling can be used and how to do so (i.e. STRIDE and beyond).

Designing-in effective safeguards begins at the concept phase, enables the definition and refinement of precise design recommendations, and continues throughout the product lifecycle, to operations and product retirement. Discover life beyond 21434…



또한 스폰서로 참여하여 TARA, STPA, FMEA, FTA의 안전 및 사이버보안을 분석을 지원하는 VisualPro 및 개발 SBOM 취약점 관리 및 CSMS 준수를 위한 Audit을 도와주는 ALM 도구 Teamer를 선보일 예정입니다.


VisualPro TARA 화면 — 차내 WiFi 모듈 시스템의 Attack Path List 와 Attack Path Diagram. 위협 시나리오 TH-1~TH-7(내부망 물리적 접근을 통한 신원 도용, 네트워크 취약점 노출, 기업 기밀 유출, 데이터 외부 유출 등)과 공격 경로 AP-1~AP-6, 왼쪽에 자산·위협분석·리스크평가·보고서 메뉴 트리, 아래에 블록 다이어그램

VisualPro TARA


Teamer 의 SBOM 관리 화면 — 사이버보안 감사 프로젝트에서 생성한 취약점 보고서. 심각도별 분포 원그래프(High 45, Medium 16, Critical 12, Low 5)와 컴포넌트별 취약점 목록(dropwizard-validation CVE-2020-11002·CVE-2020-5245, h2·junit·jetty-io·jackson-databind 의 GitHub GHSA 항목)을 표시하고, 왼쪽 메뉴에 ISO/SAE 21434 조항(9. 개념, 10. 제품 개발, 11. 사이버보안 검증, 15. 위협 분석 및 리스크 평가 등) 트리

Teamer - SBOM Vulnerability Management


자동차 와이어프레임 주변의 홀로그램 패널을 손가락으로 만지는 그림 — Automotive Cybersecurity Europe 참가 소식 표제