Program Introduction, Project Descriptions, and Project Allocations
Being reading related literature in the domain of:
a. Risk assessment frameworks for Connected and Autonomous Vehicles (CAV)
b. Different attacks and defenses identified and proposed for CAVs
Being reading related literature in the domain of:
a. Risk assessment frameworks for Connected and Autonomous Vehicles (CAV)
b. Different attacks and defenses identified and proposed for CAVs
Start developing draft of attack repository to be considered for project
Other notes and deliverables:
Memorial day holiday
Wrap up CAV related literature review
Work towards formalizing attack repository
Begin work on developing outline for threat/attack model and network architecture/scenario
Start reading about traditional process of risk assessment (Document NIST SP800-30), CVSS 3.0 (scoring parameters)
Start reading about traditional process of risk assessment: Bayesian Attack Graphs (BAGs)
Further revisions on attack repository, threat model, and network scenario
Finalize reading of traditional process of risk assessment
Draw outlines of risk assessment procedure to be used, drawing similarity and differences from the related literature in CAVs and traditional risk assessment procedure
Other notes and deliverables:
Register for Mid-SURE (https://urca.msu.edu/mid-sure/reg) Hard Deadline.
Presentation topics: Introduction of problem description, motivations, literature review till date, developed outlines in attack repository, threat model, proposed framework/approach
Start reading and implementation on Bayesian Belief Networks and complex probabilities
Work on quantization of attack repository using complex number and probabilities
Develop outlines of BAG implementation using complex probabilities
Other notes and deliverables:
Mid term presentations
Continue implementation of BAG using complex probabilities
Debugging and trouble shooting
Start on implementation of web-application framework
Integrate web application and implemented BAG
Start writing final report
Other notes and deliverables:
Independence day observed
Keep working on any lingering implementation challenges
Work towards finishing up final report
Finish up final poster for final presentation next week
Finish up report in LaTeX using IEEE conference template based on feedback received from mentor
Finish up any remainder activities with respect to simulation, if any.
Other notes and deliverables:
Final Presentations, Report, codebase, and other materials due (final poster, PPT, etc)
July 28th - MidSURE workshop presentation - virtual
This week we are reviewing relevant research related to risk assessment for connected and autonomous vehicles.
We read in total 7 papers on cybersecurity of CAVs. From these papers we made an index of attacks on CAVs. A LaTeX document was made and the abstract and paper references were added.
We read through 6 more papers related to risk assessment of CAVs. From all the papers we've read, we were able to update the attack index with more information.
We also created a draft of our network scenario.
More readings regarding traditional methods of risk assessment were completed. From these readings we implemented CVSS metrics in our attack repository. We also updated our network scenario.
We developed a draft of the threat model, making some tentative assumptions about protected communications and attacker capability. We transferred all of our attacks from the google sheet to a MongoDB database. We also worked on different quantization schemes, and generally tried to find some interpretations of complex probabilities.
After reviewing various equations, we settled on 3 equations that would build our complex probabilities.
We established the equations for the components of our complex numbers and decided on what we wanted each part of our complex numbers to represent. We also made some updates to our MongoDB attack repository and continued development of our attack graphs.
We primarily focused on our web application and some finalizations of our framework.
This week was mostly dedicated to cleaning up and finishing our web application and then moving on to our deliverables for the program.
Weekly presentations weren't scheduled for the past two weeks. For this final week, we were primarily focused on finishing up our deliverables. This includes our poster, presentation, final writeup, and other miscellaneous documents for the REU program. We also have to prepare a pitch video for the Mid-SURE conference we present at next week.