TY - GEN
T1 - A MITRE ATT&CK-Driven Risk Assessment Methodology for Connected and Autonomous Vehicles
AU - Baccari, Sihem
AU - Hadded, Mohamed
AU - Laouiti, Anis
AU - Elhadef, Mourad
AU - Yeng, Prosper
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026/1/1
Y1 - 2026/1/1
N2 - Connected and Autonomous Vehicles (CAVs) operate as complex cyber-physical systems, exposing critical vehicle assets to sophisticated cyber threats that can propagate into unsafe physical behaviors. In this paper, we present a MITRE ATT&CK-driven risk assessment methodology for CAVs, integrating systematic identification of 8 critical assets, adversary-centric threat mapping, and quantitative risk evaluation. We analyze assets across perception, communication, computing and planning, and motion control layers, and identify 22 potential threats mapped to ATT&CK tactics, techniques, and sub-techniques. Threat exploitability is assessed using the Common Vulnerability Scoring System (CVSS) v3.1 and combined with 5 defined impact levels. Risk prioritization is then performed via a 5×5 probability-impact matrix to support actionable cybersecurity decisions, aligned with ISO/SAE 21434. Based on the results, we analyze ITS-specific countermeasures, including secure authentication, integrity verification, encrypted communications, and intrusion detection. The findings underline that integrity and availability represent the most critical systemic risks, especially in motion control and communication subsystems, while also highlighting the value of a behavior-driven knowledge-based approach for guiding cybersecurity decisions in CAVs.
AB - Connected and Autonomous Vehicles (CAVs) operate as complex cyber-physical systems, exposing critical vehicle assets to sophisticated cyber threats that can propagate into unsafe physical behaviors. In this paper, we present a MITRE ATT&CK-driven risk assessment methodology for CAVs, integrating systematic identification of 8 critical assets, adversary-centric threat mapping, and quantitative risk evaluation. We analyze assets across perception, communication, computing and planning, and motion control layers, and identify 22 potential threats mapped to ATT&CK tactics, techniques, and sub-techniques. Threat exploitability is assessed using the Common Vulnerability Scoring System (CVSS) v3.1 and combined with 5 defined impact levels. Risk prioritization is then performed via a 5×5 probability-impact matrix to support actionable cybersecurity decisions, aligned with ISO/SAE 21434. Based on the results, we analyze ITS-specific countermeasures, including secure authentication, integrity verification, encrypted communications, and intrusion detection. The findings underline that integrity and availability represent the most critical systemic risks, especially in motion control and communication subsystems, while also highlighting the value of a behavior-driven knowledge-based approach for guiding cybersecurity decisions in CAVs.
KW - Asset-driven Analysis
KW - CAVs
KW - Countermeasures
KW - Cybersecurity
KW - ITS
KW - Risk Assessment
KW - Threat Analysis
KW - V2X
UR - https://www.scopus.com/pages/publications/105044704269
U2 - 10.1109/IWCMC69287.2026.11579870
DO - 10.1109/IWCMC69287.2026.11579870
M3 - Conference contribution
AN - SCOPUS:105044704269
T3 - 2026 International Wireless Communications and Mobile Computing Conference, IWCMC 2026
SP - 1707
EP - 1712
BT - 2026 International Wireless Communications and Mobile Computing Conference, IWCMC 2026
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 22nd International Wireless Communications and Mobile Computing Conference, IWCMC 2026
Y2 - 1 June 2026 through 6 June 2026
ER -