A Quantitative Methodology for Systemic Impact Assessment of Cyber Threats in Connected Vehicles

Don Nalin Dharshana Jayaratne, Qian Lu, Abdur Rakib, Muhamad Azfar Ramli, Rakhi Manohar Mepparambath, Siraj Ahmed Shaikh, Hoang Nga Nguyen

Research output: Contribution to journalArticlepeer-review

10 Downloads (Pure)

Abstract

The increasing integration of digital technologies in connected vehicles introduces cybersecurity risks that extend beyond individual vehicles, with the potential to disrupt entire transportation systems. Current practice (e.g., ISO/SAE~21434 TARA) focuses on threat identification and qualitative impact ratings at the vehicle boundary, with limited systemic quantification. This study presents a systematic, simulation-based methodology for quantifying the systemic operational and safety impacts of cyber threats on connected vehicles, evaluating cascading effects across the transport network. Three representative scenarios are examined: (I) telematics-induced sudden braking causing a cascading collision, (II) remote disabling on a motorway (M25) segment, and (III) a compromised Roadside Unit (RSU) spoofing Variable Speed Limit (VSL) and phantom lane closure messages to connected and automated vehicles (CAVs). The results highlight the potential for cascading safety incidents and systemic operational degradation, as evidenced by the defined systemic operational and safety vectors, factors that are insufficiently addressed in the current scope of the ISO/SAE 21434 standard, which primarily focuses on individual vehicle-level threats. The findings underscore the need to incorporate systemic evaluation into existing frameworks to enhance cyber resilience across connected vehicle ecosystems. The framework complements ISO/SAE~21434 by supplying quantitative, reproducible evidence for the impact rating step at a systemic scale, reducing assessor subjectivity and supporting policy and operations, enabling more data-driven evaluations of systemic cyber risks.
Original languageEnglish
Article number104729
Number of pages16
JournalComputers and Security
Volume160
Early online date27 Oct 2025
DOIs
Publication statusPublished - Jan 2026

Bibliographical note

This is an open access article under the CC BY license (http://creativecommons.org/licenses/by/4.0/)

Funding

This work was supported by Coventry University, UK and the A*STAR Research Attachment Programme (ARAP), Singapore.

FundersFunder number
Coventry University
The Agency for Science, Technology and Research of Singapore

    Keywords

    • Connected Vehicles
    • Automotive Cybersecurity
    • Threat analysis and risk assessments (TARA)
    • Impact Assessment
    • Simulation

    Fingerprint

    Dive into the research topics of 'A Quantitative Methodology for Systemic Impact Assessment of Cyber Threats in Connected Vehicles'. Together they form a unique fingerprint.

    Cite this