The increasing frequency of Over-The-Air (OTA) updates on Software-Defined Vehicles (SDVs), combined with heterogeneous OTA architectures, introduces unpredictable attack entry points and vulnerabilities that may scale with fleet size. These vulnerabilities can escalate from external infrastructure components to in-vehicle systems, expanding the attack surface across the update ecosystem. In SDV architectures, real-time vulnerability risk management is challenging, as OTA updates may be deployed before corresponding security patches are released and validated.
This work presents OTARQ (OTA Risk Quantification), an automated risk quantification framework that integrates cybersecurity, safety, and fleet impact assessment. The framework automatically computes a final risk score from natural-language vulnerability descriptions. OTARQ is adaptive and context-aware, dynamically adjusting its parameters according to update criticality and vulnerability location. Experiments on representative OTA threat scenarios validate both the accuracy of the risk quantification and its sensitivity to deployment context.
- Venue: Preprint / working paper — HAL
- HAL record: hal-05709703
- PDF: download
- Co-authors: Khaoula Sghaier, Ghada Gharbi, Badis Hammi, Pierre Merdrignac, Didier Verna
