Week 4 - Cybersecurity Risk Management (Threat Analysis)

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/22

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

23 Terms

1
New cards

What is an APT?

Advanced Persistent Threat - a long term targeted attack.

2
New cards

What is ISO/SAE 21434?

A standard for automotive cybersecurity engineering.

3
New cards

State and define the two things risk assessment (in ISO 21434) looks at?

  • Impact types: safety, financial, operational and privacy

  • Impact ratings: sever, major, moderate, and negligible

4
New cards

Common in-vehicle networks

CAN, FlexRay, Automotive Ethernet

5
New cards

Common external connections (vehicle network technologies)

Wi-Fi, Bluetooth, EV charging etc…

6
New cards

what are common attach surfaces in vehicles?

wireless (Wi-Fi, Bluetooth)

wired (OBD-II, USB, ECUs)

7
New cards

What is an ‘item definition’ in ISO/SAE 21434?

Scope of the item including boundaries, functions, and architecture

8
New cards

state and describe the 4 things in risk treatment

  • Transfer or share the risk to another component or entity

  • Avoid through redesign or remove a component or a feature in a system;

  • Reduce through security controls and mechanisms placed to reduce likelihood and/or impact;

  • Accept the risk (along with any further appropriate measures such as monitoring).

9
New cards

CAN/CAN-FD

basic communication, but lacks built-in authentication

10
New cards

FlexRay

designded for time-deterministic communication like braking/steering. also lacks authentication

11
New cards

automotive ethernet

modern, supports cryptographic security like TLS/IPSec

12
New cards

steps in threat analysis under ISO/SAE 21434

  • asset identification

  • threat scenarios

  • attack path analysis

  • impact feasibility

  • risk determination

13
New cards

what is a damage scenario?

a consequence involving a vehicle function that harms stakeholders

14
New cards

what is domain separation?

segmenting the vehicle network into domains to limit threat propagation

15
New cards

what is the Bowtie Model?

a model showing cause-effect relationships around a risk scenario

-          Left = causes —> threats

-          Right = effects —> damage

-          Centre = asset

16
New cards

what is STRIDE?

a threat modelling method: spoofing, Tampering, Repudiation, Information disclosure, denial of service, elevation of privilege

17
New cards

Spoofing

(S) = a person or entity masquerades as another

18
New cards

Tampering

(T) = insertion, modification or deletion of data

19
New cards

Repudiation

(R) = an entity denies responsibility for an action

20
New cards

Information disclosure

(I) = provision or leak of information to an unauthorized entity

21
New cards

Denial of Service (DoS)

(D) = making a resource unavailable to authorized entities

22
New cards

Elevation of Privilege

(E) = an entity gains greater authorization than permitted

23
New cards

What is TARA?

Threat Analysis and Risk Assessment