A Comparative Risk Analysis on CyberShip System with STPA-Sec, STRIDE and CORAS

12/21/2022
by   Rishikesh Sahay, et al.
0

The widespread use of software-intensive cyber systems in critical infrastructures such as ships (CyberShips) has brought huge benefits, yet it has also opened new avenues for cyber attacks to potentially disrupt operations. Cyber risk assessment plays a vital role in identifying cyber threats and vulnerabilities that can be exploited to compromise cyber systems. A number of methodologies have been proposed to carry out these analyses. This paper evaluates and compares the application of three risk assessment methodologies: system theoretic process analysis (STPA-Sec), STRIDE and CORAS for identifying threats and vulnerabilities in a CyberShip system. We specifically selected these three methodologies because they identify threats not only at the component level, but also threats or hazards caused due to the interaction between components, resulting in sets of threats identified with each methodology and relevant differences. Moreover, STPA-Sec which is a variant of the STPA is widely used for safety and security analysis of cyber physical systems (CPS); CORAS offers a framework to perform cyber risk assessment in a top-down approach that aligns with STPA-Sec; and STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of Service, Elevation of Privilege) considers threat at the component level as well as during the interaction that is similar to STPA-Sec. As a result of this analysis, this paper highlights the pros and cons of these methodologies, illustrates areas of special applicability, and suggests that their complementary use as threats identified through STRIDE can be used as an input to CORAS and STPA-Sec to make these methods more structured.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/02/2017

A Systems Approach for Eliciting Mission-Centric Security Requirements

The security of cyber-physical systems is first and foremost a safety pr...
research
07/05/2023

Security Risk Analysis Methodologies for Automotive Systems

Nowadays, systematic security risk analysis plays a vital role in the au...
research
03/18/2019

An Adversarial Risk Analysis Framework for Cybersecurity

Cyber threats affect all kinds of organisations. Risk analysis is an ess...
research
06/07/2023

Development of a Multi-purpose Fuzzer to Perform Assessment as Input to a Cybersecurity Risk Assessment and Analysis System

Fuzzing is utilized for testing software and systems for cybersecurity r...
research
07/07/2022

A Methodology to Support Automatic Cyber Risk Assessment Review

Cyber risk assessment is a fundamental activity for enhancing the protec...
research
04/18/2020

Human Factors in Biocybersecurity Wargames

Within the field of biocybersecurity, it is important to understand what...
research
04/06/2023

Gotta Assess `Em All: A Risk Analysis of Criminal Offenses Facilitated through PokemonGO

Location-based games have come to the forefront of popularity in casual ...

Please sign up or login with your details

Forgot password? Click here to reset