Commit 55faccf4 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Removing C-ITS risk analysis

parent 4b41ed4e
Loading
Loading
Loading
Loading
+0 −337
Original line number Diff line number Diff line
@@ -3644,343 +3644,6 @@ The risk are then calculated and their applicability defined using the matrixes
    <th>UC / App.</th>
  </tr>

  <tr>
    <td>T.DOS</td>
    <td>A Remote attacker disables communication between the product and the ITS-S station</td>
    <td>PKI services </td>
    <td>Integrity, Availability</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-1, INT-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>


  <tr>
    <td>T.ITS-S_Impersonation</td>
    <td>A Remote attacker (Rogue ITS-S) sends fake requests in order to get valid EC and AT with forged attributes or fake MR in order to have targeted ITS-S to be considered misbehaving by the TAE</td>
    <td>Certificates <br> Misbehaviour detection </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-1</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>




  <tr>
    <td>T.TrustListsReplay</td>
    <td>A Remote attacker intercepts and responds to an ITS-S requesting for trust list (CRL CTL ECTL) updates by sending an old version</td>
    <td>Trust lists </td>
    <td>Integrity, Availability</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-1, INT-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>


  <tr>
    <td>T.GlobalMisbehaviourReportingTampering</td>
    <td>A Remote attacker may exploit interactions between the MA and the EA or AA in order to modify global misbehaving detection information in order to force wrong reaction either on correct ITS-S station or misbehaving stations</td>
    <td>Misbehaviour Detection <br> Trust lists <br> PKI services </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-1</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>



  <tr>
    <td>T.AuthorizationValidationProcessTampering</td>
    <td>A Remote attacker may exploit interactions between the EA and AA in order to modify Authorization calidation requests or responses to allow or deny inappropriate AT generation </td>
    <td>Certificates <br> PKI services </td>
    <td>Integrity, Availability</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-1, INT-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>

  <tr>
    <td>T.RegistrationTampering</td>
    <td>A Remote attacker may exploit interactions between the manufacturer and the EA in order to modify or deny an ITS-S registration </td>
    <td>Station registration Data </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>



  <tr>
    <td>T.PrivateKeys</td>
    <td>A Local attacker or Rogue user disclose or tamper to the product secrets i.e. Data encryption key or CA private keys </td>
    <td>Keys </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>


  <tr>
    <td>T.Logs_Tampering</td>
    <td>A Local attacker or Rogue user tries to modify the product's Log File in order to hide its activities </td>
    <td>Logs and Configuration </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-1</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>



</Table>
</div>


<div align="center">

**Table B.18: Risk evaluation part 6**
</br>
<table style="border-collapse:collapse; width:100%;">
  <tr>
    <td colspan="3">Threat</td>
    <td colspan="6">Risk-factor</td>
    <td colspan="1">Value UC1</td>
    <td colspan="1">Value UC2</td>
    <td colspan="1">Value UC3</td>
    <td colspan="1">Value UC4</td>
    <td colspan="6">Value UC4</td>
  </tr>

  <tr>
    <th>ID</th>
    <th>Description</th>
    <th>Asset</th>
    <th>Impact Type</th>
    <th>Value UC1</th>
    <th>Value UC2</th>
    <th>Value UC3</th>
    <th>Value UC4</th>
    <th>Likelihood Type</th>
    <th>Value UC1</th>
    <th>Value UC2</th>
    <th>Value UC3</th>
    <th>Value UC4</th>
    <th>Risk Value UC1</th>
    <th>Risk Value UC2</th>
    <th>Risk Value UC3</th>
    <th>Risk Value UC4</th>
    <th>UC / App.</th>
  </tr>

  <tr>
    <td>T.Logs_Disclosure</td>
    <td>A Local attacker or Rogue user tries to gain access to the product's Log File in order to gain sensitive information on the product's security status and functions as well as other C-ITS stations</td>
    <td>Logs and Configuration </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-1</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>


  <tr>
    <td>T.Configuration_Tampering</td>
    <td>A Local attacker or Rogue user tries to modify the product's Certificate Policy configuration data and therefore compromise the integrity of the product's applications or communication security</td>
    <td>Logs and Configuration </td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-1</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>





  <tr>
    <td>T.Stored_Certificates_Tampering</td>
    <td>A Local attacker or Rogue user tries to modify stored CA Certificates Enrolment Credential (EC) Authorization Ticket (AT) TLM certificate content and therefore compromise the confidentiality or integrity of the product's communications</td>
    <td>Certificates</td>
    <td>Integrity, Availability</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-1, INT-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>



  <tr>
    <td>T.Administrators_Impersonation</td>
    <td>An attacker (Remote attacker Local attacker or Rogue user) may gain access to product information by impersonating an authorized user or via privilege escalation of the product and thus disclose or manipulate product assets</td>
    <td>Keys <br> Certificates <br> Station registration data <br> CA Network addresses <br> Policies <br> Trust lists <br> PKI services <br> Misbehaviour detection</td>
    <td>Integrity, Availability, Confidentiality</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-0, INT-0, CON-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>



  <tr>
    <td>T.Software_Tampering</td>
    <td>A Local or Remote attacker tries to modify the product's software and therefore compromise the integrity of the product's applications </td>
    <td> PKI services </td>
    <td>Integrity, Availability</td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>AVA-1, INT-0</td>
    <td></td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>DEP-1, NET-2, USR-2, OPS-2, IF-0/td>
    <td>NA</td>
    <td>NA</td>
    <td>NA</td>
    <td>High</td>
    <td>UC4</td>
  </tr>

</Table>
</div>

# Annex K (normative): Generic requirements and assessment criteria for the use of state of the art cryptography V 0.51 (2025-02-16)

ETSI Drafting rules do not allow footnotes. All footnotes in this Annex will have to be deleted or replaced by relevant references and notes before publication.