Commit 79b27f41 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Update Annex B Security analysis to revised structure (was Annex C)

closes #105, closes #143, closes #121
parent e89aab20
Loading
Loading
Loading
Loading
+57 −90
Original line number Diff line number Diff line
@@ -2206,13 +2206,23 @@ Once the present document is cited in the Official Journal of the European Union
Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.

# Annex C (informative): Risk identification and assessment methodology
# Annex B (informative): Security analysis 

## C.1 Assets
This Annex applies state of the art methodology to identify assets, threats, identify and evaluate risk factors, and associate risk factor levels with different use cases identified in the product context. This security analysis informs the applicability of the technical requirements.

### C.1.1 Data
The security analysis in this Annex represents a risk assessment done by the standardisers solely for the purpose of informing the applicability of technical requirements.

#### C.1.1.1 Physical network interfaces
A list of product assets are used to identify potential threats to the product. The assumptions are used to define the scope of potential threats that are addressed by this security analysis.

Risk factor levels for each use case are determined by using the definition of the use case to choose a risk factor level that most accurately represents the highest risk for that use case. The use case is restricted by the intended purpose and reasonably foreseeable use as specified by the manufacturer.

For each threat, a formula based on the risk factor levels is used to calculate the Likelihood and Impact of the threat. This security analysis uses the Likelihood and Impact of each threat to identify specific technical requirements that treat that risk.

## B.1 Assets

### B.1.1 Data

#### B.1.1.1 Physical network interfaces

* Firmware
* Device identity (MAC address etc.)
@@ -2224,16 +2234,16 @@ Other Union legislation may be applicable to the product(s) falling within the s
* All accessible host data and functions
* Packet data

#### C.1.1.2 Virtual network interfaces or device drivers
#### B.1.1.2 Virtual network interfaces or device drivers

* Device driver executable
* Interface configuration
* Statistics
* Security keys

### C.1.2 Product functions
### B.1.2 Product functions

#### C.1.2.1 Physical network interface essential functions
#### B.1.2.1 Physical network interface essential functions

* Receive and transmit data between host and network at data link layer
* Execute commands from the host (power, config, tx/rx)
@@ -2251,7 +2261,7 @@ Optional:
* Provide remote management interface
* Implement/support network boot

### C.1.2.2 Device driver essential functions
### B.1.2.2 Device driver essential functions

* Copy data between network device interface and host memory
* Handle interrupts, set up tx/rx, keep/copy statistics, etc.
@@ -2267,13 +2277,13 @@ Optional:
* Generate log messages
* Use debug interfaces

### C.1.2.3 Virtual network interface essential functions
### B.1.2.3 Virtual network interface essential functions

* Process/move around data sent to virtual network interface
* Interact with operating system
* Configure the network interface
* Keep and report network statistics
* Read/write/etc host resources accessible from device driver
* Read/write/etc host resources accessible from virtual network interface

Optional:

@@ -2281,11 +2291,11 @@ Optional:
* Provision keys (network access, management, packet encryption)
* Generate log messages

## C.2 Risk factors
## B.2 Risk factors

### C.2.1 List of risk factors
### B.2.1 List of risk factors

Risk factors determine which mitigation(s) satisfy each of the technical cybersecurity requirements in clause 5.2. The manufacturer of a product determines the level of each risk factor via the development of a threat model and risk profile based on the intended and foreseeable use and misuse of the network interface.
Risk factors determine which mitigation(s) satisfy each of the technical cybersecurity requirements in clause 5.2. The manufacturer of a product determines the level of each risk factor via its own independent risk assessment.

Risk factors may increase the likelihood of an incident, increase the impact of an incident, or both. As a result, different mitigation strategies may be more or less relevant to different risk factors.

@@ -2409,9 +2419,9 @@ Rationale: The more sensitive the functions of the product, the higher the impac

Type: Affects impact of attack.

  * **[SDT-L-0]** Foreseeable use is for unimportant functions
  * **[SDT-L-1]** Foreseeable use is for moderately sensitive functions, such as encrypting transmitted data
  * **[SDT-L-2]** Foreseeable use is for highly sensitive functions, such as primary management interface of host system
  * **[FUN-L-0]** Foreseeable use is for unimportant functions
  * **[FUN-L-1]** Foreseeable use is for moderately sensitive functions, such as encrypting transmitted data
  * **[FUN-L-2]** Foreseeable use is for highly sensitive functions, such as primary management interface of host system

**[INT]** Integration in host system

@@ -2425,27 +2435,31 @@ Type: Affects impact of attack.
  * **[INT-L-1]** Product is connected to host system via internal adapter requiring disassembly to change
  * **[INT-L-2]** Product is fully integrated into and cannot be removed from host system

## C.3 Assumptions
## B.3 Assumptions

### B.3.1 Overview

### C.3.1 Proper host system
Assumptions are used to define the scope of the potential threats addressed by this analysis.

**[AS-PH]:** The host system the product is attached to is trustworthy.
### B.3.2 Proper host system

### C.3.2 Proper administrator
The host system the product is attached to is trustworthy.

**[AS-PA]:** The product administrator is not intentionally hostile and is engaging in good faith efforts to administer the product properly.
### B.3.3 Proper administrator

### C.3.3 Attacker has limited physical access to product
The product administrator is not intentionally hostile and is engaging in good faith efforts to administer the product properly.

**[AS-LP]:** An attacker will have only temporary physical access to the product.
### B.3.4 Attacker has limited physical access to product

### C.3.4 Attacker has limited resources
An attacker will have only temporary physical access to the product.

**[AS-LR]:** An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.
### B.3.5 Attacker has limited resources

## C.4 Threats and risk assessment of threats
An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.

### C.4.1 General
## B.4 Threats and security analysis of threats

### B.4.1 General

The approach to listing threats is to separate them by mitigation so that they may be associated with mitigations more directly.

@@ -2455,7 +2469,7 @@ For the purposes of the list of threats, the product includes:
  * the device driver (if any)
  * the virtual network interface (if any)

### C.4.2 Risk assessment methodology
### B.4.2 Security analysis methodology

Risk factor levels for each security profile are determined by reading the descriptions for each risk factor level and choosing the one that most accurately represents the highest risk for the intended purpose and reasonably foreseeable use and misuse of the product, as specified by the manufacturer.

@@ -2475,9 +2489,9 @@ The mitigations that reduce risk by type are:

  * Impact: IMSL, DCTX, DJST, IDST, NTFY, WDOG, LOGG, SDRF, SDTR

### C.4.3 List of threats, risk assessments, and mitigations
### B.4.3 List of threats, risk assessments, and mitigations

#### C.4.3.1 TH-UEVU: Unknown exploitable vulnerabilities
#### B.4.3.1 TH-UEVU: Unknown exploitable vulnerabilities

Attacker may use unknown exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.

@@ -2507,7 +2521,7 @@ Mitigations for Impact:

* High to Low: DJST, LOGG

#### C.4.3.2 TH-KEVU: Known exploitable vulnerabilities
#### B.4.3.2 TH-KEVU: Known exploitable vulnerabilities

Attacker may use known exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.

@@ -2533,7 +2547,7 @@ Mitigations for Likelihood:

* High to Low: KEVD, KEVA, (KEVT or SCAN), KEVM, (SUAP or SUAO), VULH

#### C.4.3.3 TH-PHYS: Access to data via acquisition of used product
#### B.4.3.3 TH-PHYS: Access to data via acquisition of used product

Attacker may get unauthorized access to confidential data stored on the product through acquisition of a used product.

@@ -2563,7 +2577,7 @@ Mitigations for Impact:

* High to Low: CDST

#### C.4.3.4 TH-CONF: Access to assets via configuration errors
#### B.4.3.4 TH-CONF: Access to assets via configuration errors

Attacker may use configuration errors to get unauthorized access to the product assets.

@@ -2593,7 +2607,7 @@ Mitigations for Impact:

* High to Low: CDST, DJST, LOGG

#### C.4.3.5 TH-UADT: Unauthorized access to confidential data transmitted
#### B.4.3.5 TH-UADT: Unauthorized access to confidential data transmitted

Attacker may use network access to get unauthorized access to confidential data transmitted by the product.

@@ -2623,7 +2637,7 @@ Mitigations for Impact:

* High to Low: DJST

#### C.4.3.6 TH-AVAI: Denial of service attack on product via exploitation of vulnerabilities
#### B.4.3.6 TH-AVAI: Denial of service attack on product via exploitation of vulnerabilities

Attacker may exploit vulnerabilities in the product to reduce availability of product assets.

@@ -2649,7 +2663,7 @@ Mitigations for Impact:

* High to Low: NTFY, WDOG

#### C.4.3.7 TH-PDOS: Denial of service attack on product functions via system or network access
#### B.4.3.7 TH-PDOS: Denial of service attack on product functions via system or network access

Attacker may use host system or network access for a denial-of-service attack on product functions.

@@ -2679,7 +2693,7 @@ Mitigations for Impact:

* High to Low: NTFY, WDOG, FDRP, LMEM, FAIR, LOGG

#### C.4.3.8 TH-DDOS: Denial of service attack on other products via exploitation of vulnerabilities
#### B.4.3.8 TH-DDOS: Denial of service attack on other products via exploitation of vulnerabilities

Attacker may exploit vulnerabilities in the product to attack other products.

@@ -2705,7 +2719,7 @@ Mitigations for Impact:

* High to Low: MDOC, MPHY

#### C.4.3.9 TH-MQSE: Masquerading authorized server
#### B.4.3.9 TH-MQSE: Masquerading authorized server

Attacker may masquerade as an authorized server to get unauthorized access to product assets.

@@ -2735,7 +2749,7 @@ Mitigations for Impact:

* High to Low: LOGG

#### C.4.3.10 TH-AHHS: Harm to host system via unauthorized access through the network
#### B.4.3.10 TH-AHHS: Harm to host system via unauthorized access through the network

Attacker may use unauthorized access to the product through the network to harm the host system.

@@ -2763,9 +2777,9 @@ Mitigations for Likelihood:

* High to Low: AUTH

### C.5.2 Mapping of use cases to risk factors and security profiles
### B.5.2 Mapping of use cases to risk factors and security profiles

#### C.5.2.1 Wired network interface use cases
#### B.5.2.1 Wired network interface use cases

| Use case | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT | Sec Pro |
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
@@ -2780,7 +2794,7 @@ Mitigations for Likelihood:
| UC-WD-9  | 0   | 2   | 1   | 1   | 0   | 0   | 2   | 0   | 1   | 2   | 1   | SP-WD-4 |
| UC-WD-10 | 2   | 2   | 1   | 1   | 1   | 0   | 2   | 0   | 0   | 0   | 1   | SP-WD-4 |

#### C.5.2.2 Wireless network interface use cases
#### B.5.2.2 Wireless network interface use cases

| Use case | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT | Sec Pro |
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
@@ -2792,7 +2806,7 @@ Mitigations for Likelihood:
| UC-WL-6  | 1   | 1   | 2   | 2   | 2   | 2   | 2   | 1   | 1   | 1   | 1   | SP-WL-3 |
| UC-WL-7  | 2   | 2   | 1   | 2   | 1   | 2   | 1   | 0   | 0   | 0   | 1   | SP-WL-3 |

#### C.5.2.3 Virtual network interface use cases
#### B.5.2.3 Virtual network interface use cases

| Use case | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT | Sec Pro |
|----------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|---------|
@@ -2801,53 +2815,6 @@ Mitigations for Likelihood:
| UC-VI-3  | 0   | 1   | 1   | 2   | 0   | 0   | 2   | 2   | 2   | 2   | 0   | SP-VI-2 |
| UC-VI-4  | 0   | 2   | 2   | 2   | 0   | 0   | 2   | 2   | 2   | 2   | 0   | SP-VI-2 |

## C.6 Security profiles

### C.6.1 General

Security profiles are an informative resource to the manufacturer. Each security profile is associated with a collection of levels of risk factors. Security profiles will be mapped to specific mitigations for each cybersecurity requirements necessary to treat the risk.

### C.6.2 Mapping of security profile to risk factors

Security profiles are associated with sets of risk factor levels.

#### C.6.2.1 Wired network interface security profiles

| Security profile | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT |
|------------------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|
| SP-WD-1          | 0   | 0   | 0   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 2   |
| SP-WD-2          | 0   | 0   | 2   | 1   | 1   | 0   | 2   | 0   | 1   | 2   | 1   |
| SP-WD-3          | 1   | 1   | 2   | 1   | 2   | 0   | 1   | 0   | 1   | 1   | 1   |
| SP-WD-4          | 2   | 2   | 2   | 1   | 1   | 2   | 2   | 0   | 1   | 2   | 1   |

#### C.6.2.2 Wireless network interface security profiles

| Security profile | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT |
|------------------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|
| SP-WL-1          | 0   | 0   | 1   | 2   | 2   | 1   | 1   | 1   | 1   | 1   | 1   |
| SP-WL-2          | 1   | 1   | 2   | 2   | 2   | 2   | 2   | 1   | 1   | 1   | 1   |
| SP-WL-3          | 2   | 2   | 2   | 2   | 2   | 2   | 2   | 1   | 1   | 1   | 1   |

#### C.6.2.3 Virtual network interface security profiles

| Security profile | PHY | SFT | NET | COM | ADM | LIS | SYS | SDS | SDT | FUN | INT |
|------------------|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|-----|
| SP-VI-1          | 0   | 1   | 0   | 0   | 0   | 0   | 1   | 1   | 1   | 1   | 0   |
| SP-VI-2          | 0   | 2   | 2   | 2   | 2   | 0   | 2   | 2   | 2   | 2   | 0   |

## C.7 How to add new security profiles

To add a new security profile, do the following:

1. Do a risk assessment on the category of product covered by the new security profile.
1. Determine the risk factors for the new security profile.
1. If there are any new threats, add them to the threats list along with their risk calculation formula.
1. If any new risk factors are necessary to calculate risks for the new security profile, add the risk factors and update the score for all the security profiles.
1. Use the risk factors of the new security profile and the risk formula for each threat to calculate which of the existing mitigations must be applied.
1. After the existing risk mitigations are applied, check if all threats are sufficiently mitigated. If not, add new mitigations until the threats have been reduced sufficiently.
1. Update all relevant mappings (e.g. security profile to risk mitigation sets).
1. Propose the new security profile as a contribution to the standard.

# Annex D (informative): Risk evaluation guidance

## D.1 Explanation of Risk Modeling Approach