Commit e6f28211 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Annex B.4/B.5: Update security analysis

Update the security analysis for the new risk factors and framing of
use cases from the point of view of the network interface itself.
parent f4086e52
Loading
Loading
Loading
Loading
+171 −193
Original line number Diff line number Diff line
@@ -2369,271 +2369,245 @@ For each threat, a formula based on the risk factor levels is used to calculate

For each threat, both likelihood and impact must be Low before the risk is considered sufficiently mitigated. If the calculated levels are not already Low, then mitigations must be applied until they are both Low. The mitigation sets that will accomplish this are listed in each threat description.

The risk factors by type are:

  * Likelihood: PHY NET COM INI

  * Impact: NET HOS FUN

### B.4.3 List of threats, risk assessments, and mitigations

#### B.4.3.1 TH-UEVU: Unknown exploitable vulnerabilities
TODO fill out use cases in risk factor tables

Attacker may use unknown exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.
#### B.4.3.1 TH-UEVU: Unknown exploitable vulnerabilities

| Risk factors                      | Likelihood | Security profiles      |
|-----------------------------------|------------|------------------------|
| max(PHY, SFT, NET) = 0 or COM = 0 | Low        | WD-1, VI-1             |
| all others                        | Medium     | WD-2, WD-3, WD-4, WL-1 |
| max(PHY, SFT, NET) = 2 & COM = 2  | High       | WL-2, WL-3, VI-2       |
Attacker may use unknown exploitable vulnerabilities in the product to harm the product's assets.

| Risk factors                | Impact | Security profiles                  |
|-----------------------------|--------|------------------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                               |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, WL-1, VI-1             |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-2, WL-3, WL-4, VI-2 |
| Risk factors                    | Likelihood | Use cases         |
|---------------------------------|------------|-------------------|
| (PHY and NET are 0) or COM is 0 | Low        |                   |
| all others                      | Medium     |                   |
| (PHY or NET is 2) and COM is 2  | High       |                   |

cybersecurity requirements that mitigate this threat: SSDD, LMII, DMIN, LMAS, LOGG
| Risk factors      | Impact  | Use cases         |
|-------------------|---------|-------------------|
| FUN and HOS are 0 | Low     |                   |
| all others        | Medium  |                   |
| FUN or HOS are 2  | High    |                   |

Mitigations for Likelihood:

* Medium to Low: SCFS, SSCA, ADEF, DPAH, PDDI-\*
* Medium to Low:
  * REQ-ALC-01
  * REQ-ASM-01
  * REQ-EM-01

* High to Low: SCFS, SSCA, (FZ95 or BTIN or IMSL), MSAF-\*, MZRO-\*, ADEF, DPAH, PDDI-\*, JSTY
* High to Low:
  * REQ-ALC-01
  * REQ-ASM-01
  * REQ-EM-01

Mitigations for Impact:

* Medium to Low: LOGG
* Medium to Low:
  * REQ-MON-01

* High to Low: DJST, LOGG
* High to Low:
  * REQ-MON-01

#### B.4.3.2 TH-KEVU: Known exploitable vulnerabilities

Attacker may use known exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.

| Risk factors                                 | Likelihood | Security profiles            |
|----------------------------------------------|------------|------------------------------|
| max(PHY, SFT, NET) = 0 or COM = 0 or ADM = 0 | Low        | WD-1                         |
| all others                                   | Medium     | WD-2, WD-3, WD-4, WL-1, VI-1 |
| max(PHY, SFT, NET) = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2             |
| Risk factors                                | Likelihood | Use cases         |
|---------------------------------------------|------------|-------------------|
| (PHY and NET are 0) or COM is 0 or ADM is 0 | Low        |                   |
| all others                                  | Medium     |                   |
| (PHY or NET is 2) and COM is 2 and ADM is 2 | High       |                   |

| Risk factors                | Impact | Security profiles                  |
|-----------------------------|--------|------------------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                               |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, WL-1, VI-1             |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-2, WL-3, WL-4, VI-2 |

Cybersecurity requirements that mitigate this threat: NKEV, SSDD, LMII, SCUD, DMIN, LMAS, LOGG, VULH

All mitigations from TH-UEVU apply (using that cybersecurity requirement's risk formula), in addition to:
| Risk factors      | Impact | Use cases         |
|-------------------|--------|-------------------|
| FUN and HOS are 0 | Low    |                   |
| all others        | Medium |                   |
| FUN or HOS are 2  | High   |                   |

Mitigations for Likelihood:

* Medium to Low: (KEVD or KEVA or KEVT or SCAN), KEVM, (SUVP or SUAP or SUOE or SUAO), VULH
* Medium to Low:
  * REQ-KEV-01
  * REQ-SU-01

* High to Low: KEVD, KEVA, (KEVT or SCAN), KEVM, (SUAP or SUAO), VULH
* High to Low:
  * REQ-KEV-01
  * REQ-SU-01

#### B.4.3.3 TH-PHYS: Access to data via acquisition of used product
#### B.4.3.3 TH-DSTP Compromise of data stored on product

Attacker may get unauthorized access to confidential data stored on the product through acquisition of a used product.
Attacker may get unauthorized access to confidential data stored on the product through acquisition of a used product or during transfer of user data and settings from one product to another.

| Risk factors       | Likelihood | Security profiles |
|--------------------|------------|-------------------|
| ADM = 0 or SDS = 0 | Low        | WD-\*, VI-1       |
| all others         | Medium     | WL-\*             |
| ADM = 2 & SDS = 2  | High       | VI-2              |
| Risk factors | Likelihood | Use cases         |
|--------------|------------|-------------------|
| ADM is 0     | Low        |                   |
| all others   | Medium     |                   |
| ADM is 2     | High       |                   |

| Risk factors | Impact | Security profiles |
| Risk factors | Impact | Use cases         |
|--------------|--------|-------------------|
| SDS = 0      | Low    | WD-\*             |
| SDS = 1      | Medium | WL-\*, VI-1       |
| SDS = 2      | High   | VI-2              |

Cybersecurity requirements that mitigate this threat: CDST, SCDL, SDEF
| FUN = 0      | Low    |                   |
| FUN = 1      | Medium |                   |
| FUN = 2      | High   |                   |

Mitigations for Likelihood:

* Medium to Low: ADEF, DPAH, (RSET or INST or DELE), SDRF
* Medium to Low:
  * REQ-AAC-01
  * REQ-CP-01
  * REQ-IP-01
  * REQ-SDT-01

* High to Low: ADEF, DPAH, PDDI-\*, (RSET or INST or DELE), SDRF, SDTR
* High to Low:
  * REQ-AAC-01
  * REQ-CP-01
  * REQ-IP-01
  * REQ-SDT-01

Mitigations for Impact:

* Medium to Low: CDST
* Medium to Low:
  * REQ-DM-01

* High to Low: CDST
  * REQ-DM-01

#### B.4.3.4 TH-CONF: Access to assets via configuration errors

Attacker may use configuration errors to get unauthorized access to the product assets.
Attacker may use unintentional configuration errors to get unauthorized access to the product assets.

| Risk factors                      | Likelihood | Security profiles      |
|-----------------------------------|------------|------------------------|
| max(PHY, SFT, NET) = 0 or ADM = 0 | Low        | WD-1, VI-1             |
| all others                        | Medium     | WL-1                   |
| max(PHY, SFT, NET) = 2 & ADM = 2  | High       | WD-3, WL-2, WL-3, VI-2 |
| Risk factors  | Likelihood | Use cases         |
|---------------|------------|-------------------|
| INI is 0 or 1 | Medium     |                   |
| all others    | High       |                   |

| Risk factors                     | Impact | Security profiles      |
|----------------------------------|--------|------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                   |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, VI-1       |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-\* VI-2 |

Cybersecurity requirements that mitigate this threat: CDST, SDEF, DMIN, LOGG
| Risk factors      | Impact | Use cases         |
|-------------------|--------|-------------------|
| FUN and HOS are 0 | Low    |                   |
| all others        | Medium |                   |
| FUN or HOS are 2  | High   |                   |

Mitigations for Likelihood:

* Medium to Low: ADEF, DPAH, PDDI-1
* Medium to Low:
  * REQ-SBD-01

* High to Low: ADEF, DPAH, PDDI-2 if PHY = 2, PDDI-3 if SFT = 2, PDDI-4 if NET = 2
* High to Low:
  * REQ-SBD-02

Mitigations for Impact:

* Medium to Low: CDST

* High to Low: CDST, DJST, LOGG
* Medium to Low:
  * REQ-MON-01

#### B.4.3.5 TH-UADT: Unauthorized access to confidential data transmitted
* High to Low:
  * REQ-MON-01

Attacker may use network access to get unauthorized access to confidential data transmitted by the product.
#### B.4.3.5 TH-UADT: Unauthorized access to data transmitted

| Risk factors | Likelihood | Security profiles            |
|--------------|------------|------------------------------|
| LIS = 0      | Low        | WD-1, WD-2, WD-3, VI-1, VI-2 |
| LIS = 1      | Medium     | WL-1                         |
| LIS = 2      | High       | WD-4, WL-2, WL-3             |
Attacker may use access to the attached network to compromise the confidentiality or integrity of data transmitted by the product.

| Risk factors | Impact | Security profiles  |
|--------------|--------|--------------------|
| SDT = 0      | Low    | none               |
| SDT = 1      | Medium | WD-\*, WL-\*, VI-1 |
| SDT = 2      | High   | VI-2               |
| Risk factors | Likelihood | Use cases         |
|--------------|------------|-------------------|
| NET is 0     | Low        |                   |
| NET is 1     | Medium     |                   |
| NET is 2     | High       |                   |

Cybersecurity requirements that mitigate this threat: CDTX, IDTX, DMIN
| Risk factors | Impact | Use cases         |
|--------------|--------|-------------------|
| FUN is 0     | Low    |                   |
| FUN is 1     | Medium |                   |
| FUN is 2     | High   |                   |

Mitigations for Likelihood:

* Medium to Low: DOCC
* Medium to Low:
  * REQ-CP-01
  * REQ-IP-01

* High to Low: CDTX, DOCC
* High to Low:
  * REQ-CP-01
  * REQ-IP-01

Mitigations for Impact:

* Medium to Low: DJST

* High to Low: DJST

#### B.4.3.6 TH-AVAI: Denial of service attack on product via exploitation of vulnerabilities

Attacker may exploit vulnerabilities in the product to reduce availability of product assets.

| Risk factors                                 | Likelihood | Security profiles            |
|----------------------------------------------|------------|------------------------------|
| max(PHY, SFT, NET) = 0 or COM = 0 or ADM = 0 | Low        | WD-1                         |
| all others                                   | Medium     | WD-2, WD-3, WD-4, WL-1, VI-1 |
| max(PHY, SFT, NET) = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2             |
* Medium to Low:
  * REQ-MON-01

| Risk factors           | Impact | Security profiles       |
|------------------------|--------|-------------------------|
| max(SDS, SDT, FUN) = 0 | Low    | none                    |
| max(SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, WL-\*, VI-1 |
| max(SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, VI-2        |

Cybersecurity requirements that mitigate this threat: NKEV, AVAI, LMII, LMAS, LOGG, VULH

All mitigations for TH-KEVU apply (using that cybersecurity requirement's risk formula), plus:

Mitigations for Impact:
* High to Low:
  * REQ-MON-01

* Medium to Low: (NTFY or WDOG)
#### B.4.3.6 TH-AVAI: Denial of service attack on product

* High to Low: NTFY, WDOG
Attacker may use network access to product to reduce availability of product functions.

#### B.4.3.7 TH-PDOS: Denial of service attack on product functions via system or network access
| Risk factors | Likelihood | Use cases         |
|--------------|------------|-------------------|
| NET is 0     | Low        |                   |
| all others   | Medium     |                   |
| NET is 2     | High       |                   |

Attacker may use host system or network access for a denial-of-service attack on product functions.

| Risk factors      | Likelihood |                                    |
|-------------------|------------|------------------------------------|
| max(SFT, NET) = 0 | Low        | WD-1                               |
| max(SFT, NET) = 1 | Medium     | WL-1, VI-1                         |
| max(SFT, NET) = 2 | High       | WD-2, WD-3, WD-4, WL-2, WL-3, VI-2 |

| Risk factors | Impact | Security profiles       |
|--------------|--------|-------------------------|
| FUN = 0      | Low    | none                    |
| FUN = 1      | Medium | WD-1, WD-3, WL-\*, VI-1 |
| FUN = 2      | High   | WD-2, WD-4, VI-2        |

Cybersecurity requirements that mitigate this threat: AUTH, AVAI, LMII, LOGG
| Risk factors      | Impact | Use cases         |
|-------------------|--------|-------------------|
| FUN and HOS are 0 | Low    |                   |
| all others        | Medium |                   |
| FUN or HOS are 2  | High   |                   |

Mitigations for Likelihood:

* Medium to Low: DOST

* High to Low: DOST

Mitigations for Impact:

* Medium to Low: (NTFY or WDOG), LMEM, LOGG

* High to Low: NTFY, WDOG, FDRP, LMEM, FAIR, LOGG

#### B.4.3.8 TH-DDOS: Denial of service attack on other products via exploitation of vulnerabilities
* Medium to Low:
  * REQ-AP-01
  * REQ-AP-02
  * REQ-AP-03

Attacker may exploit vulnerabilities in the product to attack other products.

| Risk factors                  | Likelihood | Security profiles            |
|-------------------------------|------------|------------------------------|
| NET = 0 or COM = 0 or ADM = 0 | Low        | WD-1                         |
| all others                    | Medium     | WD-2, WD-3, WD-4, WL-1, VI-1 |
| NET = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2             |

| Risk factors | Impact | Security profiles                 |
|--------------|--------|-----------------------------------|
| NET = 0      | Low    | WD-1, VI-1                        |
| NET = 1      | Medium | WL-1,                             |
| NET = 2      | High   | WD-2, WD-3, WD-4, WL-2, WL-3, V-2 |

Cybersecurity requirements that mitigate this threat: NKEV, LMII, MINI, LMAS, LOGG, VULH

All mitigations from TH-KEVU apply (using that cybersecurity requirement's risk formula), plus:
* High to Low:
  * REQ-AP-01
  * REQ-AP-02
  * REQ-AP-03

Mitigations for Impact:

* Medium to Low: MDOC

* High to Low: MDOC, MPHY
* Medium to Low:
  * REQ-MON-01
  * REQ-AP-04

#### B.4.3.9 TH-MQSE: Masquerading authorized server
* High to Low:
  * REQ-MON-01
  * REQ-AP-04
  * REQ-AP-05

Attacker may masquerade as an authorized server to get unauthorized access to product assets.
#### B.4.3.8 TH-DDOS: Interference with other devices

| Risk factors       | Likelihood | Security profiles |
|--------------------|------------|-------------------|
| NET = 0 or COM = 0 | Low        | WD-1, VI-1        |
| all others         | Medium     | WD-2, WD-3, WD-4  |
| NET = 2 & COM = 2  | High       | WL-2, WL-3, VI-2  |
Attacker may use product functions to interfere with other devices or services.

| Risk factors                | Impact | Security profiles      |
|-----------------------------|--------|------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                   |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, VI-1       |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-\* VI-2 |
| Risk factors | Likelihood | Use cases         |
|--------------|------------|-------------------|
| NET = 0      | Low        |                   |
| NET = 1      | Medium     |                   |
| NET = 2      | High       |                   |

Cybersecurity requirements that mitigate this threat: CDTX, IDTX, AUTH, SCUD, LOGG
| Risk factors | Impact | Use cases         |
|--------------|--------|-------------------|
| NET = 0      | Low    |                   |
| NET = 1      | Medium |                   |
| NET = 2      | High   |                   |

Mitigations for Likelihood:

* Medium to Low: AUTH, SUDC, (SUVP or SUAP or SUOE or SUAO), CDTX, IDTX
* Medium to Low:
  * REQ-NI-01

* High to Low: AUTH, SUDC, (SUAP or SUAO), CDTX, IDTX
* High to Low:
  * REQ-NI-01

Mitigations for Impact:

* Medium to Low: LOGG
* Medium to Low:
  * REQ-MON-01

* High to Low: LOGG
* High to Low:
  * REQ-MON-01

#### B.4.3.10 TH-AHHS: Harm to host system via unauthorized access through the network

@@ -2641,27 +2615,31 @@ Attacker may use unauthorized access to the product through the network to harm

> NOTE: If the attacker has physical or host system software access, they do not need to use the network device to harm the system.

| Risk factors                  | Likelihood | Security profiles |
|-------------------------------|------------|-------------------|
| NET = 0 or COM = 0 or ADM = 0 | Low        | WD-1, VI-1        |
| all others                    | Medium     | WD-4              |
| NET = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2  |
| Risk factors | Likelihood | Use cases         |
|--------------|------------|-------------------|
| NET = 0      | Low        |                   |
| NET = 1      | Medium     |                   |
| NET = 2      | High       |                   |

| Risk factors | Impact | Security profiles             |
|--------------|--------|-------------------------------|
| SYS = 0      | Low    | none                          |
| SYS = 1      | Medium | WD-1, WD-3, WL-1, VI-1        |
| SYS = 2      | High   | WD-2, WD-4, WL-2, WL-3,  VI-2 |
| Risk factors | Impact | Use cases         |
|--------------|--------|-------------------|
| HOS = 0      | Low    |                   |
| HOS = 1      | Medium |                   |
| HOS = 2      | High   |                   |

Cybersecurity requirements that mitigate this threat: NKEV, SSDD, LMII, SCUD, AUTH, LMAS, LOGG
Mitigations for Likelihood:

All mitigations from TH-KEVU apply (using that cybersecurity requirement's risk formula), plus:
* Medium to Low:
  * REQ-ACC-01

Mitigations for Likelihood:
* High to Low:
  * REQ-ACC-01

* Medium to Low: AUTH
* Medium to Low:
  * REQ-MON-01

* High to Low: AUTH
* High to Low:
  * REQ-MON-01

### B.5.2 Mapping of use cases to risk factors