Commit 3605f4bf authored by Valerie Aurora (Bow Shock)'s avatar Valerie Aurora (Bow Shock)
Browse files

Add list of threats from network interfaces, to be updated

parent d381da63
Loading
Loading
Loading
Loading
+251 −11
Original line number Diff line number Diff line
@@ -1938,7 +1938,7 @@ Assumptions can be updated to be less stringent as more use cases and mitigation

**[AS-LR]:** An attacker has the resources available to a small group of skilled individuals, without the backing of large corporations, nation-states, or immense wealth.

## C.4 Risk assessments of threats
## C.4 Threats and risk assessments of threats

### C.4.1 General

@@ -2029,25 +2029,265 @@ MI-LOGG: Logging
MI-SDRF: Secure data read from product
MI-SDTR: Secure data transfer to another product

**[TH-USDA]:** An attacker may read or modify security-relevant data without proper authorization while stored or in transmission.
### C.4.3 List of threats, risk assessments, and mitigations

**[TH-DATA]:** An attacker may read or modify data without proper authorization while being processed, stored, or transmitted by the product.
#### C.4.3.1 TH-UEVU: Unknown exploitable vulnerabilities

**[TH-FUNC]:** An attacker may use or modify functions of the product without proper authorization.
Attacker may use unknown exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.

**[TH-TRCH]:** An attacker may access or intercept the establishment of a communication channel over a network with a trusted system without proper authorization, or masquerade as a trusted system during the establishment.
| Risk factors                      | Likelihood | Security profiles      |
|-----------------------------------|------------|------------------------|
| max(PHY, SFT, NET) = 0 or COM = 0 | Low        | WD-1, VI-1             |
| all others                        | Medium     | WD-2, WD-3, WD-4, WL-1 |
| max(PHY, SFT, NET) = 2 & COM = 2  | High       | WL-2, WL-3, VI-2       |

**[TH-NETA]:** An attacker may transmit or access data over the network without proper authorization.
| Risk factors                | Impact | Security profiles                  |
|-----------------------------|--------|------------------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                               |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, WL-1, VI-1             |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-2, WL-3, WL-4, VI-2 |

**[TH-MASQ]:** An attacker may masquerade as the product itself to access data in remote systems without proper authorization.
Requirements that mitigate this threat: SSDD, LMII, DMIN, LMAS, LOGG

**[TH-DOSE]:** An attacker may prevent the performance of the essential functions of the product by overloading system resources.
Mitigations for Likelihood:

**[TH-DOSA]:** An attacker may use the unauthorized access to the product to prevent the performance of the essential functions of other devices.
* Medium to Low: SCFS, SSCA, ADEF, DPAH, PDDI-\*

**[TH-CONF]:** An attacker may read or modify configuration data of the product without proper authorization.
* High to Low: SCFS, SSCA, (FZ95 or BTIN or IMSL), MSAF-\*, MZRO-\*, ADEF, DPAH, PDDI-\*, JSTY

**[TH-UPDA]:** An attacker may cause unauthorized software updates to be installed or prevent authorized software updates.
Mitigations for Impact:

* Medium to Low: LOGG

* High to Low: DJST, LOGG

#### C.4.3.2 TH-KEVU: Known exploitable vulnerabilities

Attacker may use known exploitable vulnerabilities in the product implementation to get unauthorized access to product assets.

| Risk factors                                 | Likelihood | Security profiles            |
|----------------------------------------------|------------|------------------------------|
| max(PHY, SFT, NET) = 0 or COM = 0 or ADM = 0 | Low        | WD-1                         |
| all others                                   | Medium     | WD-2, WD-3, WD-4, WL-1, VI-1 |
| max(PHY, SFT, NET) = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2             |

| Risk factors                | Impact | Security profiles                  |
|-----------------------------|--------|------------------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                               |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, WL-1, VI-1             |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-2, WL-3, WL-4, VI-2 |

Requirements that mitigate this threat: NKEV, SSDD, LMII, SCUD, DMIN, LMAS, LOGG, VULH

All mitigations from TH-UEVU apply (using that requirement's risk formula), in addition to:

Mitigations for Likelihood:

* Medium to Low: (KEVD or KEVA or KEVT or SCAN), KEVM, (SUVP or SUAP or SUOE or SUAO), VULH

* High to Low: KEVD, KEVA, (KEVT or SCAN), KEVM, (SUAP or SUAO), VULH

#### C.4.3.3 TH-CONF: Access to assets via configuration errors

Attacker may use configuration errors to get unauthorized access to the product assets.

| Risk factors                      | Likelihood | Security profiles      |
|-----------------------------------|------------|------------------------|
| max(PHY, SFT, NET) = 0 or ADM = 0 | Low        | WD-1, VI-1             |
| all others                        | Medium     | WL-1                   |
| max(PHY, SFT, NET) = 2 & ADM = 2  | High       | WD-3, WL-2, WL-3, VI-2 |

| Risk factors                     | Impact | Security profiles      |
|----------------------------------|--------|------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                   |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, VI-1       |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-\* VI-2 |

Requirements that mitigate this threat: CDST, SDEF, DMIN, LOGG

Mitigations for Likelihood:

* Medium to Low: ADEF, DPAH, PDDI-1

* High to Low: ADEF, DPAH, PDDI-2 if PHY = 2, PDDI-3 if SFT = 2, PDDI-4 if NET = 2

Mitigations for Impact:

* Medium to Low: CDST

* High to Low: CDST, DJST, LOGG

#### C.4.3.4 TH-UADT: Unauthorized access to confidential data transmitted

Attacker may use network access to get unauthorized access to confidential data transmitted by the product.

| Risk factors | Likelihood | Security profiles            |
|--------------|------------|------------------------------|
| LIS = 0      | Low        | WD-1, WD-2, WD-3, VI-1, VI-2 |
| LIS = 1      | Medium     | WL-1                         |
| LIS = 2      | High       | WD-4, WL-2, WL-3             |

| Risk factors | Impact | Security profiles  |
|--------------|--------|--------------------|
| SDT = 0      | Low    | none               |
| SDT = 1      | Medium | WD-\*, WL-\*, VI-1 |
| SDT = 2      | High   | VI-2               |

Requirements that mitigate this threat: CDTX, IDTX, DMIN

Mitigations for Likelihood:

* Medium to Low: DOCC

* High to Low: CDTX, DOCC

Mitigations for Impact:

* Medium to Low: DJST

* High to Low: DJST

#### C.4.3.5 TH-AVAI: Denial of service attack on product via exploitation of vulnerabilities

Attacker may exploit vulnerabilities in the product to reduce availability of product assets.

| Risk factors                                 | Likelihood | Security profiles            |
|----------------------------------------------|------------|------------------------------|
| max(PHY, SFT, NET) = 0 or COM = 0 or ADM = 0 | Low        | WD-1                         |
| all others                                   | Medium     | WD-2, WD-3, WD-4, WL-1, VI-1 |
| max(PHY, SFT, NET) = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2             |

| Risk factors           | Impact | Security profiles       |
|------------------------|--------|-------------------------|
| max(SDS, SDT, FUN) = 0 | Low    | none                    |
| max(SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, WL-\*, VI-1 |
| max(SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, VI-2        |

Requirements that mitigate this threat: NKEV, AVAI, LMII, LMAS, LOGG, VULH

All mitigations for TH-KEVU apply (using that requirement's risk formula), plus:

Mitigations for Impact:

* Medium to Low: (NTFY or WDOG)

* High to Low: NTFY, WDOG

#### C.4.3.6 TH-PDOS: Denial of service attack on product functions via system or network access

Attacker may use host system or network access for a denial-of-service attack on product functions.

| Risk factors      | Likelihood |                                    |
|-------------------|------------|------------------------------------|
| max(SFT, NET) = 0 | Low        | WD-1                               |
| max(SFT, NET) = 1 | Medium     | WL-1, VI-1                         |
| max(SFT, NET) = 2 | High       | WD-2, WD-3, WD-4, WL-2, WL-3, VI-2 |

| Risk factors | Impact | Security profiles       |
|--------------|--------|-------------------------|
| FUN = 0      | Low    | none                    |
| FUN = 1      | Medium | WD-1, WD-3, WL-\*, VI-1 |
| FUN = 2      | High   | WD-2, WD-4, VI-2        |

Requirements that mitigate this threat: AUTH, AVAI, LMII, LOGG

Mitigations for Likelihood:

* Medium to Low: DOST

* High to Low: DOST

Mitigations for Impact:

* Medium to Low: (NTFY or WDOG), LMEM, LOGG

* High to Low: NTFY, WDOG, FDRP, LMEM, FAIR, LOGG

#### C.4.3.7 TH-DDOS: Denial of service attack on other products via exploitation of vulnerabilities or unauthorized use of product functions

Attacker may exploit vulnerabilities in the product to attack other products.

Guidance: Traffic amplication attacks and other misuses of product functions are considered vulnerabilities and/or unauthorized use for the purpose of this threat.

| Risk factors                  | Likelihood | Security profiles            |
|-------------------------------|------------|------------------------------|
| NET = 0 or COM = 0 or ADM = 0 | Low        | WD-1                         |
| all others                    | Medium     | WD-2, WD-3, WD-4, WL-1, VI-1 |
| NET = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2             |

| Risk factors | Impact | Security profiles                 |
|--------------|--------|-----------------------------------|
| NET = 0      | Low    | WD-1, VI-1                        |
| NET = 1      | Medium | WL-1,                             |
| NET = 2      | High   | WD-2, WD-3, WD-4, WL-2, WL-3, V-2 |

Requirements that mitigate this threat: NKEV, LMII, MINI, LMAS, LOGG, VULH

All mitigations from TH-KEVU apply (using that requirement's risk formula), plus:

Mitigations for Impact:

* Medium to Low: MDOC

* High to Low: MDOC, MPHY

#### C.4.3.8 TH-MQSE: Masquerading authorized server

Attacker may masquerade as an authorized server to get unauthorized access to product assets.

| Risk factors       | Likelihood | Security profiles |
|--------------------|------------|-------------------|
| NET = 0 or COM = 0 | Low        | WD-1, VI-1        |
| all others         | Medium     | WD-2, WD-3, WD-4  |
| NET = 2 & COM = 2  | High       | WL-2, WL-3, VI-2  |

| Risk factors                | Impact | Security profiles      |
|-----------------------------|--------|------------------------|
| max(SYS, SDS, SDT, FUN) = 0 | Low    | none                   |
| max(SYS, SDS, SDT, FUN) = 1 | Medium | WD-1, WD-3, VI-1       |
| max(SYS, SDS, SDT, FUN) = 2 | High   | WD-2, WD-4, WL-\* VI-2 |

Requirements that mitigate this threat: CDTX, IDTX, AUTH, SCUD, LOGG

Mitigations for Likelihood:

* Medium to Low: AUTH, SUDC, (SUVP or SUAP or SUOE or SUAO), CDTX, IDTX

* High to Low: AUTH, SUDC, (SUAP or SUAO), CDTX, IDTX

Mitigations for Impact:

* Medium to Low: LOGG

* High to Low: LOGG

#### C.4.3.9 TH-AHHS: Harm to host system via unauthorized access through the network

Attacker may use unauthorized access to the product through the network to harm the host system.

_Note: If the attacker has physical or host system software access, they don't need to use the network device to harm the system._

| Risk factors                  | Likelihood | Security profiles |
|-------------------------------|------------|-------------------|
| NET = 0 or COM = 0 or ADM = 0 | Low        | WD-1, VI-1        |
| all others                    | Medium     | WD-4              |
| NET = 2 & COM = 2 & ADM = 2   | High       | WL-2, WL-3, VI-2  |

| Risk factors | Impact | Security profiles             |
|--------------|--------|-------------------------------|
| SYS = 0      | Low    | none                          |
| SYS = 1      | Medium | WD-1, WD-3, WL-1, VI-1        |
| SYS = 2      | High   | WD-2, WD-4, WL-2, WL-3,  VI-2 |

Requirements that mitigate this threat: NKEV, SSDD, LMII, SCUD, AUTH, LMAS, LOGG

All mitigations from TH-KEVU apply (using that requirement's risk formula), plus:

Mitigations for Likelihood:

* Medium to Low: AUTH

* High to Low: AUTH

## C.5 Mapping of Use Cases to Risk Factors