id, title, category, status, canonical_id, aliases, duplicate_of, source_trust_level, confidence_score, verification_status, tags, raw_sources, last_reinforced, github_commit, tech_stack
id
title
category
status
canonical_id
aliases
duplicate_of
source_trust_level
confidence_score
verification_status
tags
raw_sources
last_reinforced
github_commit
tech_stack
wiki-2026-0508-tara
TARA (Threat Analysis and Risk Assessment)
10_Wiki/Topics
verified
self
Threat Analysis Risk Assessment
ISO 21434 TARA
Automotive Threat Modeling
none
A
0.9
applied
security
threat-modeling
automotive
iso-21434
2026-05-10
pending
language
framework
methodology
iso-21434
TARA (Threat Analysis and Risk Assessment)
매 한 줄
"매 automotive cybersecurity 의 mandatory threat modeling" . 매 ISO/SAE 21434 의 core process — 매 vehicle E/E system 의 cybersecurity risk 의 systematic 의 identify + assess + treat. 2026 의 UNECE R155 type-approval 의 prerequisite.
매 핵심
매 7 steps (ISO 21434 §15)
Asset identification : 매 cybersecurity property (CIAA) 의 정의.
Threat scenario identification : STRIDE/EVITA 의 적용.
Impact rating : Safety, Financial, Operational, Privacy (SFOP).
Attack path analysis : 매 attack tree / kill chain.
Attack feasibility rating : time, expertise, knowledge, opportunity, equipment.
Risk determination : Impact × Feasibility → 1-5 risk value.
Risk treatment : avoid, reduce, share, retain.
매 STRIDE for automotive
S poofing — 매 ECU identity forgery (CAN ID).
T ampering — 매 firmware mod, OTA hijack.
R epudiation — 매 audit log absence.
I nfo disclosure — 매 GPS/PII leak.
D oS — 매 CAN bus flood.
E oP — 매 infotainment → drive ECU pivot.
매 vs IT threat modeling
Lifecycle : 매 15 yr vehicle 의 — 매 long-term update.
Safety coupling : 매 cyber → physical harm (브레이크).
Supply chain : 매 multi-tier (OEM ← T1 ← T2).
Standards : 매 ISO 21434 + UNECE R155 의 mandatory.
매 응용
New vehicle development (concept phase).
CSMS audit evidence.
Post-incident re-assessment.
💻 패턴
Asset table (YAML)
Damage scenario × impact rating
Threat scenario (STRIDE)
Attack path
Feasibility rating (ISO 21434 Annex G)
Risk matrix
Treatment plan
매 결정 기준
상황
Approach
Automotive E/E (mandatory)
TARA per ISO 21434
IT system
STRIDE / PASTA
Industrial control (ICS)
IEC 62443 ZCR
Generic risk
NIST 800-30
기본값 : 매 ISO 21434 TARA — 매 OEM type approval (UNECE R155) 의 required.
🔗 Graph
🤖 LLM 활용
언제 : threat scenario brainstorming, attack tree generation, control gap analysis.
언제 X : final risk decision (human cybersecurity engineer 의 sign-off).
❌ 안티패턴
One-shot TARA : 매 lifecycle 의 update 의 — 매 vuln/incident 의 trigger.
Generic STRIDE only : 매 automotive-specific 의 EVITA 의 augment.
Skipping feasibility : 매 impact-only 의 risk 의 inflated.
Doc theater : 매 controls 의 implement 의 X — 매 evidence 의 X.
🧪 검증 / 중복
Verified (ISO/SAE 21434:2021, UNECE WP.29 R155, EVITA project).
신뢰도 A.
🕓 Changelog
날짜
변경
2026-05-08
Phase 1
2026-05-10
Manual cleanup — ISO 21434 7-step TARA, automotive STRIDE