TARA - Threat Analysis and Risk Assessment
Introduction
- Structured cybersecurity process used especially in the automotive industry to:
- identify what could be attacked in a vehicle/system,
- understand the consequences,
- estimate the cybersecurity risk, and
- decide what security controls are needed.
- TARA is a central part of ISO/SAE 21434, the automotive cybersecurity engineering standard.
Flow
-
Identify assets - determine what needs protection, such as an ECU, CAN communication, braking commands, vehicle keys, user data, firmware, or diagnostic interfaces.
-
Define damage scenarios - ask what could happen if an asset is compromised. For example, “an attacker sends unauthorized braking commands.”
-
Identify threats / threat scenarios - describe what an attacker might do, such as spoofing CAN messages, modifying firmware, stealing credentials, or exploiting a wireless interface.
-
Model attack paths - determine how the attacker could reach the target, for example:
Internet → Telematics ECU → Gateway → CAN bus → Brake ECU. Attack trees are one technique used for representing such paths. -
Assess impact - evaluate how serious the resulting damage would be, considering areas such as safety, financial loss, operational consequences, and privacy.
-
Assess attack feasibility - estimate how difficult the attack is considering factors such as attacker knowledge, equipment, access, and time.
-
Determine cybersecurity risk - combine the potential impact and feasibility to determine which threats require priority treatment.
-
Define risk treatment - decide whether to reduce, avoid, share/transfer, or accept the risk, and establish cybersecurity requirements and controls.
Example
Asset: Infotainment/vehicle network
Threat: Attacker exploits Bluetooth remotely
Attack path: Phone → Bluetooth → Infotainment ECU → Gateway → CAN
Damage scenario: Attacker sends unauthorized vehicle-control messages
Impact: Potentially high because vehicle functions could be affected
Feasibility: Depends on required access, expertise, exploit complexity, equipment, etc.
Risk: If the resulting combination is unacceptable, controls might include network segmentation, authentication, secure gateways, message validation, and software hardening.