<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[ - Chapter 1 - Understanding Threat Models]]></title>
		<link>https://hackmyride.com/forum/</link>
		<description><![CDATA[ - https://hackmyride.com/forum]]></description>
		<pubDate>Sat, 06 Jun 2026 05:27:38 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Enhancement of Automotive Penetration Testing with Threat Analyses Results]]></title>
			<link>https://hackmyride.com/forum/showthread.php?tid=2651</link>
			<pubDate>Mon, 27 Mar 2023 17:37:16 -0500</pubDate>
			<dc:creator><![CDATA[<a href="https://hackmyride.com/forum/member.php?action=profile&uid=1">HackMaster</a>]]></dc:creator>
			<guid isPermaLink="false">https://hackmyride.com/forum/showthread.php?tid=2651</guid>
			<description><![CDATA[<span style="font-weight: bold;" class="mycode_b"><span style="font-size: large;" class="mycode_size">Enhancement of Automotive Penetration Testing with Threat Analyses Results</span></span><br />
<br />
<br />
<iframe src="https://hackmyride.com/forum/attachment.php?aid=171" width="100%" height="950px"></iframe><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://hackmyride.com/forum/images/attachtypes/pdf.png" title="Adobe Acrobat PDF" border="0" alt=".pdf" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=171" target="_blank" title="">Enhancement of Automotive Penetration Testing.pdf</a> (Size: 296.92 KB / Downloads: 7)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;" class="mycode_b"><span style="font-size: large;" class="mycode_size">Enhancement of Automotive Penetration Testing with Threat Analyses Results</span></span><br />
<br />
<br />
<iframe src="https://hackmyride.com/forum/attachment.php?aid=171" width="100%" height="950px"></iframe><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://hackmyride.com/forum/images/attachtypes/pdf.png" title="Adobe Acrobat PDF" border="0" alt=".pdf" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=171" target="_blank" title="">Enhancement of Automotive Penetration Testing.pdf</a> (Size: 296.92 KB / Downloads: 7)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[ACEA Principles of Automobile Cybersecurity]]></title>
			<link>https://hackmyride.com/forum/showthread.php?tid=2647</link>
			<pubDate>Mon, 27 Mar 2023 17:13:08 -0500</pubDate>
			<dc:creator><![CDATA[<a href="https://hackmyride.com/forum/member.php?action=profile&uid=1">HackMaster</a>]]></dc:creator>
			<guid isPermaLink="false">https://hackmyride.com/forum/showthread.php?tid=2647</guid>
			<description><![CDATA[<span style="font-weight: bold;" class="mycode_b"><span style="font-size: large;" class="mycode_size">ACEA Principles of Automobile Cybersecurity</span></span><br />
<br />
<br />
<br />
<iframe src="https://hackmyride.com/forum/attachment.php?aid=172" width="100%" height="950px"></iframe><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://hackmyride.com/forum/images/attachtypes/pdf.png" title="Adobe Acrobat PDF" border="0" alt=".pdf" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=172" target="_blank" title="">ACEA_Principles_of_Automobile_Cybersecurity.pdf</a> (Size: 632.38 KB / Downloads: 7)
<!-- end: postbit_attachments_attachment -->]]></description>
			<content:encoded><![CDATA[<span style="font-weight: bold;" class="mycode_b"><span style="font-size: large;" class="mycode_size">ACEA Principles of Automobile Cybersecurity</span></span><br />
<br />
<br />
<br />
<iframe src="https://hackmyride.com/forum/attachment.php?aid=172" width="100%" height="950px"></iframe><br /><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://hackmyride.com/forum/images/attachtypes/pdf.png" title="Adobe Acrobat PDF" border="0" alt=".pdf" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=172" target="_blank" title="">ACEA_Principles_of_Automobile_Cybersecurity.pdf</a> (Size: 632.38 KB / Downloads: 7)
<!-- end: postbit_attachments_attachment -->]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[The Automotive Threat Modeling Template]]></title>
			<link>https://hackmyride.com/forum/showthread.php?tid=2556</link>
			<pubDate>Mon, 27 Mar 2023 05:57:23 -0500</pubDate>
			<dc:creator><![CDATA[<a href="https://hackmyride.com/forum/member.php?action=profile&uid=1">HackMaster</a>]]></dc:creator>
			<guid isPermaLink="false">https://hackmyride.com/forum/showthread.php?tid=2556</guid>
			<description><![CDATA[<span style="color: #eeeeee;" class="mycode_color"><span style="font-size: large;" class="mycode_size">The Automotive Threat Modeling Template</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">Threat mitigation is an important part of the security development lifecycle (SDL) and at NCC Group we have been performing a number of threat modeling workshops focused specifically on the automotive sector.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">Considering the increasing research and media attention in relation to connected cars, it is fundamental to understand the threats affecting these new emerging systems and technologies.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">In order to assist with the need to secure automotive vehicles, we developed a customized template for automotive threat modeling activities, tailored to the threats affecting the cyber security posture of connected vehicles.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The Automotive Threat Modeling &#153; Template was created using the Microsoft (MS) Threat Modeling Tool 2016 and therefore threat models are created using this product.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Background & Motivations: Why the template?</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The STRIDE [1] approach has proved to be an effective way to highlight and categorise threats. With the goal to assist with this approach, the MS Threat Modeling Tool 2016 provides a way to use Data Flow Diagrams (DFDs) to identify threats in the design phase of any software/hardware and understand potential attacks based on the identified threats.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">A threat modeling workshop for automotive-related technologies requires DFDs with custom elements, tailored threats and specific recommendations. The lack of a specific template for automotive threat modeling brought about the development of the Automotive TM Template, which takes advantage of a new feature in the MS Threat Modeling Tool 2016 that allows the creation of entirely new customised templates.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">The Solution and its Features</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The template permits the creation of specific automotive threat models with:</span><br />
<ul class="mycode_list"><li><span style="color: #eeeeee;" class="mycode_color">Processes and Data Stores related to the components of connected cars.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">External Interactors tailored to an automotive system.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Data Flows that correspond to the messages exchanged over the air or inside the vehicle itself.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Trust Boundaries that take into consideration the environment and the vehicle-to-vehicle (V2V) networks.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Threat Types and Categories that follow the STRIDE classification, based on known and potential threats to the connected cars’ components.</span><br />
</li>
</ul>
<br />
<span style="color: #eeeeee;" class="mycode_color">Tailored Threat Properties including:</span><br />
<ul class="mycode_list"><li><span style="color: #eeeeee;" class="mycode_color">Priority, based on the risk of every threat applied in its context.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Attack Methods to potentially exploit the identified threats and to help further with the creation of Attack Trees.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Recommendations that suggest how to mitigate the threats.</span><br />
</li>
</ul>
<br />
<span style="color: #eeeeee;" class="mycode_color">The following screenshot provides a view of a sample threat model created using the template:</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><img src="https://i0.wp.com/research.nccgroup.com/wp-content/uploads/2020/12/th-cc-11.png?resize=1024%2C452&amp;ssl=1" loading="lazy"  width="1024" height="452" alt="[Image: th-cc-11.png?resize=1024%2C452&amp;ssl=1]" class="mycode_img" /></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #eeeeee;" class="mycode_color"><span style="font-style: italic;" class="mycode_i"><span style="font-weight: bold;" class="mycode_b">Figure 1 – Sample threat model using the Automotive TM Template</span></span></span></div>
<br />
<span style="color: #eeeeee;" class="mycode_color">The following screenshot shows the template itself and a specific threat type that was added: </span><br />
<span style="color: #eeeeee;" class="mycode_color"><img src="https://i0.wp.com/research.nccgroup.com/wp-content/uploads/2020/12/thcc2.png?resize=1024%2C306&amp;ssl=1" loading="lazy"  width="1024" height="306" alt="[Image: thcc2.png?resize=1024%2C306&amp;ssl=1]" class="mycode_img" /></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-style: italic;" class="mycode_i">Figure 2 – View of the tailored threat types from the template editor</span></span></span></div>
<div style="text-align: center;" class="mycode_align">
<br />
<br />
<div style="text-align: left;" class="mycode_align"><span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">The Results</span></span></div>
</div>
<br />
<span style="color: #eeeeee;" class="mycode_color">During a number of automotive threat modeling workshops, the template has been used to provide our clients with a view of the threats and attacks to their automotive systems.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">We have created various threat models for different technologies and connected car platforms from SAE [2] Level 1 of Driving Automation (non-autonomous car with some assisted driving modes), up to SAE [2] Level 5 of Driving Automation (full automation with the “system” that monitors the driving environment).</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The threat modeling, in conjunction with our security assessment activities (for both software and hardware), have proven an effective way to increase the security assurance of automotive technologies, architectures and products.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Download the Template</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The Automotive Threat Modeling Template can be downloaded from:</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><a href="https://github.com/nccgroup/The_Automotive_Threat_Modeling_Template" target="_blank" rel="noopener" class="mycode_url">https://github.com/nccgroup/The_Automoti...g_Template</a></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Further Developments</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The benefits we have gained from creating automotive threat models using our customized template have highlighted the need for new templates such as one for Internet of Things (IoT) products and technologies, which we are currently developing.</span><br />
<br />
<br />
<span style="color: #eeeeee;" class="mycode_color">Written by Christiano Corradini</span><br />
<span style="color: #eeeeee;" class="mycode_color">First published on 20/07/16</span>]]></description>
			<content:encoded><![CDATA[<span style="color: #eeeeee;" class="mycode_color"><span style="font-size: large;" class="mycode_size">The Automotive Threat Modeling Template</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">Threat mitigation is an important part of the security development lifecycle (SDL) and at NCC Group we have been performing a number of threat modeling workshops focused specifically on the automotive sector.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">Considering the increasing research and media attention in relation to connected cars, it is fundamental to understand the threats affecting these new emerging systems and technologies.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">In order to assist with the need to secure automotive vehicles, we developed a customized template for automotive threat modeling activities, tailored to the threats affecting the cyber security posture of connected vehicles.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The Automotive Threat Modeling &#153; Template was created using the Microsoft (MS) Threat Modeling Tool 2016 and therefore threat models are created using this product.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Background & Motivations: Why the template?</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The STRIDE [1] approach has proved to be an effective way to highlight and categorise threats. With the goal to assist with this approach, the MS Threat Modeling Tool 2016 provides a way to use Data Flow Diagrams (DFDs) to identify threats in the design phase of any software/hardware and understand potential attacks based on the identified threats.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">A threat modeling workshop for automotive-related technologies requires DFDs with custom elements, tailored threats and specific recommendations. The lack of a specific template for automotive threat modeling brought about the development of the Automotive TM Template, which takes advantage of a new feature in the MS Threat Modeling Tool 2016 that allows the creation of entirely new customised templates.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">The Solution and its Features</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The template permits the creation of specific automotive threat models with:</span><br />
<ul class="mycode_list"><li><span style="color: #eeeeee;" class="mycode_color">Processes and Data Stores related to the components of connected cars.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">External Interactors tailored to an automotive system.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Data Flows that correspond to the messages exchanged over the air or inside the vehicle itself.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Trust Boundaries that take into consideration the environment and the vehicle-to-vehicle (V2V) networks.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Threat Types and Categories that follow the STRIDE classification, based on known and potential threats to the connected cars’ components.</span><br />
</li>
</ul>
<br />
<span style="color: #eeeeee;" class="mycode_color">Tailored Threat Properties including:</span><br />
<ul class="mycode_list"><li><span style="color: #eeeeee;" class="mycode_color">Priority, based on the risk of every threat applied in its context.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Attack Methods to potentially exploit the identified threats and to help further with the creation of Attack Trees.</span><br />
</li>
<li><span style="color: #eeeeee;" class="mycode_color">Recommendations that suggest how to mitigate the threats.</span><br />
</li>
</ul>
<br />
<span style="color: #eeeeee;" class="mycode_color">The following screenshot provides a view of a sample threat model created using the template:</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><img src="https://i0.wp.com/research.nccgroup.com/wp-content/uploads/2020/12/th-cc-11.png?resize=1024%2C452&amp;ssl=1" loading="lazy"  width="1024" height="452" alt="[Image: th-cc-11.png?resize=1024%2C452&amp;ssl=1]" class="mycode_img" /></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #eeeeee;" class="mycode_color"><span style="font-style: italic;" class="mycode_i"><span style="font-weight: bold;" class="mycode_b">Figure 1 – Sample threat model using the Automotive TM Template</span></span></span></div>
<br />
<span style="color: #eeeeee;" class="mycode_color">The following screenshot shows the template itself and a specific threat type that was added: </span><br />
<span style="color: #eeeeee;" class="mycode_color"><img src="https://i0.wp.com/research.nccgroup.com/wp-content/uploads/2020/12/thcc2.png?resize=1024%2C306&amp;ssl=1" loading="lazy"  width="1024" height="306" alt="[Image: thcc2.png?resize=1024%2C306&amp;ssl=1]" class="mycode_img" /></span><br />
<div style="text-align: center;" class="mycode_align"><span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-style: italic;" class="mycode_i">Figure 2 – View of the tailored threat types from the template editor</span></span></span></div>
<div style="text-align: center;" class="mycode_align">
<br />
<br />
<div style="text-align: left;" class="mycode_align"><span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">The Results</span></span></div>
</div>
<br />
<span style="color: #eeeeee;" class="mycode_color">During a number of automotive threat modeling workshops, the template has been used to provide our clients with a view of the threats and attacks to their automotive systems.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">We have created various threat models for different technologies and connected car platforms from SAE [2] Level 1 of Driving Automation (non-autonomous car with some assisted driving modes), up to SAE [2] Level 5 of Driving Automation (full automation with the “system” that monitors the driving environment).</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The threat modeling, in conjunction with our security assessment activities (for both software and hardware), have proven an effective way to increase the security assurance of automotive technologies, architectures and products.</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Download the Template</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The Automotive Threat Modeling Template can be downloaded from:</span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><a href="https://github.com/nccgroup/The_Automotive_Threat_Modeling_Template" target="_blank" rel="noopener" class="mycode_url">https://github.com/nccgroup/The_Automoti...g_Template</a></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b">Further Developments</span></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color">The benefits we have gained from creating automotive threat models using our customized template have highlighted the need for new templates such as one for Internet of Things (IoT) products and technologies, which we are currently developing.</span><br />
<br />
<br />
<span style="color: #eeeeee;" class="mycode_color">Written by Christiano Corradini</span><br />
<span style="color: #eeeeee;" class="mycode_color">First published on 20/07/16</span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Chapter 1 - Understanding Threat Models]]></title>
			<link>https://hackmyride.com/forum/showthread.php?tid=414</link>
			<pubDate>Sat, 25 Feb 2023 04:13:25 -0600</pubDate>
			<dc:creator><![CDATA[<a href="https://hackmyride.com/forum/member.php?action=profile&uid=1">HackMaster</a>]]></dc:creator>
			<guid isPermaLink="false">https://hackmyride.com/forum/showthread.php?tid=414</guid>
			<description><![CDATA[<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-size: large;" class="mycode_size">Chapter 1 - Understanding Threat Models</span></span></span><br />
<br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><iframe src="https://hackmyride.com/forum/attachment.php?aid=173" width="100%" height="950px"></iframe></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://hackmyride.com/forum/images/attachtypes/pdf.png" title="Adobe Acrobat PDF" border="0" alt=".pdf" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=173" target="_blank" title="">Chapter 1 - Understanding Threat Models.pdf</a> (Size: 259.57 KB / Downloads: 14)
<!-- end: postbit_attachments_attachment --></span>]]></description>
			<content:encoded><![CDATA[<span style="color: #eeeeee;" class="mycode_color"><span style="font-weight: bold;" class="mycode_b"><span style="font-size: large;" class="mycode_size">Chapter 1 - Understanding Threat Models</span></span></span><br />
<br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><iframe src="https://hackmyride.com/forum/attachment.php?aid=173" width="100%" height="950px"></iframe></span><br />
<br />
<span style="color: #eeeeee;" class="mycode_color"><!-- start: postbit_attachments_attachment -->
<br /><!-- start: attachment_icon -->
<img src="https://hackmyride.com/forum/images/attachtypes/pdf.png" title="Adobe Acrobat PDF" border="0" alt=".pdf" />
<!-- end: attachment_icon -->&nbsp;&nbsp;<a href="attachment.php?aid=173" target="_blank" title="">Chapter 1 - Understanding Threat Models.pdf</a> (Size: 259.57 KB / Downloads: 14)
<!-- end: postbit_attachments_attachment --></span>]]></content:encoded>
		</item>
	</channel>
</rss>