The practical approach
Armed with the TARA fundamentals and the common pitfalls, we are now ready to walk through the practical approach of threat modeling automotive systems. Throughout this approach, we will focus on three objectives:
- Producing the highest threat coverage possible for our target system
- Choosing the correct risk treatment decisions
- Finishing the TARA within a reasonable time frame that fits within the project’s allotted time
Know your system
TARA is most effective and streamlined when the security analyst is intimately familiar with the system under analysis. However, given the breadth of knowledge required for accurately analyzing automotive systems, in most cases, the security analyst must collaborate with the domain experts to understand the system functions, uncover damage scenarios, and accurately capture assets that need protection. This can be done in an interview-style setting, where the security analyst asks a series of questions...