Cyber on Board 2025

Software design patterns for a STRIDE approach on an AUV fleet

Vous devez être inscrit et connecté pour accéder à cette fonctionnalité

Description

This work applies the STRIDE threat modeling framework to UAV fleets, using a model-based systems engineering (MBSE) approach. STRIDE identifies six types of threat: Spoofing, tampering, repudiation, information disclosure, denial of service and privilege escalation. The aim is to simulate the operations of a fleet of drones and assess the impact of potential attacks or threats. The modeling approach relies on established software design patterns such as Singleton, Composite, Proxy, Adapter, Memento, Observer and Policy to ensure modularity, reusability and ease of maintenance. These models also promote interoperability with third-party tools, enabling hybrid simulations and flexible integration of new devices. Currently, this approach is being used in a case study to map an area of interest using a fleet of virtual drones. Future work will extend this framework to advanced threat and risk assessments (TARA), taking partial failures into account, exploring more complex scenarios and drawing on more comprehensive metrics to propose appropriate security enhancement measures.

Présentée par