Sammanfattning

As cyber-physical systems become increasingly integrated and interconnected, risks and threats also become dependent on each component in a complex system. Previously, threat analysis and risk assessments have been done separately to identify and reduce vulnerabilities within each system. However, this is no longer a sustainable practice as cyber-physical systems and IT/OT systems are more dependent on each other than ever. Furthermore, the overlap in methods used to analyze and assess threats and risks for safety and security, respectively, is quite substantial, but there is a lack of tools to leverage this into a more comprehensive process. The need for tools with the capability to support threat analysis and risk assessment in both cybersecurity and functional safety is apparent. This thesis investigates how a method agnostic TARA/HARA framework can be designed and supported in software. The work explores design principles and technical solutions for supporting co-analysis of cybersecurity and functional safety across both OT and IT domains. Particular emphasis is placed on collaboration between multiple stakeholders, support for concurrent risk assessment, and mechanisms for maintaining and evolving risk assessments over time. As part of the study, an artifact is designed and implemented to demonstrate key concepts and functionality. This artifact is then evaluated with respect to threat model agnosticism, usability, flexibility and its support for collaborative and iterative risk assessment. Finally, the thesis investigates the potential role of Large Language Models (LLMs) as decision-support tools for threat identification and analysis.

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.