Joonhyuk Park (School of Cybersecurity, Korea University), Jiwon Kwak (School of Cybersecurity, Korea University), Geunwoo Baek (School of Cybersecurity, Korea University), Dohee Kang (School of Cybersecurity, Korea University), Seungjoo Kim (School of Cybersecurity, Korea University)

The increasing significance of space-system cybersecurity in the space industry underscores the necessity of moving beyond development paradigms based on security by obscurity. Consequently, international standards such as ISO 20517 recommend the use of threat modeling to ensure security when developing space systems. Because manual threat modeling is time-consuming, it has motivated substantial research into the development of automated tools. Despite this interest, automated threat modeling tools specialized for the space domain remain scarce. Therefore, this paper proposes an automated threat modeling tool for the space domain by enhancing the Microsoft Threat Modeling Tool (MS-TMT). The tool was developed by integrating the Aerospace SPARTA matrix and the D3FEND knowledge base into MS-TMT. To evaluate its effectiveness, we conducted a case study involving four space-system security incidents, including the Viasat hacking. In the absence of existing satellite-specific threat modeling tools, we selected SecOpsTM as a comparative baseline because it is an automated threat modeling tool that identifies threats in a manner conceptually similar to our approach, enabling a fair and meaningful comparison. The quantitative evaluation demonstrated that our tool achieved an accuracy of 100%, whereas SecOpsTM achieved an average accuracy of 54%.

View More Papers

FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web...

Runhao Liu (National University of Defense Technology), Jiarun Dai (Fudan University), Haoyu Xiao (Fudan University), Yuan Zhang (Fudan University), Yeqi Mou (National University of Defense Technology), Lukai Xu (National University of Defense Technology), Bo Yu (National University of Defense Technology), Baosheng Wang (National University of Defense Technology), Min Yang (Fudan University)

Read More

SNPeek: Side-Channel Analysis for Privacy Applications on Confidential VMs

Ruiyi Zhang (CISPA Helmholtz Center for Information Security), Albert Cheu (Google), Adria Gascon (Google), Daniel Moghimi (Google), Phillipp Schoppmann (Google), Michael Schwarz (CISPA Helmholtz Center for Information Security), Octavian Suciu (Google)

Read More

PriMod4AI: Lifecycle-Aware Privacy Threat Modeling for AI Systems using...

Gautam Savaliya (Deggendorf Institute of Technology, Germany), Robert Aufschlager (Deggendorf Institute of Technology, Germany), Abhishek Subedi (Deggendorf Institute of Technology, Germany), Michael Heigl (Deggendorf Institute of Technology, Germany), Martin Schramm (Deggendorf Institute of Technology, Germany)

Read More