8 June 2024

MITRE Releases EMB3D – A Cybersecurity Threat Model for Embedded Devices


EMB3D MODEL STRENGTHENED BY PEER REVIEWS FROM INFRASTRUCTURE INDUSTRIES

After the model garnered significant interest for peer review across diverse industries, numerous organizations piloted the threat model. The EMB3D team appreciates the interest and feedback from vendors and integrators across many industries, including energy, water, manufacturing, aerospace, health, and automotive, as well as researchers and threat tool vendors. This ongoing collaborative effort has been instrumental in refining and enhancing the model’s content and usability. The team looks forward to continued collaboration to strengthen the ability of the model to enable “secure by design.”

“Our framework’s strength lies in the collaborative efforts and rigorous review process across industries,” said Yosry Barsoum, vice president and director, Center for Securing the Homeland at MITRE. “The diverse perspectives and invaluable insights shared have fortified our approach, ensuring a robust and effective solution to address the evolving challenges in embedded device security.”

LEVERAGING ESTABLISHED MODELS TO STRENGTHEN EMBEDDED DEVICE SECURITY

EMB3D aligns with and expands on several existing models, including Common Weakness Enumeration, MITRE ATT&CK®, and Common Vulnerabilities and Exposures, but with a specific embedded-device focus. The threats defined within EMB3D are based on observation of use by threat actors, proof-of-concept and theoretical/conceptual security research publications, and device vulnerability and weakness reports. These threats are mapped to device properties to help users develop and tailor accurate threat models for specific embedded devices. EMB3D suggests technical mechanisms that vendors should build into devices to mitigate each given threat. EMB3D is a comprehensive framework for the entire security ecosystem—device vendors, asset owners, security researchers, and testing organizations.

No comments: