Model-based Safety and Security Co-Analysis using Component Attack Fault Trees in the Automotive Domain
Resumo
Cyber-physical systems (CPSs) in critical domains such as self-driven cars and unmanned aerial vehicles involve complex interactions between safety and security concerns. Failures in CPSs such as self-driven cars are caused either by hardware/software component faults or attacks. The identification of hazards, their risks, and root causes is addressed by Safety Engineering, e.g., using Fault Tree Analysis. On the other hand, Security Engineering addresses the identification of asset vulnerabilities, their associated external threats, risks, and causes, using Attack Tree Analysis. Although both disciplines use separate terminology, processes, and tools, they rely on a common system architecture and in the use models such as Component Fault Trees and Attack Trees to support their analyses. In the automotive domain, such analyses should be performed in alignment with guidance defined in assurance standards, e.g., ISO 26262 for functional safety, and ISO 21434 for cybersecurity. However, existing techniques that integrate safety and security models are not fully aligned with the ISO 21434. In this paper, we introduce a novel Component Attack Fault Trees (CAFT) modelling language, built upon Component Fault Trees and ISO 21434 concepts, for integrating safety and security analysis models. Since CAFT was built in alignment with traditional safety and security analysis formalisms and standards, it has the potential to guide engineers in the development of multi-concern analysis model-driven engineering tools. We illustrate the use of our CAFT language to support safety and security co-analysis of an automotive headlamp system.Referências
Adler, R., Domis, D., Höfig, K., Kemmann, S., Kuhn, T., Schwinn, J.P., Trapp, M.: Integration of component fault trees into the UML. In: Dingel, J., Solberg, A. (eds.) Models in Software Engineering, 312–327p. Springer, New York (2011)
Avizienis, A., Laprie, J. C., Randell, B., Landwehr, C. (2004). Basic Concepts and Taxonomy of Dependable and Secure Computing. Dependable and Secure Computing, IEEE Transactions on. 1. 11 33. DOI: 10.1109/TDSC.2004.2.
Biro, M., Mashkoor, A., Sametinger, J., Seker, R.: Software safety and security risk mitigation in cyber-physical systems. IEEE Software. 35 (1), 24–29, 2017.
Dantas, Y. G., Nigam, V., Ruess, H. Security Engineering for ISO 21434. Fortiss GmbH White Paper, Munich, Germany, 2020.
Domis, D. Integrating Fault Tree Analysis and Component-Oriented Model-Based Design of Embedded Systems. Dissertation Technische Universität Kaiserslautern, 2012.
Hernan S., Lambert S., Ostwald T., Shostack A. Threat Modeling - Uncover Security Design Flaws Using the STRIDE Approach, MSDN Mag. 2006.
Hofig, K., Joanni, A., Zeller, M., Montrone, F., Rothfelder, M., Amarnath, R. and Munk, P., and Nordmann, A. Model-Based Reliability and Safety: Reducing the Complexity of Safety Analyses Using Component Fault Trees. 2018 Annual Reliability and Maintainability Symposium (RAMS), 2018, pp. 1-7.
Huq, N. Automotive Cyber Security - Emerging Risks and New Case Study Insights.
ATZ Electron Worldw 19, 14–19 (2024). DOI: 10.1007/s38314-024-18900.
ISO/SAE 21434: Road Vehicles – Cybersecurity Engineering, ISO/TC 22/SC 32, 2021.
ISO 26262. Road Vehicles— Functional Safety for Road Vehicles, ISO/TC 22/SC32, 2018.
ISO/IEC. ISO/IEC 18045:2008 – Information technology – Security techniques – Methodology for IT security evaluation, 2008.
Kaiser, B., Schneider, D., Adler, R., Domis, D., Mohrle, F., Berres, A., Zeller, M., Hofig, K., Rothfelder, M. Advances in Component Fault Trees. Safety and Reliability – Safe Societies in a Changing World – Haugen et al. (Eds), 2018, Taylor & Francis Group, London.
Kaiser, B., Liggesmeyer, P., Mackel, O. A New Component Concept for Fault Trees. In Proceedings of the 8th Australian Workshop on Safety Critical Systems and Software, Canberra, 2003.
Knight, J. C. Safety Critical Systems: Challenges and Directions. International Conference on Software Engineering (ICSE), Orlando, Florida, USA, 2002.
Kruck, B., Munk, P., Angermeier, D. 2021. Safe and secure: Mutually supporting safety and security analyses with model-based suggestions. In 2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW) (pp. 172-181). IEEE.
Moncada, D. S. V. Hazard-driven realization view for Component Fault Trees.
Software and Systems Modeling (2020) 19: 1465-1481p. DOI: 10.1007/s10270-020-00792-8
OMG. The Unified Modeling Language specification version 2.5.1. Object Management Group. 2017. Online: [link].
OMG. The System Modeling Language specification version 2.0. Object Management Group. 2025. Online: [link].
Schneier, B. Modeling security threats. Dr. Dobb’s J. 24 (12), 1999.
Upstream. Global Automotive Cybersecurity Report. Upstream Sec. Ltd., 2024. Online: [link].
Vesely, W. E., Goldberg, F. F., Roberts, N. H., and Haasl, D. F. Fault Tree Handbook.
US Nuclear Regulatory Commission, 1981.
Wired. Hackers remotely kill a Jeep on the highway with me in it, 2015. Online: [link].
Zeller, M., Sorokos, I., Reich, J., Adler, R., and Schneider, D. (2023). Open Dependability Exchange Metamodel: A Format to Exchange Safety Information. 2023 Annual Reliability and Maintainability Symposium (RAMS), Orlando, FL, USA, 2023, pp. 1-7. DOI: 10.1109/RAMS51473.2023.10088190.
Zeller, M., Hofig, K., Schwinn, J. P. ArChes – Automatic generation of component fault trees from continuous function charts. 2017 IEEE 15th International Conference on Industrial Informatics (INDIN) (2017): 577-582p.
Avizienis, A., Laprie, J. C., Randell, B., Landwehr, C. (2004). Basic Concepts and Taxonomy of Dependable and Secure Computing. Dependable and Secure Computing, IEEE Transactions on. 1. 11 33. DOI: 10.1109/TDSC.2004.2.
Biro, M., Mashkoor, A., Sametinger, J., Seker, R.: Software safety and security risk mitigation in cyber-physical systems. IEEE Software. 35 (1), 24–29, 2017.
Dantas, Y. G., Nigam, V., Ruess, H. Security Engineering for ISO 21434. Fortiss GmbH White Paper, Munich, Germany, 2020.
Domis, D. Integrating Fault Tree Analysis and Component-Oriented Model-Based Design of Embedded Systems. Dissertation Technische Universität Kaiserslautern, 2012.
Hernan S., Lambert S., Ostwald T., Shostack A. Threat Modeling - Uncover Security Design Flaws Using the STRIDE Approach, MSDN Mag. 2006.
Hofig, K., Joanni, A., Zeller, M., Montrone, F., Rothfelder, M., Amarnath, R. and Munk, P., and Nordmann, A. Model-Based Reliability and Safety: Reducing the Complexity of Safety Analyses Using Component Fault Trees. 2018 Annual Reliability and Maintainability Symposium (RAMS), 2018, pp. 1-7.
Huq, N. Automotive Cyber Security - Emerging Risks and New Case Study Insights.
ATZ Electron Worldw 19, 14–19 (2024). DOI: 10.1007/s38314-024-18900.
ISO/SAE 21434: Road Vehicles – Cybersecurity Engineering, ISO/TC 22/SC 32, 2021.
ISO 26262. Road Vehicles— Functional Safety for Road Vehicles, ISO/TC 22/SC32, 2018.
ISO/IEC. ISO/IEC 18045:2008 – Information technology – Security techniques – Methodology for IT security evaluation, 2008.
Kaiser, B., Schneider, D., Adler, R., Domis, D., Mohrle, F., Berres, A., Zeller, M., Hofig, K., Rothfelder, M. Advances in Component Fault Trees. Safety and Reliability – Safe Societies in a Changing World – Haugen et al. (Eds), 2018, Taylor & Francis Group, London.
Kaiser, B., Liggesmeyer, P., Mackel, O. A New Component Concept for Fault Trees. In Proceedings of the 8th Australian Workshop on Safety Critical Systems and Software, Canberra, 2003.
Knight, J. C. Safety Critical Systems: Challenges and Directions. International Conference on Software Engineering (ICSE), Orlando, Florida, USA, 2002.
Kruck, B., Munk, P., Angermeier, D. 2021. Safe and secure: Mutually supporting safety and security analyses with model-based suggestions. In 2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW) (pp. 172-181). IEEE.
Moncada, D. S. V. Hazard-driven realization view for Component Fault Trees.
Software and Systems Modeling (2020) 19: 1465-1481p. DOI: 10.1007/s10270-020-00792-8
OMG. The Unified Modeling Language specification version 2.5.1. Object Management Group. 2017. Online: [link].
OMG. The System Modeling Language specification version 2.0. Object Management Group. 2025. Online: [link].
Schneier, B. Modeling security threats. Dr. Dobb’s J. 24 (12), 1999.
Upstream. Global Automotive Cybersecurity Report. Upstream Sec. Ltd., 2024. Online: [link].
Vesely, W. E., Goldberg, F. F., Roberts, N. H., and Haasl, D. F. Fault Tree Handbook.
US Nuclear Regulatory Commission, 1981.
Wired. Hackers remotely kill a Jeep on the highway with me in it, 2015. Online: [link].
Zeller, M., Sorokos, I., Reich, J., Adler, R., and Schneider, D. (2023). Open Dependability Exchange Metamodel: A Format to Exchange Safety Information. 2023 Annual Reliability and Maintainability Symposium (RAMS), Orlando, FL, USA, 2023, pp. 1-7. DOI: 10.1109/RAMS51473.2023.10088190.
Zeller, M., Hofig, K., Schwinn, J. P. ArChes – Automatic generation of component fault trees from continuous function charts. 2017 IEEE 15th International Conference on Industrial Informatics (INDIN) (2017): 577-582p.
Publicado
01/09/2026
Como Citar
GRECHI, Victor L.; OLIVEIRA, André L. de; GALLINA, Barbara; MONTECCHI, Leonardo; BRAGA, Rosana T. V..
Model-based Safety and Security Co-Analysis using Component Attack Fault Trees in the Automotive Domain. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 754-769.
DOI: https://doi.org/10.5753/sbseg.2026.27039.
