A Comparative Risk Analysis on CyberShip System with STPA-Sec, STRIDE and CORAS
Rishikesh Sahay, D.A.Sepulveda Estay, Weizhi Meng, Christian D., Jensen, and Michael Bruhn Barfod

TL;DR
This paper compares three cyber risk assessment methodologies—STPA-Sec, STRIDE, and CORAS—for identifying threats in CyberShip systems, highlighting their differences, strengths, and potential for combined use to improve security analysis.
Contribution
It provides a comparative analysis of three methodologies for cyber risk assessment in CyberShips, emphasizing their unique features and proposing their integrated application.
Findings
STPA-Sec identifies threats at component and interaction levels.
STRIDE covers component and interaction threats with specific threat categories.
CORAS offers a top-down framework aligned with STPA-Sec for cyber risk assessment.
Abstract
The widespread use of software-intensive cyber systems in critical infrastructures such as ships (CyberShips) has brought huge benefits, yet it has also opened new avenues for cyber attacks to potentially disrupt operations. Cyber risk assessment plays a vital role in identifying cyber threats and vulnerabilities that can be exploited to compromise cyber systems. A number of methodologies have been proposed to carry out these analyses. This paper evaluates and compares the application of three risk assessment methodologies: system theoretic process analysis (STPA-Sec), STRIDE and CORAS for identifying threats and vulnerabilities in a CyberShip system. We specifically selected these three methodologies because they identify threats not only at the component level, but also threats or hazards caused due to the interaction between components, resulting in sets of threats identified with…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Systems Engineering Methodologies and Applications · Software Reliability and Analysis Research
