Risk ownership is shifted (e.g., contract/insurance).
avoid
Activity/path is changed to eliminate the risk.
Likelihood (L = max(E, Ex, Eq, Op, K))
Score
Description
L Value
1
Very Low
1
2
Low
2
3
Moderate
3
4
High
4
5
Very High
5
SFOP (Impact Categories)
Key
Dimension
Description (ISO/SAE 21434)
S
Safety
Potential severe consequences or physical harm to human life/health.
F
Financial
Monetary loss including repair costs, vehicle damage, or legal penalties.
O
Operational
Impact on vehicle performance, features, or the impairment of primary functions.
P
Privacy
Unauthorized access, extraction, or manipulation of private user and vehicle data.
Attack Feasibility Parameters
Key
Parameter
Description (Common Criteria)
E
Elapsed Time
The duration required to identify, design, and execute the attack path.
ex
Expertise
The specific technical knowledge and cybersecurity skills required by an attacker.
Eq
Equipment
The specialization and hardware/software tools needed to complete the exploit.
Op
Opportunity
The physical or logical proximity and access duration needed for the exploit.
K
Knowledge
The level of strict confidentiality of the system details required to execute.
ADAS PARKING ASSIST / SVS FULL TARA DASHBOARD
ADAS PARKING ASSIST / SVS FULL TARA DASHBOARD
Asset
Property
Damage Scenario
Threat Scenario
E
Ex
Eq
Op
K
L (max)
S
F
O
P
I (max of S)
RV (L*I)
Risk
Risk Assessment
Security Goal
Cybersecurity Concept / Control
Camera modules & harness
Integrity
Parking maneuver proceeds on a false free-space/obstacle assessment, risking a low-speed collision or a missed pedestrian/obstacle.
[SYS-TS-01] Attacker projects a static/adversarial image pattern or replays a recorded frame into a camera's field of view to make the perception pipeline see a false free-space/obstacle state.
3
4
12
Medium
RTMD (sensor plausibility monitoring)
Camera modules & harness
Integrity
Manipulated video injected upstream of plausibility checks corrupts the entire perception pipeline's view of the environment during a parking maneuver.
[SYS-TS-02] Compromised or physically substituted camera module injects a manipulated video stream directly onto the FPD-Link/GMSL link, bypassing plausibility checks in the ISP.
4
5
20
High
Secure Communication / SecOC + RTMD (sensor plausibility monitoring)
Ultrasonic sensors
Integrity
False-negative or false-positive obstacle readings cause a missed obstacle strike or an unnecessary emergency stop.
Emergency-stop signal is delayed on a starved bus, increasing the chance of a low-speed collision during an active parking maneuver.
[SYS-TS-04] CAN bus flooding (high-priority ID abuse) starves the parking-command frame's bus access budget, delaying an emergency-stop signal.
3
4
12
Medium
RTMD (runtime/anomaly monitoring)
In-vehicle CAN bus
Non-repudiation
After an incident, investigators cannot prove which ECU originated a disputed actuation command, blocking root-cause and liability determination.
[SYS-TS-05] Absent per-frame authenticity binding makes it impossible to prove which ECU originated a given actuation command after an incident.
3
1
3
Low
Secure Communication / SecOC + Secure Logging
CAN bus / Actuator command path
Integrity
A forged or replayed actuation command drives an unintended steering or braking action during an automated parking maneuver.
[SYS-TS-06] Forged or replayed parking actuation command frame injected via a compromised gateway ECU or physical bus access, absent SecOC MAC/freshness enforcement.
4
5
20
High
Secure Communication / SecOC
Automotive Ethernet / internal middleware bus
Authentication
A fabricated actuation-command topic from a compromised co-located process is accepted as legitimate by the planner or actuator interface.
[SYS-TS-07] Unauthenticated DDS/SOME-IP publish onto an internal actuation-command topic from a compromised co-located process.
4
4
16
High
Secure Communication / SecOC
Sensor fusion pipeline
Integrity
Desynchronized sensor fusion degrades obstacle-distance estimates, causing the planner to act on stale or misleading data.
[SYS-TS-08] Timing manipulation of one fusion input (e.g., delayed ultrasonic frame) to desynchronize sensor fusion and degrade obstacle-distance estimates.
3
3
9
Medium
RTMD (runtime/anomaly monitoring)
OTA update interface
Integrity
A malicious or downgraded firmware/perception-model package is installed and activated after reboot, altering parking-assist decision logic.
[SYS-TS-09] Malicious/downgraded SVS or Parking firmware or perception-model package delivered via OTA if signing/anti-rollback is not enforced for this subsystem's artifacts.
4
5
20
High
OTA/FOTA/SOTA + Secure Reprogramming
UDS diagnostics
Authorization
Attacker unlocks diagnostic routine-control services and directly invokes actuator test/calibration routines, bypassing the intended operating envelope.
[SYS-TS-10] Weak UDS SecurityAccess seed/key scheme allows an attacker with bus access to unlock diagnostic routine-control services and directly invoke actuator test/calibration routines.
3
5
15
Medium
Secure Access (UDS SecurityAccess pattern)
UDS diagnostics
Confidentiality
Calibration and perception-model parameters leak via diagnostics, exposing tuning/IP data and aiding further attacks.
[SYS-TS-11] Diagnostic read-data-by-identifier services exposed without adequate access control leak calibration/perception-model parameters.
Stored perception-model weights or calibration secrets are extracted from ECU non-volatile storage, exposing IP and enabling model-specific adversarial attacks.
[SYS-TS-14] Extraction of stored perception-model weights or calibration secrets from ECU non-volatile storage if not encrypted at rest.
3
1
3
Low
Secure Storage
In-vehicle CAN bus
Accountability
Rejected/attempted CAN injection attempts leave no forensic trail, preventing detection or reconstruction of an attack campaign.
[SYS-TS-15] Missing/incomplete security-event logging for rejected CAN frames prevents post-incident reconstruction of an attempted injection.
3
1
3
Low
Secure Logging
Sensor fusion pipeline
Integrity
A single spoofed sensor (camera or ultrasonic) is trusted without corroboration, propagating a false environment model to the planner.
[SYS-TS-16] Cross-sensor plausibility check absent, so a single spoofed sensor input (camera or ultrasonic) is trusted without corroboration.
3
4
12
Medium
RTMD (runtime/anomaly monitoring)
OTA update interface
Availability
An interrupted OTA flash leaves the SVS/Parking software partition non-functional, removing the parking-assist safety net until recovery.
[SYS-TS-17] OTA update process interrupted mid-flash for the SVS/Parking software partition leaves the subsystem non-functional (loss of parking-assist safety net) until recovery.
3
4
12
Medium
OTA/FOTA/SOTA + Secure Reprogramming
Automotive Ethernet switch / backbone
Availability
Broadcast storm or switch misconfiguration saturates the backbone, delaying camera-stream delivery to the fusion pipeline during an active maneuver.
[EXT-TS-01] Attacker connected to an exposed Ethernet debug/service port triggers a broadcast storm or VLAN hopping to flood the SVS backbone switch, starving time-sensitive camera streams.
3
3
9
Medium
RTMD (runtime/anomaly monitoring) + Secure Communication / SecOC
Automotive Ethernet switch / backbone
Integrity
Spoofed SOME-IP/DDS service-discovery entries redirect a fusion-topic subscriber to an attacker-controlled publisher, corrupting the fused environment model.
[EXT-TS-02] Attacker on the same Ethernet segment spoofs ARP/SOME-IP service-discovery entries to redirect a camera-stream or fusion-topic subscriber to an attacker-controlled publisher.
4
4
16
High
Secure Communication / SecOC
Radar sensors (corner/short-range)
Integrity
A false obstacle-distance report causes an unnecessary hard-braking event or a missed close-range obstacle during automated parking.
[EXT-TS-03] RF jamming or spoofed radar-chirp reflection causes false-negative or false-positive obstacle-distance readings from a corner radar module.
3
4
12
Medium
RTMD (sensor plausibility monitoring)
Wheel speed sensors / odometry
Integrity
Corrupted odometry input biases the sensor-fusion vehicle-motion estimate, causing the parking planner to misjudge remaining distance to an obstacle.
[EXT-TS-04] Tampered or spoofed wheel-speed pulse train injected onto the sensor bus biases the odometry-based motion estimate used by the fusion pipeline.
3
3
9
Medium
RTMD (sensor plausibility monitoring)
Steering angle sensor
Integrity
False steering-angle feedback causes the automated-parking trajectory controller to command an incorrect steering correction, risking a curb strike or collision.
[EXT-TS-05] Compromised steering-angle sensor node reports a falsified angle value, bypassing plausibility cross-check against the EPS actuator command.
4
4
16
High
RTMD (sensor plausibility monitoring) + Secure Communication / SecOC
EPS (steering-assist) ECU
Availability
Loss of steering-assist actuation mid-maneuver forces an aborted parking operation with the vehicle left in an unsafe position.
[EXT-TS-06] Denial-of-service against the EPS actuator ECU (bus flood or malformed-frame crash) drops steering-assist commands during an active automated-parking maneuver.
3
4
12
Medium
RTMD (runtime/anomaly monitoring)
Electric parking brake / hydraulic brake ECU
Integrity
A forged or replayed brake-hold-release command releases the electric parking brake unexpectedly on a slope during an automated parking sequence.
[EXT-TS-07] Forged or replayed electric-parking-brake release command injected onto the brake ECU's CAN segment absent freshness/authenticity checks.
4
5
20
High
Secure Communication / SecOC
HMI / infotainment top-view display
Integrity
A spoofed or frozen top-view guidance overlay shows a clear path when an obstacle is actually present, misleading the driver during a supervised parking maneuver.
[EXT-TS-08] Compromised infotainment process feeds a stale or manipulated top-view rendering to the HMI display without the fusion pipeline's current obstacle state.
An unauthorized party remotely triggers a parking maneuver from outside the vehicle, moving the vehicle without the owner's authorization.
[EXT-TS-09] Weak BLE pairing or a relay attack on the Remote Park Assist mobile-app link allows an attacker to replay or relay a start-parking-maneuver command from outside authorized range.
3
4
12
Medium
Secure Access (UDS SecurityAccess pattern) + Secure Communication / SecOC
Key fob / RKE remote-parking activation
Replay-resistance
A captured remote-parking activation signal is replayed later to move the vehicle without the driver present.
[EXT-TS-10] RF replay of a captured key-fob remote-parking-activation code, enabled by a static or short rolling-code window.
3
3
9
Medium
Secure Communication / SecOC
Camera calibration data store (intrinsic/extrinsic)
Integrity
Tampered camera calibration parameters silently distort the stitched surround-view image, causing the perception pipeline to misjudge object distance.
[EXT-TS-11] Unauthorized modification of stored camera intrinsic/extrinsic calibration parameters in ECU non-volatile storage skews the surround-view stitching geometry.
A tampered perception-model weights file installed outside the OTA-signed update path degrades obstacle-detection accuracy without detection.
[EXT-TS-12] Direct (non-OTA) modification of the on-ECU perception-model weight file via a debug or file-system access path bypasses the OTA signature-verification gate.
4
4
16
High
Secure Storage + Secure Boot & Runtime Integrity
Time synchronization service (gPTP/PTP)
Integrity
A manipulated time-sync reference desynchronizes camera, radar, and ultrasonic timestamps, causing the fusion pipeline to misalign inputs and misjudge the obstacle position.
[EXT-TS-13] Rogue or spoofed gPTP grandmaster on the Ethernet backbone shifts the shared time reference, desynchronizing sensor timestamps feeding the fusion pipeline.
4
3
12
Medium
RTMD (runtime/anomaly monitoring) + Secure Communication / SecOC
OBD-II / diagnostic physical connector
Authorization
Physical access to the exposed diagnostic connector allows an attacker to reach the UDS/CAN backbone without going through the intended gateway access-control path.
[EXT-TS-14] Unrestricted physical access to the OBD-II connector allows direct CAN-bus injection or UDS session initiation, bypassing intended gateway-level network segmentation.
A tampered SVS/Parking firmware package published upstream of the OTA delivery path is signed and distributed to the entire fleet before detection.
[EXT-TS-15] Compromise of the backend build/signing pipeline or artifact repository allows a malicious SVS/Parking firmware package to be published as a legitimate signed release.
4
4
16
High
OTA/FOTA/SOTA + Secure Reprogramming
Cloud parking-assist backend / fleet telemetry
Confidentiality
Exfiltrated fleet-wide parking-maneuver telemetry (routes, camera snapshots, timestamps) exposes driver location and behavior patterns.
[EXT-TS-16] Weak backend access control on the fleet telemetry store allows bulk exfiltration of parking-event logs and associated camera snapshots.