Impact (I = S master)

ScoreSFOP
1NoneNegl.No impactNone
2MinorLowMinorLimited
3ModerateMediumModerateSensitive
4SevereHighMajorSerious
5CriticalVery HighCatastrophicCritical Breach

Risk (RV)

RVLevel
1-8Low
9-15Medium
16-25High

Risk Assessment

OptionDescription
acceptedRisk is accepted without additional treatment.
mitigatedControls are applied to reduce likelihood/impact.
transferedRisk ownership is shifted (e.g., contract/insurance).
avoidActivity/path is changed to eliminate the risk.

Likelihood (L = max(E, Ex, Eq, Op, K))

ScoreDescriptionL Value
1Very Low1
2Low2
3Moderate3
4High4
5Very High5

SFOP (Impact Categories)

Key Dimension Description (ISO/SAE 21434)
S Safety Potential severe consequences or physical harm to human life/health.
F Financial Monetary loss including repair costs, vehicle damage, or legal penalties.
O Operational Impact on vehicle performance, features, or the impairment of primary functions.
P Privacy Unauthorized access, extraction, or manipulation of private user and vehicle data.

Attack Feasibility Parameters

Key Parameter Description (Common Criteria)
E Elapsed Time The duration required to identify, design, and execute the attack path.
ex Expertise The specific technical knowledge and cybersecurity skills required by an attacker.
Eq Equipment The specialization and hardware/software tools needed to complete the exploit.
Op Opportunity The physical or logical proximity and access duration needed for the exploit.
K Knowledge The level of strict confidentiality of the system details required to execute.

ADAS PARKING ASSIST / SVS FULL TARA DASHBOARD

ADAS PARKING ASSIST / SVS FULL TARA DASHBOARD

AssetProperty Damage ScenarioThreat Scenario EExEqOpK L (max) SFOP I (max of S) RV (L*I)Risk Risk AssessmentSecurity Goal Cybersecurity Concept / Control
Camera modules & harnessIntegrityParking maneuver proceeds on a false free-space/obstacle assessment, risking a low-speed collision or a missed pedestrian/obstacle.[SYS-TS-01] Attacker projects a static/adversarial image pattern or replays a recorded frame into a camera's field of view to make the perception pipeline see a false free-space/obstacle state.3412MediumRTMD (sensor plausibility monitoring)
Camera modules & harnessIntegrityManipulated video injected upstream of plausibility checks corrupts the entire perception pipeline's view of the environment during a parking maneuver.[SYS-TS-02] Compromised or physically substituted camera module injects a manipulated video stream directly onto the FPD-Link/GMSL link, bypassing plausibility checks in the ISP.4520HighSecure Communication / SecOC + RTMD (sensor plausibility monitoring)
Ultrasonic sensorsIntegrityFalse-negative or false-positive obstacle readings cause a missed obstacle strike or an unnecessary emergency stop.[SYS-TS-03] Ultrasonic echo spoofing/jamming causes false-negative (missed obstacle) or false-positive (phantom obstacle) readings.3412MediumRTMD (sensor plausibility monitoring)
In-vehicle CAN busAvailabilityEmergency-stop signal is delayed on a starved bus, increasing the chance of a low-speed collision during an active parking maneuver.[SYS-TS-04] CAN bus flooding (high-priority ID abuse) starves the parking-command frame's bus access budget, delaying an emergency-stop signal.3412MediumRTMD (runtime/anomaly monitoring)
In-vehicle CAN busNon-repudiationAfter an incident, investigators cannot prove which ECU originated a disputed actuation command, blocking root-cause and liability determination.[SYS-TS-05] Absent per-frame authenticity binding makes it impossible to prove which ECU originated a given actuation command after an incident.313LowSecure Communication / SecOC + Secure Logging
CAN bus / Actuator command pathIntegrityA forged or replayed actuation command drives an unintended steering or braking action during an automated parking maneuver.[SYS-TS-06] Forged or replayed parking actuation command frame injected via a compromised gateway ECU or physical bus access, absent SecOC MAC/freshness enforcement.4520HighSecure Communication / SecOC
Automotive Ethernet / internal middleware busAuthenticationA fabricated actuation-command topic from a compromised co-located process is accepted as legitimate by the planner or actuator interface.[SYS-TS-07] Unauthenticated DDS/SOME-IP publish onto an internal actuation-command topic from a compromised co-located process.4416HighSecure Communication / SecOC
Sensor fusion pipelineIntegrityDesynchronized sensor fusion degrades obstacle-distance estimates, causing the planner to act on stale or misleading data.[SYS-TS-08] Timing manipulation of one fusion input (e.g., delayed ultrasonic frame) to desynchronize sensor fusion and degrade obstacle-distance estimates.339MediumRTMD (runtime/anomaly monitoring)
OTA update interfaceIntegrityA malicious or downgraded firmware/perception-model package is installed and activated after reboot, altering parking-assist decision logic.[SYS-TS-09] Malicious/downgraded SVS or Parking firmware or perception-model package delivered via OTA if signing/anti-rollback is not enforced for this subsystem's artifacts.4520HighOTA/FOTA/SOTA + Secure Reprogramming
UDS diagnosticsAuthorizationAttacker unlocks diagnostic routine-control services and directly invokes actuator test/calibration routines, bypassing the intended operating envelope.[SYS-TS-10] Weak UDS SecurityAccess seed/key scheme allows an attacker with bus access to unlock diagnostic routine-control services and directly invoke actuator test/calibration routines.3515MediumSecure Access (UDS SecurityAccess pattern)
UDS diagnosticsConfidentialityCalibration and perception-model parameters leak via diagnostics, exposing tuning/IP data and aiding further attacks.[SYS-TS-11] Diagnostic read-data-by-identifier services exposed without adequate access control leak calibration/perception-model parameters.326LowSecure Access (UDS SecurityAccess) + Secure Storage
Actuator interfaces (EPS/brake)AvailabilityThe planner's actuation command is dropped or delayed during an active maneuver, leaving the vehicle without commanded steering/braking action.[SYS-TS-12] Denial-of-service on the actuation command channel causes the planner's command to be dropped/delayed during an active maneuver.3412MediumRTMD (runtime/anomaly monitoring)
SVS/Parking ECU compute (TDA4VM)IntegrityDirect manipulation of ISP/perception/planner runtime state via an open debug port bypasses every higher-layer software control.[SYS-TS-13] JTAG/debug port left open in a non-HS-SE lifecycle state allows direct manipulation of ISP/perception/planner runtime state.3515MediumSecure JTAG & Debug Control + Secure Boot & Runtime Integrity
SVS/Parking ECU compute (TDA4VM)ConfidentialityStored perception-model weights or calibration secrets are extracted from ECU non-volatile storage, exposing IP and enabling model-specific adversarial attacks.[SYS-TS-14] Extraction of stored perception-model weights or calibration secrets from ECU non-volatile storage if not encrypted at rest.313LowSecure Storage
In-vehicle CAN busAccountabilityRejected/attempted CAN injection attempts leave no forensic trail, preventing detection or reconstruction of an attack campaign.[SYS-TS-15] Missing/incomplete security-event logging for rejected CAN frames prevents post-incident reconstruction of an attempted injection.313LowSecure Logging
Sensor fusion pipelineIntegrityA single spoofed sensor (camera or ultrasonic) is trusted without corroboration, propagating a false environment model to the planner.[SYS-TS-16] Cross-sensor plausibility check absent, so a single spoofed sensor input (camera or ultrasonic) is trusted without corroboration.3412MediumRTMD (runtime/anomaly monitoring)
OTA update interfaceAvailabilityAn interrupted OTA flash leaves the SVS/Parking software partition non-functional, removing the parking-assist safety net until recovery.[SYS-TS-17] OTA update process interrupted mid-flash for the SVS/Parking software partition leaves the subsystem non-functional (loss of parking-assist safety net) until recovery.3412MediumOTA/FOTA/SOTA + Secure Reprogramming
Automotive Ethernet switch / backboneAvailabilityBroadcast storm or switch misconfiguration saturates the backbone, delaying camera-stream delivery to the fusion pipeline during an active maneuver.[EXT-TS-01] Attacker connected to an exposed Ethernet debug/service port triggers a broadcast storm or VLAN hopping to flood the SVS backbone switch, starving time-sensitive camera streams.339MediumRTMD (runtime/anomaly monitoring) + Secure Communication / SecOC
Automotive Ethernet switch / backboneIntegritySpoofed SOME-IP/DDS service-discovery entries redirect a fusion-topic subscriber to an attacker-controlled publisher, corrupting the fused environment model.[EXT-TS-02] Attacker on the same Ethernet segment spoofs ARP/SOME-IP service-discovery entries to redirect a camera-stream or fusion-topic subscriber to an attacker-controlled publisher.4416HighSecure Communication / SecOC
Radar sensors (corner/short-range)IntegrityA false obstacle-distance report causes an unnecessary hard-braking event or a missed close-range obstacle during automated parking.[EXT-TS-03] RF jamming or spoofed radar-chirp reflection causes false-negative or false-positive obstacle-distance readings from a corner radar module.3412MediumRTMD (sensor plausibility monitoring)
Wheel speed sensors / odometryIntegrityCorrupted odometry input biases the sensor-fusion vehicle-motion estimate, causing the parking planner to misjudge remaining distance to an obstacle.[EXT-TS-04] Tampered or spoofed wheel-speed pulse train injected onto the sensor bus biases the odometry-based motion estimate used by the fusion pipeline.339MediumRTMD (sensor plausibility monitoring)
Steering angle sensorIntegrityFalse steering-angle feedback causes the automated-parking trajectory controller to command an incorrect steering correction, risking a curb strike or collision.[EXT-TS-05] Compromised steering-angle sensor node reports a falsified angle value, bypassing plausibility cross-check against the EPS actuator command.4416HighRTMD (sensor plausibility monitoring) + Secure Communication / SecOC
EPS (steering-assist) ECUAvailabilityLoss of steering-assist actuation mid-maneuver forces an aborted parking operation with the vehicle left in an unsafe position.[EXT-TS-06] Denial-of-service against the EPS actuator ECU (bus flood or malformed-frame crash) drops steering-assist commands during an active automated-parking maneuver.3412MediumRTMD (runtime/anomaly monitoring)
Electric parking brake / hydraulic brake ECUIntegrityA forged or replayed brake-hold-release command releases the electric parking brake unexpectedly on a slope during an automated parking sequence.[EXT-TS-07] Forged or replayed electric-parking-brake release command injected onto the brake ECU's CAN segment absent freshness/authenticity checks.4520HighSecure Communication / SecOC
HMI / infotainment top-view displayIntegrityA spoofed or frozen top-view guidance overlay shows a clear path when an obstacle is actually present, misleading the driver during a supervised parking maneuver.[EXT-TS-08] Compromised infotainment process feeds a stale or manipulated top-view rendering to the HMI display without the fusion pipeline's current obstacle state.3412MediumRTMD (runtime/anomaly monitoring) + Secure Logging
Remote Park Assist mobile app / BLE linkAuthenticationAn unauthorized party remotely triggers a parking maneuver from outside the vehicle, moving the vehicle without the owner's authorization.[EXT-TS-09] Weak BLE pairing or a relay attack on the Remote Park Assist mobile-app link allows an attacker to replay or relay a start-parking-maneuver command from outside authorized range.3412MediumSecure Access (UDS SecurityAccess pattern) + Secure Communication / SecOC
Key fob / RKE remote-parking activationReplay-resistanceA captured remote-parking activation signal is replayed later to move the vehicle without the driver present.[EXT-TS-10] RF replay of a captured key-fob remote-parking-activation code, enabled by a static or short rolling-code window.339MediumSecure Communication / SecOC
Camera calibration data store (intrinsic/extrinsic)IntegrityTampered camera calibration parameters silently distort the stitched surround-view image, causing the perception pipeline to misjudge object distance.[EXT-TS-11] Unauthorized modification of stored camera intrinsic/extrinsic calibration parameters in ECU non-volatile storage skews the surround-view stitching geometry.3412MediumSecure Storage + RTMD (sensor plausibility monitoring)
Perception ML model storage (NVM)IntegrityA tampered perception-model weights file installed outside the OTA-signed update path degrades obstacle-detection accuracy without detection.[EXT-TS-12] Direct (non-OTA) modification of the on-ECU perception-model weight file via a debug or file-system access path bypasses the OTA signature-verification gate.4416HighSecure Storage + Secure Boot & Runtime Integrity
Time synchronization service (gPTP/PTP)IntegrityA manipulated time-sync reference desynchronizes camera, radar, and ultrasonic timestamps, causing the fusion pipeline to misalign inputs and misjudge the obstacle position.[EXT-TS-13] Rogue or spoofed gPTP grandmaster on the Ethernet backbone shifts the shared time reference, desynchronizing sensor timestamps feeding the fusion pipeline.4312MediumRTMD (runtime/anomaly monitoring) + Secure Communication / SecOC
OBD-II / diagnostic physical connectorAuthorizationPhysical access to the exposed diagnostic connector allows an attacker to reach the UDS/CAN backbone without going through the intended gateway access-control path.[EXT-TS-14] Unrestricted physical access to the OBD-II connector allows direct CAN-bus injection or UDS session initiation, bypassing intended gateway-level network segmentation.4312MediumSecure Access (UDS SecurityAccess pattern) + Secure JTAG & Debug Control
Software/firmware update package repository (backend)IntegrityA tampered SVS/Parking firmware package published upstream of the OTA delivery path is signed and distributed to the entire fleet before detection.[EXT-TS-15] Compromise of the backend build/signing pipeline or artifact repository allows a malicious SVS/Parking firmware package to be published as a legitimate signed release.4416HighOTA/FOTA/SOTA + Secure Reprogramming
Cloud parking-assist backend / fleet telemetryConfidentialityExfiltrated fleet-wide parking-maneuver telemetry (routes, camera snapshots, timestamps) exposes driver location and behavior patterns.[EXT-TS-16] Weak backend access control on the fleet telemetry store allows bulk exfiltration of parking-event logs and associated camera snapshots.339MediumSecure Storage + Secure Access (UDS SecurityAccess pattern)