为提高嵌入式系统可靠性,开发安全可信的系统,需要在软件开发设计阶段尽早考虑安全问题。提出一种面向嵌入式系统的威胁建模方法,该方法分析了嵌入式系统可能存在的威胁漏洞,以威胁树的形式建立了嵌入式系统威胁模型;根据该模型,以量化的方式从下到上迭代地计算各个节点的威胁值,然后根据各个节点的威胁值对嵌入式系统进行风险评估。为更好地说明威胁模型及其各节点威胁值的计算方法,以智能电表中用户电表账单信息受到的威胁为例,说明了整个建模和量化过程。通过具体实例验证了该方法的实用性和有效性。
In order to improve the safe and reliable embedded system, software development design phase needs to consider security as soon as possible. Therefore, this paper presented a threat model for embedded system that analyzed the possible threats in embedded system. For evaluating the scale of thread, the method established the threat model in the form of trees and calculated the thread value of tree' s nodes from bottom to top. It used the thread of meter billing information in smart meters as an example to illustrate the process of building the threat model and calculating the thread value of each node that verifying the practicability and effectiveness of this method.