MITRE has teamed up with the cybersecurity community and the industrial sector to create EMB3D, a threat model specifically designed for embedded devices used in critical infrastructure.
Its goal is to provide a collaborative framework that enables organizations to have a common understanding of the threats targeting embedded devices and how those threats can be mitigated.
The new threat model - recommended for manufacturers, vendors, asset owners, testers and security researchers - expands on resources such as ATT&CK, CVE and CWE, with a focus on embedded devices.
It provides a knowledge base of threats, including ones seen in the wild and ones demonstrated through theoretic research and proofs of concept.
In order to help users create and tailor threat models to specific devices, threats are mapped to device properties.
The mitigations suggested by EMB3D are exclusively focused on technical mechanisms that can be implemented by device vendors.
The framework will be continuously updated by its maintainers and the cybersecurity community with new information on threat actors, vulnerabilities and defenses.
EMB3D is in a pre-release review period, with device vendors, asset owners, academics and researchers being encouraged to review the framework before its official launch, which is scheduled for early 2024.
This Cyber News was published on www.securityweek.com. Publication date: Wed, 13 Dec 2023 16:13:18 +0000