You are required to read and agree to the below before accessing a full-text version of an article in the IDE article repository.
The full-text document you are about to access is subject to national and international copyright laws. In most cases (but not necessarily all) the consequence is that personal use is allowed given that the copyright owner is duly acknowledged and respected. All other use (typically) require an explicit permission (often in writing) by the copyright owner.
For the reports in this repository we specifically note that
- the use of articles under IEEE copyright is governed by the IEEE copyright policy (available at http://www.ieee.org/web/publications/rights/copyrightpolicy.html)
- the use of articles under ACM copyright is governed by the ACM copyright policy (available at http://www.acm.org/pubs/copyright_policy/)
- technical reports and other articles issued by M‰lardalen University is free for personal use. For other use, the explicit consent of the authors is required
- in other cases, please contact the copyright owner for detailed information
By accepting I agree to acknowledge and respect the rights of the copyright owner of the document I am about to access.
If you are in doubt, feel free to contact webmaster@ide.mdh.se
Model-based Safety and Security Co-Analysis using Component Attack Fault Trees
Authors:
Victor Luiz Grechi
,
André Luiz de Oliveira
,
Barbara Gallina,
Leonardo Montecchi
,
Rosana Teresinha Vaccare Braga
Publication Type:
Conference/Workshop Paper
Venue:
XXVI Brazilian Symposium on Cybersecurity
Publisher:
SBC Sol database
DOI:
10.5753/sbseg.2026.27039
Abstract
Cyber-physical systems (CPSs) in critical domains such as self-driven cars and unmanned aerial vehicles involve complex interactions between safety and security concerns. Failures in CPSs such as self-driven cars are caused either by hardware/software component faults or attacks. The identification of hazards, their risks, and root causes is addressed by Safety Engineering, e.g., using Fault Tree Analysis. On the other hand, Security Engineering addresses the identification of asset vulnerabilities, their associated external threats, risks, and causes, using Attack Tree Analysis. Although both disciplines use separate terminology, processes, and tools, they rely on a common system architecture and in the use models such as Component Fault Trees and Attack Trees to support their analyses. In the automotive domain, such analyses should be performed in alignment with guidance defined in assurance standards, e.g., ISO 26262 for functional safety, and ISO 21434 for cybersecurity. However, existing techniques that integrate safety and security models are not fully aligned with the ISO 21434. In this paper, we introduce a novel Component Attack Fault Trees (CAFT) modelling language, built upon Component Fault Trees and ISO 21434 concepts, for integrating safety and security analysis models. Since CAFT was built in alignment with traditional safety and security analysis formalisms and standards, it has the potential to guide engineers in the development of multi-concern analysis model-driven engineering tools. We illustrate the use of our CAFT language to support safety and security co-analysis of an automotive headlamp system.
Bibtex
@inproceedings{Grechi7426,
author = {Victor Luiz Grechi and Andr{\'e} Luiz de Oliveira and Barbara Gallina and Leonardo Montecchi and Rosana Teresinha Vaccare Braga},
title = {Model-based Safety and Security Co-Analysis using Component Attack Fault Trees},
month = {September},
year = {2026},
booktitle = {XXVI Brazilian Symposium on Cybersecurity},
publisher = {SBC Sol database},
url = {http://www.es.mdu.se/publications/7426-}
}