{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T17:48:19Z","timestamp":1783014499851,"version":"3.54.6"},"reference-count":146,"publisher":"Association for Computing Machinery (ACM)","issue":"5","funder":[{"DOI":"10.13039\/501100000780","name":"European Union","doi-asserted-by":"crossref","award":["101070008"],"award-info":[{"award-number":["101070008"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Belfort ERC","award":["101020005 695305"],"award-info":[{"award-number":["101020005 695305"]}]},{"name":"CyberSecurity Research Flanders","award":["VR20192203"],"award-info":[{"award-number":["VR20192203"]}]},{"DOI":"10.13039\/501100001665","name":"French National Research Agency","doi-asserted-by":"crossref","award":["NF-HiSec ANR-22-PEFT-0009"],"award-info":[{"award-number":["NF-HiSec ANR-22-PEFT-0009"]}],"id":[{"id":"10.13039\/501100001665","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Apricot\/ENCOPIA ANR MESRI-BMBF project","award":["ANR-20-CYAL-0001"],"award-info":[{"award-number":["ANR-20-CYAL-0001"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,9,30]]},"abstract":"<jats:p>Threat modeling (TM) is essential to manage, prevent, and fix security and privacy issues in our society. TM requires a data model to represent threats and tools to exploit such data. Current TM data models and tools have significant limitations preventing their usage in real-world scenarios. For example, it is challenging to TM embedded devices with current data models and tools as they cannot model their hardware, firmware, and low-level software. Moreover, it is impossible to TM a device lifecycle or security-privacy tradeoffs as these data models and tools were developed for other use cases (e.g., software security or user privacy).<\/jats:p>\n          <jats:p>\n            We fill this relevant gap by presenting the AttackDefense Framework (ADF), which provides a novel data model and related tools to augment TM. ADF\u2019s building block is the AD object that can be used to represent heterogeneous and complex threats. Moreover, ADF provides automations to process a collection of AD objects, including ways to create sets, maps, chains, trees, and wordclouds of AD objects. We present\n            <jats:monospace>ADF<\/jats:monospace>\n            , a toolkit implementing ADF composed of four modules (Catalog, Parse, Check, and Analyze).\n          <\/jats:p>\n          <jats:p>We confirm that the data model and tools provided by ADF are useful by running an extensive set of experiments while threat modeling a crypto wallet and its lifecycle. Our experiments involved seven expert groups from academia and industry, each using the ADF on an orthogonal threat class. The evaluation generated 175 high-quality ADs covering ISA\/IEC 62433-4-1 SecDev Lifecycle, side-channels, fault injection, microarchitectural attacks, speculative execution, pre-silicon testing, invasive physical chip modifications, Bluetooth protocol and implementation threats, and FIDO2 authentication.<\/jats:p>","DOI":"10.1145\/3698396","type":"journal-article","created":{"date-parts":[[2024,10,8]],"date-time":"2024-10-08T11:42:31Z","timestamp":1728387751000},"page":"1-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["AttackDefense Framework (ADF): Enhancing IoT Devices and Lifecycles Threat Modeling"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-6146-6465","authenticated-orcid":false,"given":"Tommaso","family":"Sacchetti","sequence":"first","affiliation":[{"name":"Digital Security, EURECOM","place":["Sophia Antipolis, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8641-7549","authenticated-orcid":false,"given":"Marton","family":"Bognar","sequence":"additional","affiliation":[{"name":"KU Leuven","place":["Leuven, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2295-9979","authenticated-orcid":false,"given":"Jesse","family":"De Meulemeester","sequence":"additional","affiliation":[{"name":"KU Leuven","place":["Leuven, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5866-1990","authenticated-orcid":false,"given":"Benedikt","family":"Gierlichs","sequence":"additional","affiliation":[{"name":"KU Leuven","place":["Leuven, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5438-153X","authenticated-orcid":false,"given":"Frank","family":"Piessens","sequence":"additional","affiliation":[{"name":"KU Leuven","place":["Leuven, Belgium"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0508-1709","authenticated-orcid":false,"given":"Volodymyr","family":"Bezsmertnyi","sequence":"additional","affiliation":[{"name":"NXP","place":["Hamburg, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2901-2972","authenticated-orcid":false,"given":"Maria Chiara","family":"Molteni","sequence":"additional","affiliation":[{"name":"Security Pattern","place":["Mazzano, Italy"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0124-4467","authenticated-orcid":false,"given":"Stefano","family":"Cristalli","sequence":"additional","affiliation":[{"name":"Security Pattern","place":["Mazzano, Italy"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9722-9949","authenticated-orcid":false,"given":"Arianna","family":"Gringiani","sequence":"additional","affiliation":[{"name":"Security Pattern","place":["Mazzano, Italy"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-6914-7428","authenticated-orcid":false,"given":"Olivier","family":"Thomas","sequence":"additional","affiliation":[{"name":"Texplained","place":["Valbonne, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9342-3920","authenticated-orcid":false,"given":"Daniele","family":"Antonioli","sequence":"additional","affiliation":[{"name":"Digital Security, EURECOM","place":["Sophia Antipolis, France"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,9,12]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3140241.3140252"},{"key":"e_1_3_2_3_2","unstructured":"FIDO Alliance. 2024. FIDO: Simpler Stronger Authentication. Retrieved from https:\/\/fidoalliance.org\/"},{"key":"e_1_3_2_4_2","unstructured":"FIDO Alliance. 2024. FIDO2. Retrieved from https:\/\/fidoalliance.org\/fido2\/"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3140368.3140372"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394497"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3523258"},{"key":"e_1_3_2_8_2","first-page":"1047","volume-title":"Proceedings of the 28th USENIX Security Symposium","author":"Antonioli Daniele","year":"2019","unstructured":"Daniele Antonioli, Nils Ole Tippenhauer, and Kasper B. Rasmussen. 2019. The KNOB is broken: Exploiting low entropy in the encryption key negotiation of bluetooth BR\/EDR. In Proceedings of the 28th USENIX Security Symposium. 1047\u20131061."},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66402-6_7"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564550"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-30806-7_4"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-38471-5_11"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833735"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-69053-0_4"},{"key":"e_1_3_2_15_2","first-page":"249","volume-title":"Proceedings of the 28th USENIX Security Symposium, USENIX Security 2019, August 14\u201316, 2019","author":"Canella Claudio","year":"2019","unstructured":"Claudio Canella, Jo Van Bulck, Michael Schwarz, Moritz Lipp, Benjamin von Berg, Philipp Ortner, Frank Piessens, Dmitry Evtyushkin, and Daniel Gruss. 2019. A systematic evaluation of transient execution attacks and defenses. In Proceedings of the 28th USENIX Security Symposium, USENIX Security 2019, August 14\u201316, 2019, Nadia Heninger and Patrick Traynor (Eds.). USENIX Association, 249\u2013266."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.14722\/madweb.2022.23001"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00050"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338507.3358617"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48405-1_26"},{"key":"e_1_3_2_20_2","article-title":"Threat models over space and time: A case study of E2EE messaging applications","author":"Chowdhury Partha Das","year":"2023","unstructured":"Partha Das Chowdhury, Maria Sameen, Jenny Blessing, Nicholas Boucher, Joseph Gardiner, Tom Burrows, Ross Anderson, and Awais Rashid. 2023. Threat models over space and time: A case study of E2EE messaging applications. arXiv preprint arXiv:2301.05653 (2023).","journal-title":"arXiv preprint arXiv:2301.05653"},{"key":"e_1_3_2_21_2","unstructured":"CISA. 2024. Decider Web Application. Retrieved from https:\/\/github.com\/cisagov\/Decider\/"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00054"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48059-5_25"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-010-0115-7"},{"key":"e_1_3_2_25_2","unstructured":"Graphviz developers. 2024. Graphviz is an Open Source Graph Visualization Software. Retrieved from https:\/\/graphviz.org\/"},{"key":"e_1_3_2_26_2","unstructured":"Graphviz developers. 2024. Package Facilitating the Creation and Rendering of Graph Descriptions in the DOT Language of Graphviz. Retrieved from https:\/\/pypi.org\/project\/graphviz\/"},{"key":"e_1_3_2_27_2","unstructured":"LibYAML developers. 2024. LibYAML - A C Library for Parsing and Emitting YAML. Retrieved from https:\/\/github.com\/yaml\/libyaml"},{"key":"e_1_3_2_28_2","unstructured":"Linux Kernel Developers. 2024. The Kernel Address Sanitizer (KASAN). Retrieved from https:\/\/www.kernel.org\/doc\/html\/latest\/dev-tools\/kasan.html"},{"key":"e_1_3_2_29_2","unstructured":"Linux Kernel Developers. 2024. The Kernel Memory Sanitizer (KMSAN). Retrieved from https:\/\/www.kernel.org\/doc\/html\/latest\/dev-tools\/kmsan.html"},{"key":"e_1_3_2_30_2","unstructured":"Pandas developers. 2024. Pandas is a Fast Powerful Flexible and Easy to Use Open Source Data Analysis and Manipulation Tool Built on Top of the Python Programming Language. Retrieved from https:\/\/pandas.pydata.org\/"},{"key":"e_1_3_2_31_2","unstructured":"PyYAML developers. 2024. PyYAML is a Full-featured YAML Framework for the Python Programming Language. Retrieved from https:\/\/pyyaml.org\/"},{"key":"e_1_3_2_32_2","unstructured":"Rust developers. 2024. Rust: A Language Empowering Everyone to Build Reliable and Efficient Software. Retrieved from https:\/\/www.rust-lang.org\/"},{"key":"e_1_3_2_33_2","unstructured":"SoloKeys developers. 2024. SoloKeys Blog. Retrieved from https:\/\/solokeys.com\/blogs\/news"},{"key":"e_1_3_2_34_2","unstructured":"SoloKeys developers. 2024. SoloKeys Homepage. Retrieved from https:\/\/solokeys.com\/"},{"key":"e_1_3_2_35_2","unstructured":"TheHive developers. 2024. TheHive is a FOSS Security Incident Response Platform. Retrieved from https:\/\/github.com\/TheHive-Project\/TheHive"},{"key":"e_1_3_2_36_2","unstructured":"Threatspec developers. 2024. Threatspec - Continuous Threat Modeling through Code. Retrieved from https:\/\/github.com\/threatspec\/threatspec"},{"key":"e_1_3_2_37_2","unstructured":"Wordcloud developers. 2024. A Little Word Cloud Generator in Python. Retrieved from https:\/\/pypi.org\/project\/wordcloud\/"},{"key":"e_1_3_2_38_2","unstructured":"Matplotlib development team. 2024. Matplotlib: Visualization with Python. Retrieved from https:\/\/matplotlib.org\/"},{"key":"e_1_3_2_39_2","unstructured":"Guardian Digital. 2024. Linux Security Advisories. Retrieved from https:\/\/linuxsecurity.com\/advisories"},{"key":"e_1_3_2_40_2","first-page":"869","volume-title":"28th USENIX Security Symposium (USENIX Security\u201919)","author":"Dong Ying","year":"2019","unstructured":"Ying Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing, Yuqing Zhang, and Gang Wang. 2019. Towards the detection of inconsistencies in public security vulnerability reports. In 28th USENIX Security Symposium (USENIX Security\u201919). USENIX Association, Santa Clara, CA, 869\u2013885. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/dong"},{"key":"e_1_3_2_41_2","article-title":"Towards measuring supply chain attacks on package managers for interpreted languages","author":"Duan Ruian","year":"2020","unstructured":"Ruian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder, Brendan Saltaformaggio, and Wenke Lee. 2020. Towards measuring supply chain attacks on package managers for interpreted languages. arXiv preprint arXiv:2002.01139 (2020).","journal-title":"arXiv preprint arXiv:2002.01139"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2022.3142338"},{"key":"e_1_3_2_43_2","unstructured":"engn33r. 2024. Awesome Bluetooth Security (BR EDR LE and Mesh). Retrieved from https:\/\/github.com\/engn33r\/awesome-bluetooth-security"},{"key":"e_1_3_2_44_2","unstructured":"The Center for Threat-Informed Defense. 2024. Threat Report ATT&CK Mapping (TRAM). Retrieved from https:\/\/github.com\/center-for-threat-informed-defense\/tram"},{"key":"e_1_3_2_45_2","unstructured":"Christian Frichot. 2024. hcltm: Threat Modeling with HCL. Retrieved from https:\/\/github.com\/xntrik\/hcltm"},{"key":"e_1_3_2_46_2","first-page":"5","volume-title":"Proceedings of the 14th International VDI Congress Electronic Systems for Vehicles, Baden-Baden","volume":"62","author":"F\u00fcrst Simon","year":"2009","unstructured":"Simon F\u00fcrst, J\u00fcrgen M\u00f6ssinger, Stefan Bunzel, Thomas Weber, Frank Kirschke-Biller, Peter Heitk\u00e4mper, Gerulf Kinkelin, Kenji Nishikawa, and Klaus Lange. 2009. AUTOSAR\u2013A worldwide standard is on the road. In Proceedings of the 14th International VDI Congress Electronic Systems for Vehicles, Baden-Baden, Vol. 62. Citeseer, 5."},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-44709-1_21"},{"key":"e_1_3_2_48_2","first-page":"911","volume-title":"Proceedings of the 2020 USENIX Conference on Usenix Annual Technical Conference","author":"Garbelini Matheus E.","year":"2020","unstructured":"Matheus E. Garbelini, Chundong Wang, Sudipta Chattopadhyay, Sumei Sun, and Ernest Kurniawan. 2020. Sweyntooth: Unleashing mayhem over bluetooth low energy. In Proceedings of the 2020 USENIX Conference on Usenix Annual Technical Conference. 911\u2013925."},{"key":"e_1_3_2_49_2","unstructured":"Google. 2024. Android Security Bulletins. Retrieved from https:\/\/source.android.com\/docs\/security\/bulletin"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48059-5_15"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2015.13"},{"key":"e_1_3_2_53_2","article-title":"Beyond continuous monitoring: Threat modeling for real-time response","author":"Hardy MG","year":"2012","unstructured":"MG Hardy. 2012. Beyond continuous monitoring: Threat modeling for real-time response. SANS Institute (2012).","journal-title":"SANS Institute"},{"key":"e_1_3_2_54_2","unstructured":"Geoffrey Hill. 2024. Rapid Threat Model Prototyping (RTMP). Retrieved from https:\/\/github.com\/geoffrey-hill-tutamantic\/rapid-threat-model-prototyping-docs"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/CANET.2007.4401672"},{"key":"e_1_3_2_56_2","unstructured":"Securin Inc.2021. Pegasus Spyware Snoops on Political Figures\u00a0Worldwide. Retrieved from https:\/\/www.securin.io\/articles\/pegasus-spyware-snoops-on-political-figures-worldwide\/"},{"key":"e_1_3_2_57_2","unstructured":"OASIS Cyber Threat Intelligence. 2024. Sharing Threat Intelligence Just Got a Lot Easier! Retrieved from https:\/\/oasis-open.github.io\/cti-documentation\/"},{"key":"e_1_3_2_58_2","unstructured":"IriusRisk. 2024. IriusRisk is the Industry Leader in Automated Threat Modeling and Secure Software Design. Retrieved from https:\/\/www.iriusrisk.com\/"},{"key":"e_1_3_2_59_2","unstructured":"IriusRisk. 2024. The Open Threat Modeling Format (OTM) Defines a Platform Independent Way to Define the Threat Model of Any System. Retrieved from https:\/\/github.com\/iriusrisk\/OpenThreatModel"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3465481.3470093"},{"key":"e_1_3_2_61_2","unstructured":"Peter E. Kaloroumakis and Michael J. Smith. 2021. Toward a knowledge graph of cybersecurity countermeasures. https:\/\/d3fend.mitre.org\/resources\/D3FEND.pdf"},{"key":"e_1_3_2_62_2","first-page":"1","volume-title":"Proceedings of the 15th ESCAR Conference","author":"Karahasanovic Adi","year":"2017","unstructured":"Adi Karahasanovic, Pierre Kleberger, and Magnus Almgren. 2017. Adapting threat modeling methods for the automotive industry. In Proceedings of the 15th ESCAR Conference. 1\u201310."},{"key":"e_1_3_2_63_2","unstructured":"Vladimir Keleshev. 2024. Schema Validation Just Got Pythonic. Retrieved from https:\/\/github.com\/keleshev\/schema"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISGTEurope.2017.8260283"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48405-1_25"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19751-2_6"},{"key":"e_1_3_2_68_2","unstructured":"Vaibhav Garg Kristen Tan. 2022. An Analysis of Open-source Automated Threat Modeling Tools and Their Extensibility from Security into Privacy. Retrieved from https:\/\/www.usenix.org\/publications\/loginonline\/analysis-open-source-automated-threat-modeling-tools-and-their"},{"key":"e_1_3_2_69_2","article-title":"Taxonomy of attacks on open-source software supply chains","author":"Ladisa Piergiorgio","year":"2022","unstructured":"Piergiorgio Ladisa, Henrik Plate, Matias Martinez, and Olivier Barais. 2022. Taxonomy of attacks on open-source software supply chains. arXiv preprint arXiv:2204.04008 (2022).","journal-title":"arXiv preprint arXiv:2204.04008"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11599-3_12"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/RCIS.2016.7549303"},{"key":"e_1_3_2_72_2","unstructured":"Lockheed Martin. 2022. The Cyber Kill Chain. Retrieved from https:\/\/www.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html"},{"key":"e_1_3_2_73_2","unstructured":"Microsoft. 2024. Microsoft Security Development Lifecycle (SDL). Retrieved from https:\/\/www.microsoft.com\/en-us\/securityengineering\/sdl\/"},{"key":"e_1_3_2_74_2","unstructured":"Microsoft. 2024. Microsoft Threat Modeling Tool Threats. Retrieved from https:\/\/learn.microsoft.com\/en-us\/azure\/security\/develop\/threat-modeling-tool-threats"},{"key":"e_1_3_2_75_2","unstructured":"Microsoft. 2024. Microsoft Threat Modeling Tool (TMT). Retrieved from https:\/\/learn.microsoft.com\/en-us\/azure\/security\/develop\/threat-modeling-tool"},{"key":"e_1_3_2_76_2","unstructured":"Mitre. 2021. CWE Most Important Hardware Weaknesses 2021. Retrieved from https:\/\/cwe.mitre.org\/scoring\/lists\/2021_CWE_MIHW.html"},{"key":"e_1_3_2_77_2","unstructured":"Mitre. 2022. CWE Top 25 Most Dangerous Software Weaknesses 2022. Retrieved from https:\/\/cwe.mitre.org\/top25\/archive\/2022\/2022_cwe_top25.html"},{"key":"e_1_3_2_78_2","unstructured":"Mitre. 2023. CWE Top 25 Most Dangerous Software Weaknesses 2023. Retrieved from https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html"},{"key":"e_1_3_2_79_2","unstructured":"Mitre. 2024. ATT&CK Framework. Retrieved from https:\/\/attack.mitre.org\/"},{"key":"e_1_3_2_80_2","unstructured":"Mitre. 2024. ATT&CK Framework GitHub Project. Retrieved from https:\/\/github.com\/mitre-attack"},{"key":"e_1_3_2_81_2","unstructured":"Mitre. 2024. CAPEC-668: Key Negotiation of Bluetooth Attack (KNOB). Retrieved from https:\/\/capec.mitre.org\/data\/definitions\/668.html"},{"key":"e_1_3_2_82_2","unstructured":"Mitre. 2024. Common Attack Pattern Enumerations and Classifications. Retrieved from https:\/\/capec.mitre.org\/"},{"key":"e_1_3_2_83_2","unstructured":"Mitre. 2024. Common Vulnerabilities and Exposures. Retrieved from https:\/\/www.cve.org\/"},{"key":"e_1_3_2_84_2","unstructured":"Mitre. 2024. Common Weakness Enumeration. Retrieved from https:\/\/cwe.mitre.org\/"},{"key":"e_1_3_2_85_2","unstructured":"Mitre. 2024. D3FEND Framework. Retrieved from https:\/\/d3fend.mitre.org\/"},{"key":"e_1_3_2_86_2","unstructured":"Mitre. 2024. D3FEND Framework GitHub Project. Retrieved from https:\/\/github.com\/d3fend"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2013.9"},{"key":"e_1_3_2_88_2","article-title":"A threat-driven approach to cyber security","author":"Muckin Michael","year":"2014","unstructured":"Michael Muckin and Scott C Fitch. 2014. A threat-driven approach to cyber security. Lockheed Martin Corporation (2014), 4--26.","journal-title":"Lockheed Martin Corporation"},{"key":"e_1_3_2_89_2","unstructured":"musl developers. 2024. Musl Libc for Linux Git Repository. Retrieved from https:\/\/git.musl-libc.org\/cgit\/musl"},{"key":"e_1_3_2_90_2","unstructured":"musl developers. 2024. Musl Libc for Linux Homepage. Retrieved from https:\/\/musl.libc.org\/"},{"key":"e_1_3_2_91_2","unstructured":"nccgroup. 2016. The Automotive Threat Modeling Template. Retrieved from https:\/\/github.com\/nccgroup\/The_Automotive_Threat_Modeling_Template"},{"key":"e_1_3_2_92_2","unstructured":"Rusty Newton. 2023. Threat Modeling Example with ChatGPT. Retrieved from https:\/\/blog.infosec.business\/how-to-use-chatgpt-to-learn-threat-modeling\/"},{"key":"e_1_3_2_93_2","unstructured":"NIST. 2017. An Introduction to Privacy Engineering and Risk Management in Federal Systems. Retrieved from https:\/\/csrc.nist.gov\/publications\/detail\/nistir\/8062\/final"},{"key":"e_1_3_2_94_2","unstructured":"NIST. 2024. Common Vulnerability Scoring System (CVSS). Retrieved from https:\/\/nvd.nist.gov\/vuln-metrics\/cvss"},{"key":"e_1_3_2_95_2","unstructured":"NIST. 2024. CVSS v2 Calculator. Retrieved from https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v2-calculator"},{"key":"e_1_3_2_96_2","unstructured":"NIST. 2024. CVSS v3 Calculator. Retrieved from https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v3-calculator"},{"key":"e_1_3_2_97_2","unstructured":"NIST. 2024. CVSS v4. Retrieved from https:\/\/www.first.org\/cvss\/v4-0"},{"key":"e_1_3_2_98_2","unstructured":"openhwgroup. 2024. OpenHW Group CORE-V CV32E40S RISC-V IP. Retrieved from https:\/\/github.com\/openhwgroup\/cv32e40s"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1007\/11605805_1"},{"key":"e_1_3_2_100_2","unstructured":"OWASP. 2021. OWASP Top Ten. Retrieved from https:\/\/owasp.org\/www-project-top-ten\/"},{"key":"e_1_3_2_101_2","unstructured":"OWASP. 2024. OWASP Threat Modeling Project. Retrieved from https:\/\/owasp.org\/www-project-threat-model"},{"key":"e_1_3_2_102_2","unstructured":"OWASP and Mike Goodwin. 2024. Threat Dragon is a Free Open-source Cross-platform Threat Modeling Application. Retrieved from https:\/\/github.com\/OWASP\/threat-dragon"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00088"},{"key":"e_1_3_2_104_2","first-page":"565","volume-title":"Proceedings of the 25th USENIX Security Symposium, USENIX Security 16, August 10\u201312, 2016","author":"Pessl Peter","year":"2016","unstructured":"Peter Pessl, Daniel Gruss, Cl\u00e9mentine Maurice, Michael Schwarz, and Stefan Mangard. 2016. DRAMA: Exploiting DRAM addressing for cross-CPU attacks. In Proceedings of the 25th USENIX Security Symposium, USENIX Security 16, August 10\u201312, 2016, Thorsten Holz and Stefan Savage (Eds.). USENIX Association, 565\u2013581."},{"key":"e_1_3_2_105_2","unstructured":"OpenCTI Platform. 2024. OpenCTI Allows Orgs to Manage Cyber Threat Intelligence Knowledge and Observables. Retrieved from https:\/\/github.com\/OpenCTI-Platform\/opencti"},{"key":"e_1_3_2_106_2","unstructured":"MISP Project. 2024. MISP - Threat Intelligence Sharing Platform. Retrieved from https:\/\/github.com\/MISP\/MISP"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45418-7_17"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103047"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA52012.2021.00036"},{"key":"e_1_3_2_110_2","first-page":"19","volume-title":"Proceedings of the 29th USENIX Conference on Security Symposium","author":"Ruge Jan","year":"2020","unstructured":"Jan Ruge, Jiska Classen, Francesco Gringoli, and Matthias Hollick. 2020. Frankenstein: Advanced wireless fuzzing to exploit new Bluetooth escalation targets. In Proceedings of the 29th USENIX Conference on Security Symposium. 19\u201336."},{"key":"e_1_3_2_111_2","article-title":"Crackle: Crack and Decrypt BLE Encryption","author":"Ryan Mike","year":"2019","unstructured":"Mike Ryan. 2019. Crackle: Crack and Decrypt BLE Encryption. Retrieved from https:\/\/github.com\/mikeryan\/crackle, Accessed: 2019-07-30.","journal-title":"Retrieved from https:\/\/github.com\/mikeryan\/crackle, Accessed: 2019-07-30"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1145\/310889.310900"},{"key":"e_1_3_2_113_2","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2008.10"},{"key":"e_1_3_2_114_2","unstructured":"Christian Schneider. 2024. Threagile is an Open-source Toolkit for Agile Threat Modeling:. Retrieved from https:\/\/github.com\/Threagile\/threagile"},{"issue":"12","key":"e_1_3_2_115_2","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier Bruce","year":"1999","unstructured":"Bruce Schneier. 1999. Attack trees. Dr. Dobb\u2019s Journal 24, 12 (1999), 21\u201329.","journal-title":"Dr. Dobb\u2019s Journal"},{"key":"e_1_3_2_116_2","unstructured":"Bruce Schneier. 2021. Chinese Supply-Chain Attack on Computer Systems. Retrieved from https:\/\/www.schneier.com\/blog\/archives\/2021\/02\/chinese-supply-chain-attack-on-computer-systems.html"},{"key":"e_1_3_2_117_2","unstructured":"Intel Security. 2009. Prioritizing Information Security Risks with Threat Agent Risk Assessment. Retrieved from https:\/\/media10.connectedsocialmedia.com\/intel\/10\/5725\/Intel_IT_Business_Value_Prioritizing_Info_Security_Risks_with_TARA.pdf"},{"key":"e_1_3_2_118_2","unstructured":"Ben Seri Gregory Vishnepolsky and Dor Zusman. 2019. BLEEDINGBIT: The Hidden Attack Surface within BLE Chips."},{"key":"e_1_3_2_119_2","unstructured":"Nataliya Shevchenko. 2018. Threat Modeling: 12 Available Methods. Retrieved from https:\/\/insights.sei.cmu.edu\/blog\/threat-modeling-12-available-methods\/"},{"key":"e_1_3_2_120_2","unstructured":"Nataliya Shevchenko Timothy A. Chick Paige O\u2019Riordan Thomas P. Scanlon and Carol Woody. 2018. Threat Modeling: A Summary of Available Methods."},{"key":"e_1_3_2_121_2","volume-title":"Proceedings of the CEUR Workshop","author":"Shostack Adam","year":"2008","unstructured":"Adam Shostack. 2008. Experiences threat modeling at microsoft. In Proceedings of the CEUR Workshop."},{"key":"e_1_3_2_122_2","volume-title":"Threat Modeling: Designing for Security","author":"Shostack Adam","year":"2014","unstructured":"Adam Shostack. 2014. Threat Modeling: Designing for Security. John Wiley & Sons."},{"key":"e_1_3_2_123_2","unstructured":"Adam Shostack. 2023. More on GPT-3 and Threat Modeling. Retrieved from https:\/\/shostack.org\/blog\/more-on-gpt3\/"},{"key":"e_1_3_2_124_2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"2","DOI":"10.1007\/3-540-36400-5_2","volume-title":"Proceedings of the CHES,","volume":"2523","author":"Skorobogatov Sergei P.","year":"2002","unstructured":"Sergei P. Skorobogatov and Ross J. Anderson. 2002. Optical fault induction attacks. In Proceedings of the CHES,Lecture Notes in Computer Science, Vol. 2523, Springer, 2\u201312."},{"key":"e_1_3_2_125_2","first-page":"621","volume-title":"Proceedings of the USENIX Security Symposium","author":"Stevens Rock","year":"2018","unstructured":"Rock Stevens, Daniel Votipka, Elissa M Redmiles, Colin Ahern, Patrick Sweeney, and Michelle L Mazurek. 2018. The battle for New York: A case study of applied digital threat modeling at the enterprise level. In Proceedings of the USENIX Security Symposium. 621\u2013637."},{"key":"e_1_3_2_126_2","article-title":"An analysis of open-source automated threat modeling tools and their extensibility from security into privacy","author":"Tan Kristen","year":"2022","unstructured":"Kristen Tan and Vaibhav Garg. 2022. An analysis of open-source automated threat modeling tools and their extensibility from security into privacy. Retrieved from https:\/\/www.usenix.org\/publications\/loginonline\/analysis-open-source-automated-threat-modeling-tools-and-their. USENIX Login (2022).","journal-title":"USENIX Login"},{"key":"e_1_3_2_127_2","unstructured":"Izar Tarandach. 2024. pytm: A Pythonic Framework for Threat Modeling. Retrieved from https:\/\/github.com\/izar\/pytm"},{"key":"e_1_3_2_128_2","volume-title":"Threat Modeling: A Practical Guide for Development Teams","author":"Tarandach Izar","year":"2021","unstructured":"Izar Tarandach and Matthew J. Coles. 2021. Threat Modeling: A Practical Guide for Development Teams. O\u2019Reilly."},{"key":"e_1_3_2_129_2","unstructured":"Google Cloud Security Team. 2023. Sec-PaLM: Supercharging Security with Generative AI. Retrieved from https:\/\/cloud.google.com\/blog\/products\/identity-security\/rsa-google-cloud-security-ai-workbench-generative-ai"},{"key":"e_1_3_2_130_2","unstructured":"Tutamantic. 2024. Tutamen Threat Model Automator. Retrieved from https:\/\/www.tutamantic.com\/"},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1002\/9781118988374"},{"key":"e_1_3_2_132_2","first-page":"178","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck, Frank Piessens, and Raoul Strackx. 2018. Nemesis: Studying microarchitectural timing leaks in rudimentary CPU interrupt logic. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security. 178\u2013195."},{"key":"e_1_3_2_133_2","unstructured":"William E. Vesely Francine F. Goldberg Norman H. Roberts and David F. Haasl. 1981. Fault Tree Handbook."},{"key":"e_1_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00013"},{"key":"e_1_3_2_135_2","unstructured":"W3C. 2021. Web Authentication: An API for Accessing Public Key Credentials - Level 2. Retrieved from https:\/\/www.w3.org\/TR\/webauthn\/"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1145\/2994539.2994542"},{"key":"e_1_3_2_137_2","doi-asserted-by":"publisher","DOI":"10.1145\/3331524"},{"key":"e_1_3_2_138_2","unstructured":"Jake Williams. 2020. What You Need to Know About the SolarWinds Supply-Chain Attack. Retrieved from https:\/\/www.sans.org\/blog\/what-you-need-to-know-about-the-solarwinds-supply-chain-attack\/"},{"key":"e_1_3_2_139_2","unstructured":"TMM working group. 2020. Threat Modeling Manifesto. Retrieved from https:\/\/www.threatmodelingmanifesto.org"},{"key":"e_1_3_2_140_2","volume-title":"Proceedings of the WOOT, USENIX Security Symposium","author":"Wu Jianliang","year":"2020","unstructured":"Jianliang Wu, Yuhong Nan, Vireshwar Kumar, Dave (Jing) Tian, Antonio Bianchi, Mathias Payer, and Dongyan Xu. 2020. BLESA: Spoofing attacks against reconnections in bluetooth low energy. In Proceedings of the WOOT, USENIX Security Symposium."},{"key":"e_1_3_2_141_2","unstructured":"Kim Wuyts Riccardo Scandariato and Wouter Joosen. 2014. LINDDUN Privacy Threat Tree Catalog."},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00047"},{"key":"e_1_3_2_143_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.45"},{"key":"e_1_3_2_144_2","unstructured":"yaml developers. 2024. YAML: YAML Ain\u2019t Markup Language\u2122. Retrieved from https:\/\/yaml.org\/"},{"key":"e_1_3_2_145_2","unstructured":"yamllint developers. 2024. YAMLlint: The YAML Validator. Retrieved from https:\/\/www.yamllint.com\/"},{"key":"e_1_3_2_146_2","first-page":"719","volume-title":"Proceedings of the 23rd USENIX Security Symposium, August 20\u201322, 2014","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack. In Proceedings of the 23rd USENIX Security Symposium, August 20\u201322, 2014, Kevin Fu and Jaeyeon Jung (Eds.). USENIX Association, 719\u2013732."},{"key":"e_1_3_2_147_2","first-page":"37","volume-title":"Proceedings of the USENIX Security Symposium","author":"Zhang Yue","year":"2020","unstructured":"Yue Zhang, Jian Weng, Rajib Dey, Yier Jin, Zhiqiang Lin, and Xinwen Fu. 2020. Breaking secure pairing of bluetooth low energy using downgrade attacks. In Proceedings of the USENIX Security Symposium. 37\u201354."}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3698396","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,30]],"date-time":"2025-09-30T14:56:35Z","timestamp":1759244195000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3698396"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,12]]},"references-count":146,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9,30]]}},"alternative-id":["10.1145\/3698396"],"URL":"https:\/\/doi.org\/10.1145\/3698396","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,12]]},"assertion":[{"value":"2024-02-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-07","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-09-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}