Skip to content

Additional Stencils and Threats for Medical Device Template#38

Open
jpschaaf wants to merge 2 commits intomicrosoft:masterfrom
jpschaaf:master
Open

Additional Stencils and Threats for Medical Device Template#38
jpschaaf wants to merge 2 commits intomicrosoft:masterfrom
jpschaaf:master

Conversation

@jpschaaf
Copy link
Copy Markdown
Contributor

This pull request includes additions/changes to the Medical Device Template including the following new stencils:

  • Medical Device UI
  • Smart Battery
  • Non-Invasive Blood Pressure device
  • Fetal Monitoring Sensor
  • ECG Sensor
  • Oxygen Saturation Sensor
  • Patient Monitor
  • Mobile Device Client
  • Printer
  • Barcode Reader
  • TPM
  • HSM
  • SMBus
  • USB Mass Storage Device
  • Remote Mobile Device Debug Bridge
  • Microprocessor Config Interface
  • USB DFU
  • RS232
  • SPI
  • Microprocessor EEPROM Programming Interface
  • I2C
  • JTAG

jpschaaf and others added 2 commits October 25, 2022 12:33
Merged changes from Microsoft repository relating to unix-style newlines.

4.1.0.419

Added 'Evaluation Notes' free text field to Threat Properties. 'Evaluation Notes' can be used to document discussion notes associated with the threat. The information entered in this field isn't imported or available in the SRA; it is available only in the threat model
4.1.0.418

Added the 'Medical Device UI' stencil under 'Generic Process'
Added the 'Smart Battery', 'Non Invasive Blood Pressure device NIBP', 'Fetal Monitoring Sensor', 'ECG Sensor', 'Oxygen Saturation Sensor', 'Patient Monitor' stencils under 'Generic Physical Medical Component'
Added the 'Mobile Device Client', 'Printer', 'Barcode Reader' stencils under 'Generic External Interactor'
Added the 'TPM', 'HSM' stencils under 'Generic Data Store'
Added the 'SMBus', 'USB Mass Storage Device', 'Remote Mobile Device Debug Bridge', 'Microprocessor Config Interface', 'USB DFU', 'RS232', 'SPI', 'Microprocessor EEPROM Programming Interface', 'I2C', 'JTAG' stencils under 'Generic Data Flow'
Added threats 'Smart Battery - Abuse', 'Elevation of privilege using Medical Device UI', 'Smart Battery Denial of Service', 'Printer Information Disclosure', 'Removable Storage Information Disclosure', 'Sensitive Information Disclosure via UI', 'Remote Mobile Device Debug Bridge Information Disclosure', 'Microprocessor EEPROM Programming Interface Information Disclosure', 'Microprocessor Config Interface Information Disclosure', 'JTAG Information Disclosure', 'Physical possession of HSM by threat actor', 'TPM/HSM Data Flow Sniffing', 'Medical Device UI Repudiation', 'Smart Battery safety aspects', 'Tampering using Medical Device UI', 'Code execution from removable storage device', 'Smart Battery Tampering', 'SMBus Tampering', 'RS232 Tampering', 'Microprocessor EEPROM Programming Interface Tampering', 'Microprocessor Config Interface Tampering', 'Remote Mobile Device Debug Bridge Tampering', 'USB DFU Tampering', 'JTAG Tampering', 'Bluetooth Sensor - Spoofing', 'NIBP Device - Spoofing'.
Updated threats 'Sensor - Abuse', 'Physical theft of component communicating via {flow.Name}', 'Sensor Safety Aspects'.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant