In the defense sector, which we have recently been engaging with, we are experiencing firsthand that the paradigm of cybersecurity threat analysis is significantly different from that of the traditional commercial automotive industry.
While automotive cybersecurity (ISO/SAE 21434) has been centered around preventing system malfunctions and ensuring safety, the defense sector demands a higher-level approach known as 'Mission Assurance'—ensuring that weapon systems achieve their objectives even amidst intelligent and persistent enemy attacks.

In this post, we will examine the application of the MITRE TARA (Threat Assessment & Remediation Analysis) methodology—optimized for the defense industry—to unmanned weapon systems, and outline how our VisualPro can perfectly support this complex process.
The Decisive Differences Between Automotive TARA and Defense TARA
Automotive TARA and Defense TARA exhibit a distinct difference in their starting points and criteria for analysis.
- Automotive TARA (ISO/SAE 21434): This approach freely derives threat scenarios based on the traceability between asset damage scenarios and threat scenarios. It determines the CAL (Cybersecurity Assurance Level, Levels 1-4) by synthesizing safety, privacy, operational, and financial impacts alongside attack vectors, thereby defining process rigor.
- Defense TARA (MITRE Methodology): This methodology is developed assuming Advanced Persistent Threats (APTs). It focuses on 'Mission Assurance,' which entails 'resiliency' to maintain acceptable service levels even if defense lines are breached, and 'agility' to make outcomes uncertain for attackers.
- Presence of a Catalog: Unlike automotive TARA, which relies on free-form derivation, defense TARA utilizes pre-built catalogs of TTPs (Tactics, Techniques, and Procedures) and Countermeasures (CM) along with a quantitative scoring matrix to ensure consistency and repeatability.

The Core Framework of Defense TARA (MITRE TARA)
The MITRE TARA methodology applied to unmanned weapon systems is systematically conducted in two core analytical phases based on extensive catalog data.
Phase 1: CTSA (Cyber Threat Susceptibility Analysis)
This is the process of quantitatively evaluating the degree to which a system is susceptible to cyberattacks across a range of adversarial TTPs, resulting in a ranked Threat Matrix.
- Establishing the Evaluation Scope: Characterizes the target system assets, the scope of attack TTPs to consider, and the types of adversaries (e.g., external attackers, insiders).
- Identifying Candidate TTPs: Cross-references the asset's architecture utilizing the MAE (Mission Assurance Engineering) catalog, CAPEC (Common Attack Pattern Enumeration and Classification), CWE (Common Weakness Enumeration), and CVE (Common Vulnerabilities and Exposures).
- Filtering Out Unrealistic TTPs: Eliminates attack TTPs whose prerequisites do not exist in the system environment or are rendered impossible by already hardened security configurations.
- Applying the Scoring Model: Evaluates and ranks the remaining candidate TTPs based on criteria such as impact and recovery cost.
- Constructing the Threat Matrix: Compiles the quantitatively ranked list of TTPs to be used as inputs for the next phase (CRRA).

Phase 2: CRRA (Cyber Risk Remediation Analysis)
This phase derives an optimal set of Countermeasures (CM) to reduce the vulnerabilities identified during the CTSA phase or mitigate the effects of an attack. The core of this phase is the rigorous 'Traceability' between the TTPs mitigated by the countermeasures and the mission capabilities protected by them.
- Selecting TTPs to Mitigate: Determines the scope of TTPs to address based on the generated Threat Matrix.
- Identifying Realistic Countermeasures: Derives candidate countermeasures using a TTP/CM mapping table.
- Evaluating Countermeasure Value: Assesses and scores the mitigation effectiveness of the derived countermeasures.
- Identifying the Optimal Solution: Finds the most reasonable set of countermeasures based on cost-effectiveness.
- Drafting Recommendations: Produces a final report so program managers can make informed decisions to make the system less vulnerable.

The architecture of VisualPro, which has demonstrated outstanding performance in automotive functional safety and cybersecurity design, serves as an excellent solution even in the realm of Mission Assurance under the extreme conditions of unmanned weapon systems. By advancing our analysis templates to reflect the specificities of this new industry, we will be able to drive the expansion of our footprint into the defense sector.
In the defense sector, which we have recently been engaging with, we are experiencing firsthand that the paradigm of cybersecurity threat analysis is significantly different from that of the traditional commercial automotive industry.
While automotive cybersecurity (ISO/SAE 21434) has been centered around preventing system malfunctions and ensuring safety, the defense sector demands a higher-level approach known as 'Mission Assurance'—ensuring that weapon systems achieve their objectives even amidst intelligent and persistent enemy attacks.
In this post, we will examine the application of the MITRE TARA (Threat Assessment & Remediation Analysis) methodology—optimized for the defense industry—to unmanned weapon systems, and outline how our VisualPro can perfectly support this complex process.
The Decisive Differences Between Automotive TARA and Defense TARA
Automotive TARA and Defense TARA exhibit a distinct difference in their starting points and criteria for analysis.
The Core Framework of Defense TARA (MITRE TARA)
The MITRE TARA methodology applied to unmanned weapon systems is systematically conducted in two core analytical phases based on extensive catalog data.
Phase 1: CTSA (Cyber Threat Susceptibility Analysis)
This is the process of quantitatively evaluating the degree to which a system is susceptible to cyberattacks across a range of adversarial TTPs, resulting in a ranked Threat Matrix.
Phase 2: CRRA (Cyber Risk Remediation Analysis)
This phase derives an optimal set of Countermeasures (CM) to reduce the vulnerabilities identified during the CTSA phase or mitigate the effects of an attack. The core of this phase is the rigorous 'Traceability' between the TTPs mitigated by the countermeasures and the mission capabilities protected by them.
The architecture of VisualPro, which has demonstrated outstanding performance in automotive functional safety and cybersecurity design, serves as an excellent solution even in the realm of Mission Assurance under the extreme conditions of unmanned weapon systems. By advancing our analysis templates to reflect the specificities of this new industry, we will be able to drive the expansion of our footprint into the defense sector.