EMB3D – Threat Analysis for Embedded Devices
The in-depth method and reference course on the MITRE EMB3D™ threat model: from the foundations (risk, threat, vulnerability) through all device properties, all 81 threats, and all mitigations with their tiers, to a complete worked analysis of an example device. Every lesson is self-contained and can be called up individually as a reference chapter. Note: This course is voiced by AI voices (AI narrated).
Was Sie lernen
- Justify why embedded devices need a threat model of their own
- Explain EMB3D's three pillars (properties, threats, mitigations) and their mappings
- Fully enumerate a device's properties and map them to threats
- Assess and prioritize threats using maturity and evidence
- Select mitigations tier-based (foundational first, complementary vs. superseding)
- Carry out a complete EMB3D analysis and hand it over to risk management
- Use the course as a knowledge base: every lesson is a reference chapter
Themen
securitythreat-modelingemb3dembeddedeacgAI narrated
Modul 01 - Why Embedded Is Different ▶
- ▶ Introduction 2:21
- ▶ The Most Unremarkable Device Is the Most Critical One 6:08
- ▶ Without These Four Words, No Analysis Gets Off the Ground 6:47
- ▶ Module Recap: The Questions Worth Sitting With 3:17
- ? Match the Term to Its Meaning
Modul 02 - What Is EMB3D? Origins, Blueprint, Boundaries ▶
- ▶ What Is EMB3D? Origins, Blueprint, Boundaries 0:16
- ▶ EMB3D's Three Pillars — Built by an Operator, Two Researchers, and a Catalog-Keeper 13:36
- ▶ EMB3D Delivers Atomic, Device-Bound Threats — Not a Full Deployment Model 5:33
- ? In Scope or Out of Scope for EMB3D?
Modul 03 - Device Properties: The Device's Map ▶
- ▶ Device Properties: The Device's Map 0:16
- ▶ A Property Is Attack Surface — Even When Something's Missing 6:06
- ▶ Hardware Properties: What the Board Itself Gives Away 8:35
- ▶ System Software Properties: Who's Really in Control Once It Boots 11:06
- ▶ Application Software Properties: Where Business Logic Meets the Attacker 7:34
- ▶ Networking Properties: The Smallest Category, the One That Recurs Everywhere 6:31
- ▶ The Property Inventory: Collecting It, Mapping It, Sharing It 8:20
- ▶ Module Recap: From Populated Headers to Packet Captures 5:41
- ? Match the Device Feature to Its Property Category
Modul 04 - Reading & Rating Threats ▶
- ▶ Reading & Rating Threats 0:15
- ▶ A TID Entry Always Answers the Same Three Questions 7:34
- ▶ Maturity Separates Real Danger From Academic Risk — But Fifteen Years of Service Life Changes the Math 7:22
- ▶ Module Recap: How Real, and How Long It Stays That Way 3:29
- ? Rate the Maturity From the Evidence
Modul 05 - The Threat Catalog: All 81 Attack Patterns, Explained ▶
- ▶ The Threat Catalog: All 81 Attack Patterns, Explained 0:24
- ▶ Hardware Threats: Side-Channels & Fault Injection 13:06
- ▶ Hardware Threats: Memory & Buses 10:57
- ▶ Hardware Threats: Peripherals & Debug Ports 14:29
- ▶ System Software Threats: Boot, Update Chain & Root of Trust 16:34
- ▶ System Software Threats: OS, Kernel & Privileges 15:33
- ▶ System Software Threats: Virtualization, Diagnostics & Logs 13:10
- ? Match the Threat to Its Family
- ▶ The Code Running On Your Device Is Its Own Battlefield 15:34
- ▶ The Front Door Is Usually Unlocked, Not Broken Down 12:38
- ▶ When Encryption Is Present But Doesn't Actually Protect You 10:13
- ▶ The Web Vulnerabilities You Already Know, Now Running On a Device You Can Hold 11:38
- ▶ The Network Assumes Good Faith, and Some Protocols Never Learned Otherwise 14:37
- ? Match Each Scenario to Its Threat
- ▶ Module Recap: Eighty-One Threats, One Question 7:10
Modul 06 - Mitigations: What the Device Itself Must Do ▶
- ▶ Mitigations: What the Device Itself Must Do 0:29
- ▶ A Mitigation Lives Inside the Device — 'Isolate It' Doesn't Count 7:24
- ▶ Excursus: What Is IEC 62443, Before We Map to It? 10:08
- ▶ Tiers Make Mitigations Plannable: Foundational First 9:57
- ▶ Mitigations: Boot, Integrity & the Update Chain 28:36
- ▶ Mitigations: Code & Memory Hardening 16:24
- ▶ When an Attacker Can Touch the Board, These Mitigations Are What Stand Between Them and Your Secrets 26:52
- ▶ The Buses and DMA Paths Between Chips Need Their Own Locks, Not Just the Chips Themselves 27:17
- ▶ Every Other Mitigation in This Course Leans on Cryptography — Here's What Makes That Foundation Solid 24:26
- ▶ Most Breaches Don't Need Cleverness — They Need a Door Nobody Locked, and This Family Locks It 27:18
- ▶ Mitigations: Web & Network Protection 32:27
- ▶ Mitigations: Isolation, Logging & Formal Methods 30:34
- ? Order the Bootloader Tier Ladder, First Line of Defense to Strongest
- ? Complementary or Superseding? Decide for Each Mitigation Pair
- ▶ Module Recap: What the Device Itself Has to Prove 7:25
Modul 07 - Running the Analysis: AquaSense 300, End to End ▶
- ▶ Running the Analysis: AquaSense 300, End to End 0:18
- ▶ A Real Analysis Starts With the Device Defined, Not With the Catalog Open 6:04
- ▶ Design-Time Beats the Finished Product 5:05
- ▶ Step 1: Enumerate Every Property, and the Catalog Hands You the Threats 8:03
- ▶ Step 2: Every Relevance Call Needs a Reason You Can Show Someone Else 5:54
- ▶ Step 3: Naming the Gap Is What Turns a Threat Into a Roadmap 6:02
- ▶ The Deliverable Is a Document That Carries Every Decision You Made 5:28
- ▶ Module Recap: One Device, Three Steps, One Document 5:45
- ? Transfer Check: Run the Process on a Smart Electricity Meter
Modul 08 - Drawing Conclusions: Roles, Regulation, Staying Current ▶
- ▶ Drawing Conclusions: Roles, Regulation, Staying Current 0:18
- ▶ Three Roles, Three Different Conclusions From the Same Analysis 6:56
- ▶ EMB3D Is Alive, and So Is Your Analysis 6:55
- ▶ Module Recap: One Analysis, Three Desks 4:12
Modul 09 - Final Exam ▶
- ▶ Final Exam 0:14
- ? Final Exam — 32 Questions Across All Eight Modules
- ▶ Take-home messages 0:54