Author

R. A. Dyachenko

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

2026

ASSESSMENT OF THREATS FROM SOFTWARE BACKDOORS IN EMBEDDED SYSTEMS: A COMPREHENSIVE APPROACH BASED ON THE «INFORMATION SECURITY THREAT ASSESSMENT METHODOLOGY»

This article describes the implementation of a comprehensive approach to assessing information security threats concerning a specific class of devices—embedded systems. The article combines regulatory and technical-analytical approaches to evaluating the threats posed by software backdoors in embedded systems. The assessment of the threat from software backdoors in embedded systems is conducted within the framework of the classifications outlined in the «Information Security Threat Assessment Methodology» approved by the Federal Service for Technical and Export Control of Russia on February 5, 2021. Based on the classifications regulated by the methodology concerning the capabilities, tactics, and typical techniques of an attacker, and taking into account the peculiarities of the development and operation of embedded systems, the threat from software backdoors for this class of devices is assessed. As a result of the technical analysis, potential sources of information for an attacker implementing information-gathering tactics are detailed, and clustering is performed by network type for the tactics employed by the attacker to gain initial access to system components and networks using various techniques. The results of the threat assessment from software backdoors in embedded systems can be used to develop relevant countermeasures against threats, select optimal information protection means during the development and operation of embedded systems, and formulate technical specifications for the enhancement of existing or the creation of advanced information protection means in embedded systems.

A.I. Miroshnichenko, R. A. Dyachenko · 0 citations