MOSAIC-TARA: A Comprehensive TARA Methodology for Automotive Cybersecurity

2026-26-0609

To be published on 01/16/2026

Authors Abstract
Content
Threat Analysis and Risk Assessment (TARA) is a continuous activity, acting as a foundation of cybersecurity analysis for electrical and electronics automotive products. Existing TARA methodologies in the automotive domain exhibits challenges due to redundant and manual processes, particularly in handling recurring common assets across Electronic Control Units (ECUs) and functional domains. Two primary approaches observed for performing TARA are Manual-Asset-Centric TARA and Catalogue-Driven TARA. Manual-Asset Centric TARA is constructed from scratch by manually identifying the assets, calculating risks by likelihood, and impact determination. Catalogue-Driven TARA utilizes the precompiled likelihood and impact against identified assets. Both approaches lack standardized and modular mechanisms for abstraction and reuse. This results in poor scalability, increased efforts, and difficulty in maintaining consistency across vehicle platforms. The proposed method in this research overcomes such challenges, named as “MOSAIC-TARA”. It is a Modular, Scalable, Adaptive, Interoperable, Comprehensive TARA, decomposing a vehicle system into functional domains or ECUs, and further into its components. Each module is independently assessed and analyzed for potential threats, damage scenarios, and security goals, formulating the multiple TARA modules. These independent individual TARAs are then aggregated based on the architecture to derive ECU level TARA. The modularity of this method supports reusability of assessments across different ECUs, functional domains, and vehicle platforms. This enables optimized and efficient TARA tailored to different system configurations. Additionally, the presented approach introduces damage scenarios classification based on impact criticality, as the same component may lead to varying damage impact depending on the context. Thus, the TARA modules are developed for various level of damage impacts, provides adaptability towards impact criticality of selected ECU or its functions. MOSIAC-TARA aligns with ISO/SAE 21434 and supports efficient reusable risk-driven design.
Meta TagsDetails
Citation
Goyal, Y., Sinha, S., Sutar, S., and Jaisingh, S., "MOSAIC-TARA: A Comprehensive TARA Methodology for Automotive Cybersecurity," SAE Technical Paper 2026-26-0609, 2026, .
Additional Details
Publisher
Published
To be published on Jan 16, 2026
Product Code
2026-26-0609
Content Type
Technical Paper
Language
English