CRESS: Quantifying Vulnerabilities of Attack Scenarios in Hardware Reverse Engineering

📅 2026-06-03
📈 Citations: 0
Influential: 0
📄 PDF

career value

211K/year
🤖 AI Summary
This study addresses the lack of a unified, quantifiable evaluation framework for hardware reverse engineering attacks, which hinders effective comparison and mitigation of diverse threats. Through expert interviews, the authors extend the qualitative CRESS scoring system into the first computable quantitative severity model by incorporating expert-derived weights into a formal scoring formula. The proposed approach integrates weight analysis, quantitative modeling, and empirical validation, demonstrating successful application across six real-world attack scenarios. Results show that CRESS offers greater expressiveness and adaptability compared to CVSS, thereby providing robust support for assessing emerging hardware-level threats and informing defensive design strategies.
📝 Abstract
The safety, security, and reliability of microelectronic systems depend on a trustworthy, secured supply chain and design flow. Globally distributed supply chains or unintentional design weaknesses leave the door open for attacks on the hardware level. These scenarios encompass counterfeiting, hardware trojans, or on-device attacks. For these, hardware reverse engineering (RE) results play a pivotal role. The ongoing publication of new RE-involved attacks motivated the development of the common RE scoring system (CRESS). The system enables a general classification of RE-involved scenarios for a common, consistent rating. In this work, the originally qualitative system is extended to a quantitative system. We performed an extensive interview study with experts in the field. The interview results allowed us to derive weights that measure the severity of different RE-involved attack categories. The weights form an equation that quantifies scenarios, resulting in the severity-indicating CRESS score. The score enables the coherent rating of novel scenarios, renders them comparable, and supports the development of effective countermeasures. To showcase the effectiveness of the quantitative CRESS Score, six selected case studies are rated qualitatively and quantitatively. The CRESS Score proves to be significantly more expressive than the industry-standard Common Vulnerability Scoring System (CVSS).
Problem

Research questions and friction points this paper is trying to address.

hardware reverse engineering
vulnerability quantification
attack scenarios
security assessment
CRESS
Innovation

Methods, ideas, or system contributions that make the work stand out.

CRESS
hardware reverse engineering
quantitative vulnerability scoring
attack scenario assessment
security metrics
A
Alexander Hepp
TUM School of Computation, Information and Technology, Munich, Germany
M
Matthias Ludwig
TUM School of Computation, Information and Technology, Munich, Germany
M
Michaela Brunner
TUM School of Computation, Information and Technology, Munich, Germany
J
Johanna Baehr
Fraunhofer Institute for Applied and Integrated Security (AISEC), Munich, Germany
G
Georg Sigl
TUM School of Computation, Information and Technology, Munich, Germany; Fraunhofer Institute for Applied and Integrated Security (AISEC), Munich, Germany