Logo image
An integrated STPA-STRIDE-BN framework for cybersecurity risk analysis: A case study of ship remote pilotage operations
Journal article   Peer reviewed

An integrated STPA-STRIDE-BN framework for cybersecurity risk analysis: A case study of ship remote pilotage operations

Sunil Basnet, Victor Bolbot, Awais Yousaf, Sean Gunawan, Jianying Zhou and Osiris A. Valdez Banda
Future generation computer systems, Vol.183, p.108515
01/10/2026

Abstract

Bayesian networks Denial of service Elevation of privilege/ce:text Information disclosure Repudiation Ship remote pilotage Spoofing System-theoretic process analysis Tampering Cybersecurity

The increasing adoption of novel digital-based operations in the transportation industry introduces new cybersecurity challenges due to the reliance on digital communication and automation. This paper presents a novel cybersecurity risk assessment methodology that integrates System-Theoretic Process Analysis (STPA), Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege (STRIDE), and Bayesian Networks (BN) to systematically identify and quantify cybersecurity threats in transport remote pilotage operations. The proposed framework applies STPA to identify unsafe/unsecured control actions (UCAs/U`CAs), utilizes STRIDE with emphasis on Spoofing, Tampering and Denial of Service attacks to identify potential cybersecurity threats related to safety losses, and employs BN to estimate and prioritize risk probabilities of critical cyber threats. A case study from maritime involving remote pilotage operations demonstrates the applicability of the methodology, highlighting key vulnerabilities such as cyber-attacks on navigation aids and communication channels. The results indicate that state-sponsored attacks pose higher risks than those from criminal hackers, with posterior probabilities for major losses being approximately 2.4 times higher. The findings emphasize the need for enhanced cybersecurity measures, particularly focusing on critical system components and human-system interactions. The proposed approach provides transportation stakeholders with a structured methodology for assessing and mitigating cybersecurity risks in evolving and more remote operations.

url
https://doi.org/10.1016/j.future.2026.108515View
Published (Version of record)

Metrics

Details

Logo image