Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-671 — Requirements for ASIC Functionality Maliciously Altered
CAPEC-671

Requirements for ASIC Functionality Maliciously Altered

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: Low. An adversary with access to functional requirements for an application specific integrated circuit (ASIC), a chip designed/customized for a singular particular use, maliciously alters requirements derived from originating capability needs. In the chip manufacturing process, requirements drive the chip design which, when the chip is fully manufactured, could result in an ASIC which may not meet the user’s needs, contain malicious functionality, or exhibit other anomalous behaviors thereby affecting the intended use of the ASIC.

Mitigation

Utilize DMEA’s (Defense Microelectronics Activity) Trusted Foundry Program members for acquisition of microelectronic components. | Ensure that each supplier performing hardware development implements comprehensive, security-focused configuration management including for hardware requirements and design. | Require that provenance of COTS microelectronic components be known whenever procured. | Conduct detailed vendor assessment before acquiring COTS hardware.

Details

Platforms
Supply-chain
Hardware
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.