Systematic Cybersecurity Risk Analysis of ERTMS

Systematic Cybersecurity Risk Analysis of ERTMS

Supervisor(s): Sebastian Peters, Lukas Lautenschlager
Status: finished
Topic: Others
Author: Kacper Darowski
Submission: 2026-04-17
Type of Thesis: Guided Research
Thesis topic in co-operation with the Fraunhofer Institute for Applied and Integrated Security AISEC, Garching

Description

In this work, we present the first comprehensive risk
analysis of European Rail Traffic Management System (ERTMS)
using adapted versions of the industry-proven Modular Risk
Assessment for the Development of Secure Automotive Systems
(MoRA) and Spoofing, Tampering, Repudiation, Information
Disclosure, Denial of Service, Elevation of Privilege (STRIDE)
frameworks. The study systematically models components of
ERTMS—including European Train Control System (ETCS) and
Global System for Mobile Communications – Railway (GSMR)—
and analyzes their security based on threats identified on the
underlying technologies. The results suggest a concerning state
of ERTMS, despite its critical role in ensuring human safety
during daily railway operation—the use of legacy standards like
EuroBalises and GSM-R introduces vulnerabilities that persist
throughout minimal ERTMS implementations, deployments incorporating
various optional safety measures, and prospective
future evolutions of the system, e.g., adopting Future Railway
Mobile Communication System (FRMCS). Fully transitioning to
ETCS level 2 was identified as the most significant measure
for advancing ERTMS cybersecurity, though various attacks
on availability remain unaddressed—both by the European
Union Agency for Railways (ERA) and current research. We
advocate for an attention shift within ERTMS standardization
to further security through our original proposals alongside
measures suggested by other researchers. While our chosen
methodology proved its feasibility, future work is encouraged to
develop railway-centric adaptations to improve the quantization
and evaluation of the computed risks.