Skip to main content

Attack Feasibility

According to ISO/SAE 21434, the attack feasibility rates how easily an attack path can be carried out. The result is the attack feasibility level (AFL) on a four-step scale from very low to high. Unlike the safety world, the security rating does not work with probabilities of occurrence: attackers don’t roll dice, they choose the path with the least effort. What is rated is therefore what an attack costs an attacker.

Three Rating Approaches

The standard offers three approaches to choose from. The attack-potential-based approach rates each attack step based on five factors: elapsed time, specialist expertise, knowledge of the item, window of opportunity and equipment; the methodology is based on ISO 18045 and the Common Criteria evaluation and is the most common one in the concept phase. The CVSS-based approach uses the exploitability metrics of the Common Vulnerability Scoring System and lends itself to situations where concrete vulnerabilities are known. The attack-vector-based approach simplifies by distinguishing only the access path — from network-reachable to physical access — and is suitable for early, rough assessments.

The Role in Risk Determination

In the Threat Analysis and Risk Assessment (TARA), the feasibility of the associated attack paths is rated for every threat scenario. Since the easiest path determines the rating, the AFL of a threat scenario is the highest AFL of its paths. Together with the impact level of the damage scenario, the risk level results via the risk matrix — and with it the basis of the treatment decision: reduce, avoid, share or accept.

Attack Feasibility in Practice

Rating a single attack step is manageable; what is demanding is consistency. The same attack step appears in many paths and must be rated identically everywhere, and with AND combinations efforts add up, while with OR alternatives the easiest way counts. Keeping this aggregation consistent by hand across branching paths quickly overwhelms spreadsheets. For robust analyses according to ISO/SAE 21434, a computed rating therefore proves its worth, with changes to one step automatically affecting all paths concerned — more on this in our article on the TARA.

Related terms

Frequently asked questions

Why does the standard rate feasibility instead of probability?
Because attackers don’t roll dice. Random failures can be described with probabilities of occurrence, deliberate attacks cannot: a motivated attacker carries out a step as soon as they can afford it. What is rated is therefore the effort an attack requires — the lower the effort, the higher the feasibility.
Which rating approaches does ISO/SAE 21434 allow?
Three: the attack-potential-based approach with the factors elapsed time, specialist expertise, knowledge of the item, window of opportunity and equipment (based on ISO 18045 / Common Criteria), the CVSS-based approach using the exploitability metrics, and the simplified attack-vector-based approach, which only distinguishes by the access path. The standard does not mandate any of the three.
Does the attack feasibility change over time?
Yes, and almost always upwards: new tools, published exploits and new knowledge lower the effort of an attack. A path that was considered hard to carry out at the concept phase can be trivial years later. This is why the standard requires continual activities in which existing ratings are checked against new events.
Reviewed by Jens Bühl, Product Owner on August 21, 2026