Safety analysis,
guided by ontology.
AppSTPA is an ontology-based tool that makes Systems-Theoretic Process Analysis (STPA) systematic, automated and guided — covering safety, security and business analysis of complex cyber-physical systems.
Why AppSTPA?
STPA identifies more loss scenarios than traditional methods such as FMEA and FTA — but the analysis is lengthy and complex. AppSTPA encodes STPA domain knowledge in an ontology to keep the analyst on track.
Guided Analysis
Step-by-step workflow with pertinent guidance that avoids missed loss scenarios and incomplete analyses.
Ontology-Based
STPA domain knowledge represented formally, enabling systematic, automated suggestions during the analysis.
Safety + Security + Business
Since v2, AppSTPA integrates STRIDE-based cybersecurity and business analysis, revealing conflicts and reinforcements between requirements.
Peer-Reviewed
Methodology and tool evaluated and published in IEEE Access — evidence you can cite in academic and industrial contexts.
STPA in 4 Steps
AppSTPA systematizes the MIT STPA Handbook process (Leveson & Thomas) into a guided, validated workflow.
Define the Purpose
Identify losses, system-level hazards, constraints and the system boundary.
Model the Control Structure
Model controllers, actuators, sensors, controlled processes and their interactions.
Identify Unsafe Control Actions
Find control actions that lead to a loss in a particular context (UCAs).
Identify Loss Scenarios
Explore causal factors behind each UCA and derive safety recommendations.
Publications
The scientific foundation of AppSTPA, peer-reviewed and open access.
Workflow for Conflict and Reinforcement Identification Based on STPA and STRIDE
Extends the analysis to safety, cybersecurity and business concerns, systematically identifying conflicts and reinforcements between mechanisms and countermeasures.
A. Carniel, J. de Melo Bezerra, C. M. Hirata — IEEE Access, vol. 13, pp. 5785–5814
READ ON IEEE XPLORE open_in_newAn Ontology-Based Approach to Aid STPA Analysis
Proposes the STPA ontology behind AppSTPA and shows that the tool provides pertinent guidance and more complete analyses than manual or spreadsheet-based approaches.
A. Carniel, J. D. M. Bezerra, C. M. Hirata — IEEE Access, vol. 11, pp. 12677–12697
READ ON IEEE XPLORE open_in_newHow to cite AppSTPA
@article{carniel2025workflow,
author = {Carniel, Andrei and de Melo Bezerra, Juliana and Hirata, Celso Massaki},
title = {Workflow for Conflict and Reinforcement Identification Based on STPA and STRIDE},
journal = {IEEE Access},
volume = {13},
pages = {5785--5814},
year = {2025},
doi = {10.1109/ACCESS.2024.3525002}
}
Download AppSTPA
Free under GPL license — we just ask you to cite our work. Hosted on GitHub with executables and source code.
v3.0.0
SAFETY · SECURITY · BUSINESS
Continuously updated version with STPA, STRIDE-based security and business analysis.
The Researchers
AppSTPA is the result of Ph.D. research conducted at the Instituto Tecnológico de Aeronáutica (ITA), Brazil.
Andrei Carniel
PH.D (ITA) · AUTHOR
Ph.D in Electronic and Computer Engineering from Instituto Tecnológico de Aeronáutica (ITA). Atualmente é Professor and researcher working in Software Engineering, Cyber-Physical Systems, mobile devices and IoT. Research interests include Safety and Security Critical Systems, Requirements Analysis, IoT, Software Engineering and Collaborative Systems.
Celso Massaki Hirata
FULL PROFESSOR · ITA · SUPERVISOR
Ph.D from Imperial College London. Currently serves as Pró-Reitor de Graduação. Research interests include Distributed Systems, Safety and Security Critical Systems, Discrete Simulation, Software Engineering and Collaborative Systems. Recipient of the ACM SAC Best Paper Award (2011).
Juliana de Melo Bezerra
ASSOCIATE PROFESSOR · ITA · SUPERVISOR
Ph.D. in Electronic and Computer Engineering from Instituto Tecnológico de Aeronáutica (ITA). Currently serves as Coordinator of the Systems Engineering program. Research areas include Distributed Systems, Aerospace Systems,Critical Systems, Safety, and Systems Engineering.