The Risk Assessment of ERTMS-Based Railway Systems from a Cyber Security Perspective: Methodology and Lessons Learned

被引:18
作者
Bloomfield, Robin [1 ]
Bendele, Marcus [1 ]
Bishop, Peter [1 ]
Stroud, Robert [1 ]
Tonks, Simon [2 ]
机构
[1] Adelard LLP, London, England
[2] Porterbrook Leasing Co, Derby, England
来源
RELIABILITY, SAFETY, AND SECURITY OF RAILWAY SYSTEMS: MODELLING, ANALYSIS, VERIFICATION, AND CERTIFICATION, RSSRAIL 2016 | 2016年 / 9707卷
基金
英国工程与自然科学研究理事会;
关键词
Security assessment; Safety-critical systems; Security-informed safety; ERTMS; Railway signaling systems;
D O I
10.1007/978-3-319-33951-1_1
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The impact that cyber issues might have on the safety and resilience of railway systems has been studied for more than five years by industry specialists and government agencies. This paper presents some of the work done by Adelard in this area, ranging from an analysis of potential vulnerabilities in the ERTMS specifications through to a high-level cyber security risk assessment of a national ERTMS implementation and detailed analysis of particular ERTMS systems on behalf of the GB rail industry. The focus of the paper is on our overall methodology for security-informed safety and hazard analysis. Lessons learned will be presented but of course our detailed results remain proprietary or sensitive and cannot be published.
引用
收藏
页码:3 / 19
页数:17
相关论文
共 4 条
[1]  
Bloomfield Richard, 2012, Computer Safety, Reliability,and Security. Proceedings of SAFECOMP 2012 Workshops: Sassur, ASCoMS, DESEC4LCCI, ERCIM/EWICS, IWDE, P247, DOI 10.1007/978-3-642-33675-1_22
[2]  
Department for Transport, 2016, GUID TO IND
[3]  
Network Rail, 2013, STRAT BUS PLAN 2014
[4]  
SESAMO - Security and Safety Modelling, 2012, SESAMO SECURITY SAFE