Adding Security Concerns to Safety Critical Certification

被引:6
|
作者
Nostro, Nicola [1 ]
Bondavalli, Andrea [1 ]
Silva, Nuno [2 ]
机构
[1] Univ Florence, Consorzio Interuniv Nazl Informat, Florence, Italy
[2] Crit Software SA, Project Management Off ASD, Coimbra, Portugal
来源
2014 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW) | 2014年
关键词
Safety; Security; Safety-critical system; Cyber Threats; Threats Library;
D O I
10.1109/ISSREW.2014.56
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Safety-critical systems represent those systems whose failure may lead to catastrophic consequences on users and environment. Several methods and hazard analysis, and standards in different disciplines, have been defined in order to assure the systems have been designed in compliance with safety requirements. The increasing presence of automatic controlling operation, the massive use of networks to transfer data and information, and the human operations introduce a new security concern in safety-critical systems. Security issues (threats) do not only have direct impact on systems availability, integrity and confidentiality, but they also can influence the safety aspects of the safety critical systems. Today taking into account malicious actions through intrusion into communications and computer control systems become a critical and not negligible step during the design and the assessment of safety-critical systems. The paper describes a general methodology to support the assessment of safety-critical system with respect to security aspects. The methodology is based on a library of security threats. Such threats, identified during the work, have been mapped to the NIST security controls. Then, a preliminary representation of the library in the aerospace domain is shown through some simple example, together with some considerations on the relation between security issues and safety impact as a valuable addition to the safety critical systems certification process.
引用
收藏
页码:521 / 526
页数:6
相关论文
共 50 条
  • [1] Safety and security concerns at the beach: Views of migrant visitors in Ghana
    Preko, Alexander
    TOURISM AND HOSPITALITY RESEARCH, 2021, 21 (01) : 73 - 85
  • [2] Assessment and certification of safety critical software
    El Koursi, EM
    Mariano, G
    ROBOTICS, AUTOMATION AND CONTROL AND MANUFACTURING: TRENDS, PRINCIPLES AND APPLICATIONS, 2002, 14 : 51 - 57
  • [3] Combining Models for Safety and Security Concerns in Automating Digital Production
    Kropatschek, Sebastian
    Hollerer, Siegfried
    Hoffman, David
    Winkler, Dietmar
    Luder, Arndt
    Sauter, Thilo
    Kastner, Wolfgang
    Biffl, Stefan
    2023 IEEE 21ST INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS, INDIN, 2023,
  • [4] A Study on Integrated Airworthiness Certification Criteria for Avionics Software Safety and Security
    Han, Man-Goon
    Park, Tae-Kyou
    JOURNAL OF THE KOREAN SOCIETY FOR AERONAUTICAL AND SPACE SCIENCES, 2018, 46 (01) : 86 - 94
  • [5] User Safety and Security in the Metaverse: A Critical Review
    Sharma, Saurabh
    Singh, Jaiteg
    Gupta, Ankur
    Ali, Farman
    Khan, Faheem
    Kwak, Daehan
    IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 2024, 5 : 5467 - 5487
  • [6] IMPACT OF OLYMPIC SPECTATOR SAFETY PERCEPTION AND SECURITY CONCERNS ON TRAVEL DECISIONS
    Neirotti, Lisa Delpy
    Hilliard, Tyra W.
    TOURISM REVIEW INTERNATIONAL, 2006, 10 (04): : 269 - 284
  • [7] Towards Adding Safety and Security Properties to the Industry 4.0 Asset Administration Shell
    Hosseini, Ali Mohammad
    Sauter, Thilo
    Kastner, Wolfgang
    17TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2021 (WFCS 2021), 2021, : 41 - 44
  • [8] Towards Incremental Safety and Security Requirements Co-Certification
    Andrea, Morgagni
    Philippe, Massonet
    Sbastien, Dupont
    Jeremy, Grandclaudon
    2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 79 - 84
  • [9] Application of space technology in support of security and safety of critical infrastructure
    Kurnaz, S.
    Rustamov, R. B.
    INTEGRATION OF INFORMATION FOR ENVIRONMENTAL SECURITY, 2008, : 149 - +
  • [10] Safety and Security in Critical Applications and in Information Systems - a Comparative Study
    Almeida, J. R., Jr.
    Camargo, J. B., Jr.
    Cugnasca, P. S.
    IEEE LATIN AMERICA TRANSACTIONS, 2013, 11 (04) : 1127 - 1133