Adding Security Concerns to Safety Critical Certification

被引:6
|
作者
Nostro, Nicola [1 ]
Bondavalli, Andrea [1 ]
Silva, Nuno [2 ]
机构
[1] Univ Florence, Consorzio Interuniv Nazl Informat, Florence, Italy
[2] Crit Software SA, Project Management Off ASD, Coimbra, Portugal
来源
2014 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW) | 2014年
关键词
Safety; Security; Safety-critical system; Cyber Threats; Threats Library;
D O I
10.1109/ISSREW.2014.56
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Safety-critical systems represent those systems whose failure may lead to catastrophic consequences on users and environment. Several methods and hazard analysis, and standards in different disciplines, have been defined in order to assure the systems have been designed in compliance with safety requirements. The increasing presence of automatic controlling operation, the massive use of networks to transfer data and information, and the human operations introduce a new security concern in safety-critical systems. Security issues (threats) do not only have direct impact on systems availability, integrity and confidentiality, but they also can influence the safety aspects of the safety critical systems. Today taking into account malicious actions through intrusion into communications and computer control systems become a critical and not negligible step during the design and the assessment of safety-critical systems. The paper describes a general methodology to support the assessment of safety-critical system with respect to security aspects. The methodology is based on a library of security threats. Such threats, identified during the work, have been mapped to the NIST security controls. Then, a preliminary representation of the library in the aerospace domain is shown through some simple example, together with some considerations on the relation between security issues and safety impact as a valuable addition to the safety critical systems certification process.
引用
收藏
页码:521 / 526
页数:6
相关论文
共 50 条
  • [11] Implementing a Security Architecture for Safety-Critical Railway Infrastructure
    Eckel, Michael
    Kuzhiyelil, Don
    Krauss, Christoph
    Zhdanova, Maria
    Katzenbeisser, Stefan
    Cosic, Jasmin
    Drodt, Matthias
    Pitrolle, Jean-Jacques
    2021 INTERNATIONAL SYMPOSIUM ON SECURE AND PRIVATE EXECUTION ENVIRONMENT DESIGN (SEED 2021), 2021, : 215 - 226
  • [12] Defence Transformation in Nigeria A Critical Issue for National Security Concerns
    Magbadelo, John Olushola
    INDIA QUARTERLY-A JOURNAL OF INTERNATIONAL AFFAIRS, 2012, 68 (03): : 251 - 266
  • [13] A Framework for the Integration of Safety and Security in case of Critical Infrastructure Protection (FISSCIP)
    Genserik, Reniers
    Inge, Dupont
    DISASTER ADVANCES, 2010, 3 (04): : 4 - 12
  • [14] Security and Reliability of Safety-Critical RTOS
    Luna R.
    Islam S.A.
    SN Computer Science, 2021, 2 (5)
  • [15] Understanding the Physical Safety, Security, and Privacy Concerns of People with Visual Impairments
    Ahmed, Tousif
    Hoyle, Roberto
    Shaffer, Patrick
    Connelly, Kay
    Crandall, David
    Kapadia, Apu
    IEEE INTERNET COMPUTING, 2017, 21 (03) : 56 - 63
  • [16] Communication in Change - Voice over IP in Safety and Security Critical Communication Networks
    Zeilinger, Heimo
    Sevcik, Berndt
    Turek, Thomas
    Zucker, Gerhard
    IT REVOLUTIONS, 2009, 11 : 186 - 193
  • [17] SECURA: Unified Reference Architecture for Advanced Security and Trust in Safety Critical Infrastructures
    Eckel, Michael
    Guergens, Sigrid
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [18] Fast Game Verification for Safety- and Security-Critical Distributed Applications
    Luo, Wei
    Xie, Guoqi
    Liu, Yao
    Xiao, Xiongren
    Li, Renfa
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 870 - 887
  • [19] Managing security evidence in safety-critical organizations
    Mohamad, Mazen
    Steghoefer, Jan-Philipp
    Knauss, Eric
    Scandariato, Riccardo
    JOURNAL OF SYSTEMS AND SOFTWARE, 2024, 214
  • [20] Privacy, confidentiality, security and patient safety concerns about electronic health records
    Bani Issa, W.
    Al Akour, I.
    Ibrahim, A.
    Almarzouqi, A.
    Abbas, S.
    Hisham, F.
    Griffiths, J.
    INTERNATIONAL NURSING REVIEW, 2020, 67 (02) : 218 - 230