Adding Security Concerns to Safety Critical Certification

被引:6
|
作者
Nostro, Nicola [1 ]
Bondavalli, Andrea [1 ]
Silva, Nuno [2 ]
机构
[1] Univ Florence, Consorzio Interuniv Nazl Informat, Florence, Italy
[2] Crit Software SA, Project Management Off ASD, Coimbra, Portugal
来源
2014 IEEE INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING WORKSHOPS (ISSREW) | 2014年
关键词
Safety; Security; Safety-critical system; Cyber Threats; Threats Library;
D O I
10.1109/ISSREW.2014.56
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Safety-critical systems represent those systems whose failure may lead to catastrophic consequences on users and environment. Several methods and hazard analysis, and standards in different disciplines, have been defined in order to assure the systems have been designed in compliance with safety requirements. The increasing presence of automatic controlling operation, the massive use of networks to transfer data and information, and the human operations introduce a new security concern in safety-critical systems. Security issues (threats) do not only have direct impact on systems availability, integrity and confidentiality, but they also can influence the safety aspects of the safety critical systems. Today taking into account malicious actions through intrusion into communications and computer control systems become a critical and not negligible step during the design and the assessment of safety-critical systems. The paper describes a general methodology to support the assessment of safety-critical system with respect to security aspects. The methodology is based on a library of security threats. Such threats, identified during the work, have been mapped to the NIST security controls. Then, a preliminary representation of the library in the aerospace domain is shown through some simple example, together with some considerations on the relation between security issues and safety impact as a valuable addition to the safety critical systems certification process.
引用
收藏
页码:521 / 526
页数:6
相关论文
共 50 条
  • [21] Ensuring Safety, Security, and Sustainability of Mission-Critical Cyber-Physical Systems
    Banerjee, Ayan
    Venkatasubramanian, Krishna K.
    Mukherjee, Tridib
    Gupta, Sandeep Kumar S.
    PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 283 - 299
  • [22] The AssureMOSS security certification scheme
    Milankovich, Akos
    Eberhardt, Gergely
    Lukacs, David
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [23] ICTs for Safety & Security
    Ronchi, Alfredo M.
    2017 IST-AFRICA WEEK CONFERENCE (IST-AFRICA), 2017,
  • [24] Safety, security and safeguard
    Zakariya, Nasiru Imam
    Kahn, M. T. E.
    ANNALS OF NUCLEAR ENERGY, 2015, 75 : 292 - 302
  • [25] Design optimization for security- and safety-critical distributed real-time applications
    Jiang, Wei
    Pop, Paul
    Jiang, Ke
    MICROPROCESSORS AND MICROSYSTEMS, 2017, 52 : 401 - 415
  • [26] SaSeVAL: A Safety/Security-Aware Approach for Validation of Safety-Critical Systems
    Wolschke, Christian
    Sangchoolie, Behrooz
    Simon, Jacob
    Marksteiner, Stefan
    Braun, Tobias
    Hamazaryan, Hayk
    51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN-W 2021), 2021, : 27 - 34
  • [27] Reducing Software Assurance Risks for Security-Critical and Safety-Critical Systems
    Axelrod, C. Warren
    2014 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE (LISAT), 2014,
  • [28] Virtualization sparks security concerns
    Vaughan-Nichols, Steven J.
    COMPUTER, 2008, 41 (08) : 13 - 15
  • [29] Concerns and Security for Hashing Passwords
    Herrera, Jonathan
    Ali, Md Liakat
    2018 9TH IEEE ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2018, : 861 - 865
  • [30] Omalizumab safety concerns
    Pongdee, Thanai
    Li, James T.
    JOURNAL OF ALLERGY AND CLINICAL IMMUNOLOGY, 2025, 155 (01) : 31 - 35