Conceptual Systems Security Requirements Analysis: Aerial Refueling Case Study

被引:14
作者
Span, Martin, III [1 ]
Mailloux, Logan O. [2 ]
Mills, Robert F. [2 ]
Young, William, Jr. [3 ]
机构
[1] US Air Force Acad, Colorado Springs, CO 80841 USA
[2] Air Force Inst Technol, Wright Patterson AFB, OH 45433 USA
[3] 53rd Elect Warfare Grp, Eglin AFB, FL 32542 USA
来源
IEEE ACCESS | 2018年 / 6卷
关键词
Cybersecurity; requirements engineering; security; security engineering; systems engineering; systems security engineering;
D O I
10.1109/ACCESS.2018.2865736
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's highly interconnected and technology-reliant environment, cybersecurity is no longer limited to traditional computer systems and IT networks, as a number of highly publicized attacks have occurred against complex cyber-physical systems such as automobiles and airplanes. While numerous vulnerability analysis and architecture analysis approaches are in use, these approaches are often focused on realized systems with limited solution space. A more effective approach for understanding security and resiliency requirements early in the system development is needed. One such approach, system-theoretic process analysis for security (STPA-Sec), addresses the cyber-physical security problem from a systems viewpoint at the conceptual stage when the solution trade-space is largest rather than merely examining components and adding protections during production, operation, or sustainment. This paper uniquely provides a detailed and independent evaluation of STPA-Sec's utility for eliciting, defining, and understanding security and resiliency requirements for a notional next generation aerial refueling platform.
引用
收藏
页码:46668 / 46682
页数:15
相关论文
共 50 条
  • [41] Security requirements for management systems using mobile agents
    Reiser, H
    Vogt, G
    ISCC 2000: FIFTH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, PROCEEDINGS, 2000, : 160 - 165
  • [42] Using functional analysis to determine the requirements for changes to critical systems: Railway level crossing case study
    Silmon, Joe
    Roberts, Clive
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2010, 95 (03) : 216 - 225
  • [43] Quantifying Satisfaction of Security Requirements of Cloud Software Systems
    Nhlabatsi, Armstrong
    Khan, Khaled M. D.
    Hong, Jin B.
    Kim, Dong Seong
    Fernandez, Rachael
    Fetais, Noora
    IEEE TRANSACTIONS ON CLOUD COMPUTING, 2023, 11 (01) : 426 - 444
  • [44] Deriving and Formalising Safety and Security Requirements for Control Systems
    Troubitsyna, Elena
    Vistbakka, Inna
    COMPUTER SAFETY, RELIABILITY, AND SECURITY (SAFECOMP 2018), 2018, 11093 : 107 - 122
  • [45] Security And Privacy Issues in Healthcare Monitoring Systems: A Case Study
    Handler, Daniel Tolboe
    Hauge, Lotte
    Spognardi, Angelo
    Dragoni, Nicola
    PROCEEDINGS OF THE 10TH INTERNATIONAL JOINT CONFERENCE ON BIOMEDICAL ENGINEERING SYSTEMS AND TECHNOLOGIES, VOL 5: HEALTHINF, 2017, : 383 - 388
  • [46] Enterprise Information Systems Security: A Case Study in the Banking Sector
    Chaudhry, Peggy E.
    Chaudhry, Sohail S.
    Clark, Kevin D.
    Jones, Darryl S.
    ENTERPRISE INFORMATION SYSTEMS OF THE FUTURE, 2013, 139 : 206 - 214
  • [47] Security Requirements Analysis Using Knowledge in CAPEC
    Kaiya, Haruhiko
    Kono, Sho
    Ogata, Shinpei
    Okubo, Takao
    Yoshioka, Nobukazu
    Washizaki, Hironori
    Kaijiri, Kenji
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, 2014, 178 : 343 - 348
  • [48] Systems theoretic process analysis of information security: the case of aadhaar
    Tarafdar, Pratik
    Bose, Indranil
    JOURNAL OF ORGANIZATIONAL COMPUTING AND ELECTRONIC COMMERCE, 2019, 29 (03) : 209 - 222
  • [49] A Survey on Security of Unmanned Aerial Vehicle Systems: Attacks and Countermeasures
    Wei, Xiaomin
    Ma, Jianfeng
    Sun, Cong
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (21): : 34826 - 34847
  • [50] Security and Privacy in IoT Systems: A Case Study of Healthcare Products
    Fazeldehkordi, Elahe
    Owe, Olaf
    Noll, Josef
    2019 13TH INTERNATIONAL SYMPOSIUM ON MEDICAL INFORMATION AND COMMUNICATION TECHNOLOGY (ISMICT), 2019, : 193 - 200