Skip to main content

2015 | OriginalPaper | Buchkapitel

Safe & Sec Case Patterns

verfasst von : Kenji Taguchi, Daisuke Souma, Hideaki Nishihara

Erschienen in: Computer Safety, Reliability, and Security

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Many industrial sectors, which manufacture safety intensive systems e.g., automotive, railway, etc., now face technical challenges on how to integrate and harmonize critical issues on safety in addition to security for their systems. In this paper, we will explore a new way of reconciling those issues in an argument form, which we call Safe & Sec (Safety and Security) case patterns. They are derived from process patterns identified from our literature survey on research and standards. Safe & Sec case patterns in this paper will provide practitioners a wide perspective and baseline on how they could provide an assurance framework for their safety intensive systems with security focus.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Alexander, R., Hawkins, R., Kelly, T.: Security assurance cases: Motivation and the state of the art. Department of Computer Science, University of York, Technical report (2011) Alexander, R., Hawkins, R., Kelly, T.: Security assurance cases: Motivation and the state of the art. Department of Computer Science, University of York, Technical report (2011)
2.
Zurück zum Zitat Bieber, P., Blanquart, J.P., Descargues, G., Dulucq, M., Fourastier, Y., Hazane, E., Julien, M., Léonardon, L., Sarouille, G.: Security and safety assurance for aerospace embedded systems. In: Proceedings of the 6th International Conference on Embedded Real Time Software and Systems, ERTS 2012, pp. 1–10 (2012) Bieber, P., Blanquart, J.P., Descargues, G., Dulucq, M., Fourastier, Y., Hazane, E., Julien, M., Léonardon, L., Sarouille, G.: Security and safety assurance for aerospace embedded systems. In: Proceedings of the 6th International Conference on Embedded Real Time Software and Systems, ERTS 2012, pp. 1–10 (2012)
3.
Zurück zum Zitat Bloomfield, R., Netkachova, K., Stroud, R.: Security-informed safety: if it’s not secure, it’s not safe. In: Gorbenko, A., Romanovsky, A., Kharchenko, V. (eds.) SERENE 2013. LNCS, vol. 8166, pp. 17–32. Springer, Heidelberg (2013) CrossRef Bloomfield, R., Netkachova, K., Stroud, R.: Security-informed safety: if it’s not secure, it’s not safe. In: Gorbenko, A., Romanovsky, A., Kharchenko, V. (eds.) SERENE 2013. LNCS, vol. 8166, pp. 17–32. Springer, Heidelberg (2013) CrossRef
4.
Zurück zum Zitat Boran, L.: Automotive cyber-security. In: Escar Europe (2013) Boran, L.: Automotive cyber-security. In: Escar Europe (2013)
5.
Zurück zum Zitat Born, M.: An approach to safety and security analysis for automotive systems. In: SAE 2014 World Congress and Exhibition (2014) Born, M.: An approach to safety and security analysis for automotive systems. In: SAE 2014 World Congress and Exhibition (2014)
6.
Zurück zum Zitat Goodenough, J., Lipson, H.F., Weinstock, C.B.: Arguing security - creating security assurance cases. Technical report SEI/CMU (2014) Goodenough, J., Lipson, H.F., Weinstock, C.B.: Arguing security - creating security assurance cases. Technical report SEI/CMU (2014)
7.
Zurück zum Zitat IEC 62280:2014: Railway applications - Communication, signaling and processing systems -Safety related communication in transmission systems (2014) IEC 62280:2014: Railway applications - Communication, signaling and processing systems -Safety related communication in transmission systems (2014)
8.
Zurück zum Zitat IEC61025: Fault tree analysis (FTA) (2006) IEC61025: Fault tree analysis (FTA) (2006)
9.
Zurück zum Zitat ISO26262:2011: Road Vehicle - Functional Safety -, Part 1 to Part 9 (2011) ISO26262:2011: Road Vehicle - Functional Safety -, Part 1 to Part 9 (2011)
10.
Zurück zum Zitat ISO/IEC 15408: Common Criteria for Information Technology Security Evaluation (2012) ISO/IEC 15408: Common Criteria for Information Technology Security Evaluation (2012)
11.
Zurück zum Zitat Kelly, T.: Arguing Safety - A Systematic Approach to Safety Case Management. Ph.D. thesis, Department of Computer Science, University of York (1998) Kelly, T.: Arguing Safety - A Systematic Approach to Safety Case Management. Ph.D. thesis, Department of Computer Science, University of York (1998)
13.
Zurück zum Zitat Praxis: SafSec: Integration of Safety & Security Certification, SafSec Methodology: Guidance Material (2006) Praxis: SafSec: Integration of Safety & Security Certification, SafSec Methodology: Guidance Material (2006)
14.
Zurück zum Zitat Praxis: SafSec: Integration of Safety & Security Certification, SafSec Methodology: Standard (2006) Praxis: SafSec: Integration of Safety & Security Certification, SafSec Methodology: Standard (2006)
15.
Zurück zum Zitat RTCA DO-326A: Airworthiness Security Process Specification (2014) RTCA DO-326A: Airworthiness Security Process Specification (2014)
16.
Zurück zum Zitat SAE: Cybersecurity Guidebook for Cyber-Physical Automotive Systems SAE: Cybersecurity Guidebook for Cyber-Physical Automotive Systems
17.
Zurück zum Zitat Schneier, B.: Attack Trees. Dr. Dobbs Journal (1996) Schneier, B.: Attack Trees. Dr. Dobbs Journal (1996)
19.
Zurück zum Zitat Steiner, M., Liggesmeyer, P.: Combination of safety and security analysis - finding security problems that threaten the safety of a system. In: Workshop DECS (ERCIM/EWICS Workshop on Dependable Embedded and Cyber-Physical Systems) (2013) Steiner, M., Liggesmeyer, P.: Combination of safety and security analysis - finding security problems that threaten the safety of a system. In: Workshop DECS (ERCIM/EWICS Workshop on Dependable Embedded and Cyber-Physical Systems) (2013)
20.
Zurück zum Zitat UK Ministory of Defence: Defence standard 00–56: Safety management requirements for defence systems (2004) UK Ministory of Defence: Defence standard 00–56: Safety management requirements for defence systems (2004)
Metadaten
Titel
Safe & Sec Case Patterns
verfasst von
Kenji Taguchi
Daisuke Souma
Hideaki Nishihara
Copyright-Jahr
2015
DOI
https://doi.org/10.1007/978-3-319-24249-1_3