The platform will undergo maintenance on Sep 14 at about 7:45 AM EST and will be unavailable for approximately 2 hours.
2018 Annual IEEE International Systems Conference (SysCon) 2018
DOI: 10.1109/syscon.2018.8369539
|View full text |Cite
|
Sign up to set email alerts
|

A systems approach for eliciting mission-centric security requirements

Abstract: The security of cyber-physical systems is first and foremost a safety problem, yet it is typically handled as a traditional security problem, which means that solutions are based on defending against threats and are often implemented too late. This approach neglects to take into consideration the context in which the system is intended to operate, thus system safety may be compromised. This paper presents a systems-theoretic analysis approach that combines stakeholder perspectives with a modified version of Sy… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
20
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
4
1
1

Relationship

2
4

Authors

Journals

citations
Cited by 21 publications
(20 citation statements)
references
References 6 publications
(5 reference statements)
0
20
0
Order By: Relevance
“…Mailloux et al (2019) used the STPA-Sec to elicit systems security requirements for a notional autonomous space system. Carter et al (2018) used STPA-Sec with a previous information elicitation process to analyze a small reconnaissance unmanned aerial vehicles. A further modeling technique has also been proposed by the same researchers to support a more efficient and traceable analysis (Carter et al, 2019).…”
Section: Stpa-sec Applications and Gapsmentioning
confidence: 99%
“…Mailloux et al (2019) used the STPA-Sec to elicit systems security requirements for a notional autonomous space system. Carter et al (2018) used STPA-Sec with a previous information elicitation process to analyze a small reconnaissance unmanned aerial vehicles. A further modeling technique has also been proposed by the same researchers to support a more efficient and traceable analysis (Carter et al, 2019).…”
Section: Stpa-sec Applications and Gapsmentioning
confidence: 99%
“…The proposed metamodel is an integration of multiple technology areas into a unified ontology. This integration leverages advances in MBSE [48], safety through STAMP [49], and mission aware cybersecurity [7,17]. Mission aware is a systems engineering methodology that attempts to bridge system design with safety, security, and resilience.…”
Section: Literature Reviewmentioning
confidence: 99%
“…For example, in the field of safety, Leveson has developed systems-theoretic accident model and process (STAMP) [49], which examines safety incidents in terms of hierarchical control and unacceptable losses. In the intersection of security and resilience, there is System Aware [42,43] and its evolution Mission Aware [16,17], which see mitigation in terms of resilient modes in addition to traditional security defenses. Finally, the general field of model-based systems engineering (MBSE) has produced both methods and tools in assessing the safety and security posture of system designs and is the paradigm in which the majority of system models must conform to.…”
Section: Introductionmentioning
confidence: 99%
“…In our previous work, we describe how to generate the mission context information and how the model can be applied to vulnerability analysis . This paper instead focuses on applying the modeling methodology to use a case, assuming that all the information in the model is known ahead of time.…”
Section: Introductionmentioning
confidence: 99%
“…While this is a necessary characteristic of any good model, evaluating a vulnerability in the mission context, however, requires that specific, low‐level vulnerabilities within components can be traced to potentially compromised mission requirements. Therefore, we need a systematic process for modeling the mission context, the system architecture, and linking those two together …”
Section: Introductionmentioning
confidence: 99%