首页> 外文会议>10th IET System Safety and Cyber-Security Conference 2015 >Combined security and safety risk assessment — What needs to be done for ICS and the IoT
【24h】

Combined security and safety risk assessment — What needs to be done for ICS and the IoT

机译:结合的安全和安全风险评估-ICS和IoT需要做什么

获取原文
获取原文并翻译 | 示例

摘要

Industrial Control Systems (ICS) are now routinely connected to other networks to optimise business efficiency. Designs for safety and security risk treatment measures may conflict and cannot be designed in isolation yet we find there are still problems in combining them. If a CEO were to ask his safety engineer and his security engineer of a complex, networked, software-intensive system to produce a combined security and safety risk assessment, there is no industry-recognised method to do so. We believe that Systems Engineering techniques can combine safety and security requirements to help avoid `hazardous system states', by design. However, such systems are too complex to be modelled reliably, which can lead to safety and security design failures; it is impractical to identify all their vulnerabilities and, being networked, such systems evolve, so new vulnerabilities can emerge; finally, current methodologies may not adequately address the intelligent adversary. Therefore, we believe that a `re-imagining' of approaches to safety and security risk assessment is needed to deal with such systems. We aim to expose the issues so that both communities can develop a lingua franca as the foundation for the further work that we identify.
机译:现在,工业控制系统(ICS)通常与其他网络相连,以优化业务效率。安全和安保风险处理措施的设计可能会发生冲突,不能孤立设计,但我们发现将它们组合仍然存在问题。如果首席执行官要他的安全工程师和他的安全工程师使用复杂的网络化软件密集型系统来进行组合的安全和安全风险评估,则没有业内公认的方法。我们认为,系统工程技术可以将安全要求与安全要求相结合,从而通过设计避免出现“危险的系统状态”。但是,这样的系统太复杂而无法可靠地建模,这可能导致安全性和安全性设计失败。识别它们的所有漏洞是不切实际的,并且通过网络将此类系统演化,因此可能会出现新的漏洞;最后,当前的方法论可能不足以解决聪明的对手。因此,我们认为,应对此类系统需要对安全和保安风险评估方法进行“重新想象”。我们的目的是揭露这些问题,以便两个社区都能发展一种通用语言,作为我们确定的进一步工作的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号