论文标题

基于数据流的安全性安全过程分析的扩展(STPA-SEC)

Data-Flow-Based Extension of the System-Theoretic Process Analysis for Security (STPA-Sec)

论文作者

Yu, Jinghua, Wagner, Stefan, Luo, Feng

论文摘要

安全分析是安全工程中的重要活动,以确定潜在的系统漏洞并在早期设计阶段达到安全要求。由于现代系统的复杂性日益增加,传统方法仅考虑组件故障和简单的因果关系,因此缺乏识别由物理系统,人类和社会实体之间复杂相互作用引起的不安全事件的能力。相比之下,对安全性的自上而下的系统理论过程分析(STPA-SEC)方法将损失视为互动导致的损失,专注于控制系统脆弱性而不是外部威胁,并且适用于复杂的社会技术系统。在本文中,我们根据数据流结构提出了STPA-SEC的扩展,以克服STPA-SEC的局限性并系统地实现信息关键系统的安全限制。我们通过使用拟议的和原始方法来研究两种方法之间的关系和差异,以及它们的适用性和突出显示,我们分析了车辆的蓝牙数字密钥系统。总而言之,所提出的方法可以通过技术细节确定更多与信息相关的问题,并与统一STPA流程框架下的多学科中的其他基于STPA的方法一起使用。

Security analysis is an essential activity in security engineering to identify potential system vulnerabilities and achieve security requirements in the early design phases. Due to the increasing complexity of modern systems, traditional approaches, which only consider component failures and simple cause-and-effect linkages, lack the power to identify insecure incidents caused by complex interactions among physical systems, human and social entities. By contrast, a top-down System-Theoretic Process Analysis for Security (STPA-Sec) approach views losses as resulting from interactions, focuses on controlling system vulnerabilities instead of external threats and is applicable for complex socio-technical systems. In this paper, we proposed an extension of STPA-Sec based on data flow structures to overcome STPA-Sec's limitations and achieve security constraints of information-critical systems systematically. We analyzed a Bluetooth digital key system of a vehicle by using both the proposed and the original approach to investigate the relationship and differences between both approaches as well as their applicability and highlights. To conclude, the proposed approach can identify more information-related problems with technical details and be used with other STPA-based approaches to co-design systems in multi-disciplines under the unified STPA process framework.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源