Merging safety and cybersecurity analysis in product design
When developing cyber-physical systems such as automated vehicles, safety and cybersecurity analyses are often conducted separately. However, unlike in the IT world, safety hazards and cybersecurity threats converge in cyber-physical systems; a malicious party can exploit cyber-threats to create ext...
Main Authors: | , , |
---|---|
Other Authors: | |
Format: | Article |
Language: | en_US |
Published: |
Institution of Electrical Engineers (IEE)
2018
|
Online Access: | http://hdl.handle.net/1721.1/119161 https://orcid.org/0000-0003-3748-6115 https://orcid.org/0000-0002-5540-7401 https://orcid.org/0000-0003-2812-039X |
_version_ | 1826191884194676736 |
---|---|
author | Suo, Dajiang Siegel, Joshua E Sarma, Sanjay E |
author2 | Massachusetts Institute of Technology. Department of Mechanical Engineering |
author_facet | Massachusetts Institute of Technology. Department of Mechanical Engineering Suo, Dajiang Siegel, Joshua E Sarma, Sanjay E |
author_sort | Suo, Dajiang |
collection | MIT |
description | When developing cyber-physical systems such as automated vehicles, safety and cybersecurity analyses are often conducted separately. However, unlike in the IT world, safety hazards and cybersecurity threats converge in cyber-physical systems; a malicious party can exploit cyber-threats to create extremely hazardous situations, whether in autonomous vehicles or nuclear plants. We propose a framework for integrated system-level analyses for functional safety and cyber security. We present a generic model named Threat Identification and Refinement for Cyber-Physical Systems (TIRCPS) extending Microsoft’s six classes of threat modelling including Spoofing, Tampering, Repudiation, Information Disclosure,
Denial-of-Service and Elevation Privilege (STRIDE). TIRCPS introduces three benefits for developing complex systems: first, it allows the refinement of abstract threats into specific ones as physical design information becomes available; Second, the approach provides support for constructing attack trees with traceability from high-level goals and hazardous events to threats. Third, TIRCPS formalizes the definition of threats such that intelligent tools can be built to automatically detect most of a system’s vulnerable components requiring protection. We present a case study on an automated-driving system to illustrate the proposed approach. The analysis results of a hierarchical attack tree with cyber threats traceable to highlevel hazardous events are used to design mitigation solutions. |
first_indexed | 2024-09-23T09:02:47Z |
format | Article |
id | mit-1721.1/119161 |
institution | Massachusetts Institute of Technology |
language | en_US |
last_indexed | 2024-09-23T09:02:47Z |
publishDate | 2018 |
publisher | Institution of Electrical Engineers (IEE) |
record_format | dspace |
spelling | mit-1721.1/1191612022-09-26T10:05:04Z Merging safety and cybersecurity analysis in product design Suo, Dajiang Siegel, Joshua E Sarma, Sanjay E Massachusetts Institute of Technology. Department of Mechanical Engineering Sanjay E. Sarma Suo, Dajiang Siegel, Joshua E Sarma, Sanjay E When developing cyber-physical systems such as automated vehicles, safety and cybersecurity analyses are often conducted separately. However, unlike in the IT world, safety hazards and cybersecurity threats converge in cyber-physical systems; a malicious party can exploit cyber-threats to create extremely hazardous situations, whether in autonomous vehicles or nuclear plants. We propose a framework for integrated system-level analyses for functional safety and cyber security. We present a generic model named Threat Identification and Refinement for Cyber-Physical Systems (TIRCPS) extending Microsoft’s six classes of threat modelling including Spoofing, Tampering, Repudiation, Information Disclosure, Denial-of-Service and Elevation Privilege (STRIDE). TIRCPS introduces three benefits for developing complex systems: first, it allows the refinement of abstract threats into specific ones as physical design information becomes available; Second, the approach provides support for constructing attack trees with traceability from high-level goals and hazardous events to threats. Third, TIRCPS formalizes the definition of threats such that intelligent tools can be built to automatically detect most of a system’s vulnerable components requiring protection. We present a case study on an automated-driving system to illustrate the proposed approach. The analysis results of a hierarchical attack tree with cyber threats traceable to highlevel hazardous events are used to design mitigation solutions. 2018-11-16T20:45:09Z 2018-11-16T20:45:09Z 2018 Article http://purl.org/eprint/type/JournalArticle 1751-956X 1751-9578 http://hdl.handle.net/1721.1/119161 Suo, Dajiang, et al. “Merging Safety and Cybersecurity Analysis in Product Design.” IET Intelligent Transport Systems, vol. 12, no. 9, Nov. 2018, pp. 1103–09. https://orcid.org/0000-0003-3748-6115 https://orcid.org/0000-0002-5540-7401 https://orcid.org/0000-0003-2812-039X en_US http://dx.doi.org/10.1049/iet-its.2018.5323 IET Intelligent Transport Systems Creative Commons Attribution-Noncommercial-Share Alike http://creativecommons.org/licenses/by-nc-sa/4.0/ application/pdf Institution of Electrical Engineers (IEE) Subirana, Brian |
spellingShingle | Suo, Dajiang Siegel, Joshua E Sarma, Sanjay E Merging safety and cybersecurity analysis in product design |
title | Merging safety and cybersecurity analysis in product design |
title_full | Merging safety and cybersecurity analysis in product design |
title_fullStr | Merging safety and cybersecurity analysis in product design |
title_full_unstemmed | Merging safety and cybersecurity analysis in product design |
title_short | Merging safety and cybersecurity analysis in product design |
title_sort | merging safety and cybersecurity analysis in product design |
url | http://hdl.handle.net/1721.1/119161 https://orcid.org/0000-0003-3748-6115 https://orcid.org/0000-0002-5540-7401 https://orcid.org/0000-0003-2812-039X |
work_keys_str_mv | AT suodajiang mergingsafetyandcybersecurityanalysisinproductdesign AT siegeljoshuae mergingsafetyandcybersecurityanalysisinproductdesign AT sarmasanjaye mergingsafetyandcybersecurityanalysisinproductdesign |