Data-flow-based adaption of the System-Theoretic Process Analysis for Security (STPA-Sec)

نویسندگان

چکیده

Security analysis is an essential activity in security engineering to identify potential system vulnerabilities and specify requirements the early design phases. Due increasing complexity of modern systems, traditional approaches lack power insecure incidents caused by complex interactions among physical human social entities. By contrast, System-Theoretic Process Analysis for (STPA-Sec) approach views losses as resulting from interactions, focuses on controlling instead external threats, applicable socio-technical systems. However, STPA-Sec pays less attention non-safety but information-security issues (e.g., data confidentiality) lacks efficient guidance identifying information concepts. In this article, we propose a data-flow-based adaption (named STPA-DFSec) overcome mentioned limitations elicit constraints systematically. We use STPA-DFSec analyze vehicle digital key investigate relationship differences between both approaches, their applicability, highlights. To conclude, proposed can information-related problems more directly processing aspect. As STPA-Sec, it be used with other STPA-based co-design systems multi-disciplines under unified STPA framework.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

consequence analysis of the leakage, ignition and explosion during high pressure sour gas injection process to the oil reservoir

there is no doubt that human being needs to become integrated with industry and industry needs to be progressed, daily. on the other hand, serious events in industrial units specially in oil industries has been shown that such damages and events are industry related ones. the consequence of such events and damages which resulted in chemical and poisoned explosions and loss of life and property ...

STPA-SafeSec: Safety and security analysis for cyber-physical systems

Cyber-physical systems tightly integrate physical processes and information and communication technologies. As today’s critical infrastructures, e.g., the power grid or water distribution networks, are complex cyber-physical systems, ensuring their safety and security becomes of paramount importance.Traditional safety analysis methods, such as HAZOP, are ill-suited to assess these systems. Furt...

متن کامل

a time-series analysis of the demand for life insurance in iran

با توجه به تجزیه و تحلیل داده ها ما دریافتیم که سطح درامد و تعداد نمایندگیها باتقاضای بیمه عمر رابطه مستقیم دارند و نرخ بهره و بار تکفل با تقاضای بیمه عمر رابطه عکس دارند

SW-STPA: A Software Hazard Analysis Technique based on STPA

As the uses of software are various, software is germane to human's life and property. Thus, the importance of software safety increases rapidly and many hazard analysis techniques are used for safety of system/software. STAMP/STPA is an efficient hazard analysis technique for large and complex system. But subject of STAMP/STPA is system, not software. This difference of subjects makes difficul...

متن کامل

a gender-based pragmatic analysis of the use of english compliment responses by iraqi efl students:a speech act perspective

تعارفات کنش های گفتاری هستند که افراد در زندگی روزمر? خود به منظور برقراری دوستی یا تداوم روابط مسالمت آمیز به کار می برند. ساز و کار تعارف مختص زبان انگلیسی یا هر زبان دیگری نیست و پدیده ای است جهانی و در همه زبانها حضور دارد. تفاوتی که از این نظر در زبانها و فرهنگ ها وجود دارد مربوط به پاسخ به این کنش گفتاری در گفتمان است. این مطالعه به بررسی تنوع پاسخ های انگلیسی و عربی به کنش گفتاری تعارف د...

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: PeerJ

سال: 2021

ISSN: ['2167-8359']

DOI: https://doi.org/10.7717/peerj-cs.362