Item type:Conference Paper,

Risk-Oriented Security Engineering

Loading...
Thumbnail Image

Fulltext URI

Document type

Text/Conference Paper

Additional Information

Date

relationships.isAuthorOf

Journal Title

Journal ISSN

Volume Title

Publisher

Gesellschaft für Informatik, Bonn

Abstract

Virtually every connected system will be attacked sooner or later. A 100% secure solution is not feasible. Therefore, advanced risk assessment and mitigation is the order of the day. Risk-oriented security engineering for automotive systems helps in both designing for robust systems as well as effective mitigation upon attacks or exploits of vulnerabilities. Security must be integrated early in the design phase of a vehicle to understand the threats and risks to car functions. The security analysis provides requirements and test vectors and adequate measures can be derived for balanced costs and efforts. The results are useful in the partitioning phase when functionality is distributed to ECUs and networks. We will show with concrete examples how risk-oriented cyber security can be successfully achieved in automotive systems. Three levers for automotive security are addressed: (1) Product, i.e., designing for security for components and the system, (2) Process, i.e., implementing cyber security concepts in the development process and (3) Field, i.e., ensuring security concepts are applied during service activities and effective during regular operations.

Description

Ebert, Christof (2017): Risk-Oriented Security Engineering. Automotive - Safety & Security 2017 - Sicherheit und Zuverlässigkeit für automobile Informationstechnik. Gesellschaft für Informatik, Bonn. PISSN: 1617-5468. ISBN: 978-3-88579-663-3. pp. 27-44. Stuttgart. 30.-31. Mai 2017

Keywords

Cyber Security, Safety, embedded systems, quality requirements, risk management, validation

Citation

DOI

URI

URI

Endorsement

Review

Supplemented By

Referenced By