[論文レビュー] Inadequate Risk Analysis Might Jeopardize The Functional Safety of Modern Systems
本稿では、既存の安全基準における安全工学の初期段階プロセスにセキュリティ意識を統合する手法を提案している。文脈の確立と初期リスク評価を用いて、安全とセキュリティの分野を完全に調和させる必要なく、セキュリティ脅威を特定する。このアプローチにより、将来的に安全に重点を置いたシステムの安全性が向上する。
In the early 90s, researchers began to focus on security as an important property to address in combination with safety. Over the years, researchers have proposed approaches to harmonize activities within the safety and security disciplines. Despite the academic efforts to identify interdependencies and to propose combined approaches for safety and security, there is still a lack of integration between safety and security practices in the industrial context, as they have separate standards and independent processes often addressed and assessed by different organizational teams and authorities. Specifically, security concerns are generally not covered in any detail in safety standards potentially resulting in successfully safety-certified systems that still are open for security threats from e.g., malicious intents from internal and external personnel and hackers that may jeopardize safety. In recent years security has again received an increasing attention of being an important issue also in safety assurance, as the open interconnected nature of emerging systems makes them susceptible to security threats at a much higher degree than existing more confined products.This article presents initial ideas on how to extend safety work to include aspects of security during the context establishment and initial risk assessment procedures. The ambition of our proposal is to improve safety and increase efficiency and effectiveness of the safety work within the frames of the current safety standards, i.e., raised security awareness in compliance with the current safety standards. We believe that our proposal is useful to raise the security awareness in industrial contexts, although it is not a complete harmonization of safety and security disciplines, as it merely provides applicable guidance to increase security awareness in a safety context.
研究の動機と目的
- 産業システムにおける安全とセキュリティの実践の間のギャップが拡大しているのを是正すること。
- 相互接続された現代のシステムにおいて、セキュリティ脅威が安全にどのように影響を与えるかを特定すること。
- 安全に重点を置いたシステム開発の段階でセキュリティ意識を高める実用的な手法を提案すること。
- 安全とセキュリティ基準の完全統合を要しないまま、安全プロセスの効果性と効率性を向上させること。
- 既存の安全基準の枠組み内で産業分野におけるセキュリティ検討の導入を支援すること。
提案手法
- 安全工学の文脈の確立段階を拡張し、セキュリティ関連要因を含める。
- 安全工学の初期リスク評価プロセスにセキュリティ脅威モデリングを統合する。
- 既存の安全基準を基盤とし、コンプライアンスを確保するとともにセキュリティ意識を高める。
- 安全とセキュリティの分野を完全に調和させる必要のない、軽量で段階的なアプローチを提案する。
- システムの安全性に影響を与える可能性のあるセキュリティ脅威を初期段階で特定することに焦点を当てる。
- 既存の安全認証フレームワークを変更せずに、実世界の安全プロセスにガイダンスを適用する。
実験結果
リサーチクエスチョン
- RQ1安全工学の初期段階で、どのようにしてセキュリティ脅威を事前に特定できるか?
- RQ2現在の安全基準は、システムの安全性を損なう可能性のあるセキュリティリスクをどのように不十分に扱っているか?
- RQ3安全とセキュリティの分野を完全に統合しないまま、既存の安全プロセス内でセキュリティ意識を高める実行可能な方法は何か?
- RQ4文脈の確立と初期リスク評価に、どのようにしてセキュリティ側面を体系的に組み込むことができるか?
- RQ5現在の基準下で、安全に重点を置いたシステム開発にセキュリティ検討を統合する際の実務的影響は何か?
主な発見
- 内部および外部の攻撃者によるセキュリティ脅威は、安全認証済みシステムでしばしば無視されており、機能的安全性のリスクを生じさせている。
- 現在の安全基準はセキュリティ懸念を十分に扱っておらず、悪意ある行動に対してシステムが脆弱である。
- 提案手法により、文脈の確立段階および初期リスク評価段階でセキュリティ関連リスクの早期検出が可能になる。
- 既存の安全認証フレームワークを変更せずに、セキュリティ意識を組み込むことで安全プロセスの頑健性が向上する。
- 既存の安全基準および実務に整合するため、産業分野での導入を支援する。
- 著者らは、安全プロセスへのセキュリティの部分的統合ですら、システムの安全結果を顕著に改善できることを結論づけている。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。