[논문 리뷰] Inadequate Risk Analysis Might Jeopardize The Functional Safety of Modern Systems
이 논문은 기존의 안전 기준 내에서 초기 안전 공 ing 과정에 보안 인식을 통합하는 것을 제안하며, 안전 및 보안 분야의 완전한 조율가능성을 요구하지 않고도 맥락 설정과 初기 위험 평가를 통해 보안 위협을 식별한다. 이 방법은 안전 기반 시스템의 기능적 안전성을 사전에 보완함으로써 향상시킨다.
In the early 90s, researchers began to focus on security as an important property to address in combination with safety. Over the years, researchers have proposed approaches to harmonize activities within the safety and security disciplines. Despite the academic efforts to identify interdependencies and to propose combined approaches for safety and security, there is still a lack of integration between safety and security practices in the industrial context, as they have separate standards and independent processes often addressed and assessed by different organizational teams and authorities. Specifically, security concerns are generally not covered in any detail in safety standards potentially resulting in successfully safety-certified systems that still are open for security threats from e.g., malicious intents from internal and external personnel and hackers that may jeopardize safety. In recent years security has again received an increasing attention of being an important issue also in safety assurance, as the open interconnected nature of emerging systems makes them susceptible to security threats at a much higher degree than existing more confined products.This article presents initial ideas on how to extend safety work to include aspects of security during the context establishment and initial risk assessment procedures. The ambition of our proposal is to improve safety and increase efficiency and effectiveness of the safety work within the frames of the current safety standards, i.e., raised security awareness in compliance with the current safety standards. We believe that our proposal is useful to raise the security awareness in industrial contexts, although it is not a complete harmonization of safety and security disciplines, as it merely provides applicable guidance to increase security awareness in a safety context.
연구 동기 및 목표
- 산업 시스템에서 안전과 보안 관행 간의 격차가 점점 커지는 데 대응하기 위해.
- 상호 연결된 현대 시스템에서 보안 위협이 안전에 어떻게 악영향을 미칠 수 있는지 밝히기 위해.
- 안전 중심 시스템 개발 기간 동안 보안 인식을 높이기 위한 실용적인 방법을 제안하기 위해.
- 안전 및 보안 기준의 완전한 통합이 필요 없이도 안전 프로세스의 효과성과 효율성을 향상시키기 위해.
- 기존 안전 기준 프레임워크 내에서 산업 현장에서 보안 고려사항을 도입하는 데를 지원하기 위해.
제안 방법
- 안전 공 ing의 맥락 설정 단계를 확장하여 보안 관련 요소를 포함한다.
- 안전 공 ing의 초기 위험 평가 프로세스에 보안 위협 모델링을 통합한다.
- 기존의 안전 기준을 기반으로 하여 준수를 확보하면서도 보안 인식을 향상시킨다.
- 안전 및 보안 분야의 완전한 조율가능성을 요구하지 않는 경량적이고 점진적인 접근법을 제안한다.
- 시스템 안전에 영향을 줄 수 있는 보안 위협을 초기 단계에서 식별하는 데 집중한다.
- 기본 안전 인증 프레임워크를 변경하지 않고도 실제 안전 프로세스에 지침을 적용한다.
실험 결과
연구 질문
- RQ1안전 공 ing의 초기 단계에서 보안 위협을 어떻게 사전에 식별할 수 있는가?
- RQ2현재의 안전 기준은 어떤 방식으로 안전을 위협할 수 있는 보안 위험을 충분히 다루지 못하는가?
- RQ3안전 및 보안 분야의 완전한 통합이 필요 없이도 기존 안전 프로세스 내에서 보안 인식을 높이기 위한 실현 가능한 방법은 무엇인가?
- RQ4어떻게 보안 측면을 맥락 설정 및 初기 위험 평가에 체계적으로 통합할 수 있는가?
- RQ5현재의 기준 하에 안전 중심 시스템 개발에 보안 고려사항을 통합할 경우 실질적인 영향은 무엇인가?
주요 결과
- 내부 및 외부 당사자로부터 온 보안 위협은 안전 인증 시스템에서 자주 간과되며, 이는 기능적 안전 위험을 초래한다.
- 현재의 안전 기준은 보안 문제를 충분히 다루지 않아 악성 행동으로부터 시스템이 취약해진다.
- 제안된 방법은 맥락 설정 및 초기 위험 평가 단계에서 보안 관련 위험을 조기에 탐지할 수 있도록 한다.
- 이 방법은 존재하는 안전 인증 프레임워크를 변경하지 않고도 보안 인식을 통합함으로써 안전 프로세스의 강건성을 높인다.
- 이 방법은 현재의 안전 기준 및 관행과 일치함으로써 산업 현장에서의 도입을 지원한다.
- 저자들은 조건부로라도 안전 공 ing 과정에 보안을 통합하는 것이 시스템 안전 결과에 상당한 개선 효과를 가져온다고 결론 내린다.
더 나은 연구,지금 바로 시작하세요
논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.
카드 등록 없음 · 무료 플랜 제공
이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.