Skip to main content
QUICK REVIEW

[Paper Review] Inadequate Risk Analysis Might Jeopardize The Functional Safety of Modern Systems

Kaj Hänninen, Hans Hansson|arXiv (Cornell University)|Aug 30, 2018
Safety Systems Engineering in Autonomy20 references4 citations
TL;DR

This paper proposes integrating security awareness into early safety engineering processes within existing safety standards, using context establishment and initial risk assessment to identify security threats without requiring full harmonization of safety and security disciplines. The approach enhances functional safety by proactively addressing security risks that could otherwise compromise safety-critical systems.

ABSTRACT

In the early 90s, researchers began to focus on security as an important property to address in combination with safety. Over the years, researchers have proposed approaches to harmonize activities within the safety and security disciplines. Despite the academic efforts to identify interdependencies and to propose combined approaches for safety and security, there is still a lack of integration between safety and security practices in the industrial context, as they have separate standards and independent processes often addressed and assessed by different organizational teams and authorities. Specifically, security concerns are generally not covered in any detail in safety standards potentially resulting in successfully safety-certified systems that still are open for security threats from e.g., malicious intents from internal and external personnel and hackers that may jeopardize safety. In recent years security has again received an increasing attention of being an important issue also in safety assurance, as the open interconnected nature of emerging systems makes them susceptible to security threats at a much higher degree than existing more confined products.This article presents initial ideas on how to extend safety work to include aspects of security during the context establishment and initial risk assessment procedures. The ambition of our proposal is to improve safety and increase efficiency and effectiveness of the safety work within the frames of the current safety standards, i.e., raised security awareness in compliance with the current safety standards. We believe that our proposal is useful to raise the security awareness in industrial contexts, although it is not a complete harmonization of safety and security disciplines, as it merely provides applicable guidance to increase security awareness in a safety context.

Motivation & Objective

  • To address the growing gap between safety and security practices in industrial systems.
  • To identify how security threats can undermine safety in interconnected, modern systems.
  • To propose a practical method for raising security awareness during safety-critical system development.
  • To improve the effectiveness and efficiency of safety processes without requiring full integration of safety and security standards.
  • To support industrial adoption of security considerations within the framework of existing safety standards.

Proposed method

  • Extends the context establishment phase of safety engineering to include security-relevant factors.
  • Integrates security threat modeling into the initial risk assessment process of safety engineering.
  • Uses existing safety standards as the foundation, ensuring compliance while enhancing security awareness.
  • Proposes a lightweight, incremental approach that does not require full harmonization of safety and security disciplines.
  • Focuses on early-stage identification of security threats that could impact system safety.
  • Applies guidance to real-world safety processes without altering the core safety certification framework.

Experimental results

Research questions

  • RQ1How can security threats be proactively identified during the early stages of safety engineering?
  • RQ2In what ways do current safety standards fail to address security risks that may compromise system safety?
  • RQ3What is a feasible method to raise security awareness within existing safety processes without full integration of safety and security disciplines?
  • RQ4How can security aspects be systematically included in context establishment and initial risk assessment?
  • RQ5What are the practical implications of integrating security considerations into safety-critical system development under current standards?

Key findings

  • Security threats from internal and external actors are often overlooked in safety-certified systems, creating functional safety risks.
  • Current safety standards do not adequately address security concerns, leaving systems vulnerable to malicious actions.
  • The proposed method enables early detection of security-related risks during context establishment and initial risk assessment.
  • The approach increases the robustness of safety processes by incorporating security awareness without requiring changes to existing safety certification frameworks.
  • The method supports industrial adoption by aligning with current safety standards and practices.
  • The authors conclude that even partial integration of security into safety processes significantly improves system safety outcomes.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.