[论文解读] Inadequate Risk Analysis Might Jeopardize The Functional Safety of Modern Systems
本文提出在现有安全标准框架内,将安全意识整合到早期安全工程流程中,通过建立上下文和初步风险评估来识别安全威胁,而无需完全统一安全与安全学科。该方法通过主动应对可能危及安全关键系统的安全风险,增强了功能安全。
In the early 90s, researchers began to focus on security as an important property to address in combination with safety. Over the years, researchers have proposed approaches to harmonize activities within the safety and security disciplines. Despite the academic efforts to identify interdependencies and to propose combined approaches for safety and security, there is still a lack of integration between safety and security practices in the industrial context, as they have separate standards and independent processes often addressed and assessed by different organizational teams and authorities. Specifically, security concerns are generally not covered in any detail in safety standards potentially resulting in successfully safety-certified systems that still are open for security threats from e.g., malicious intents from internal and external personnel and hackers that may jeopardize safety. In recent years security has again received an increasing attention of being an important issue also in safety assurance, as the open interconnected nature of emerging systems makes them susceptible to security threats at a much higher degree than existing more confined products.This article presents initial ideas on how to extend safety work to include aspects of security during the context establishment and initial risk assessment procedures. The ambition of our proposal is to improve safety and increase efficiency and effectiveness of the safety work within the frames of the current safety standards, i.e., raised security awareness in compliance with the current safety standards. We believe that our proposal is useful to raise the security awareness in industrial contexts, although it is not a complete harmonization of safety and security disciplines, as it merely provides applicable guidance to increase security awareness in a safety context.
研究动机与目标
- 解决工业系统中安全与安全实践之间日益扩大的差距。
- 识别安全威胁如何在互联的现代系统中破坏安全性。
- 提出一种在安全关键系统开发过程中提升安全意识的实用方法。
- 在不需完全整合安全与安全标准的前提下,提高安全流程的有效性和效率。
- 支持在现有安全标准框架内工业界采纳安全考量。
提出的方法
- 扩展安全工程的上下文建立阶段,纳入与安全相关的因素。
- 将安全威胁建模整合到安全工程的初步风险评估过程中。
- 以现有安全标准为基础,确保合规性的同时增强安全意识。
- 提出一种轻量级、渐进式的方法,无需完全统一安全与安全学科。
- 专注于早期识别可能影响系统安全的安全威胁。
- 在不改变核心安全认证框架的前提下,将指导原则应用于现实世界的安全流程。
实验结果
研究问题
- RQ1如何在安全工程的早期阶段主动识别安全威胁?
- RQ2当前的安全标准在哪些方面未能应对可能危及系统安全的安全风险?
- RQ3在不完全整合安全与安全学科的前提下,如何可行地在现有安全流程中提升安全意识?
- RQ4如何系统性地将安全方面纳入上下文建立和初步风险评估?
- RQ5在现有标准下,将安全考量整合到安全关键系统开发中具有哪些实际影响?
主要发现
- 内部和外部人员造成的安全威胁在已通过安全认证的系统中常常被忽视,从而产生功能安全风险。
- 当前的安全标准未能充分应对安全问题,导致系统易受恶意行为的攻击。
- 所提出的方法能够在上下文建立和初步风险评估阶段实现对安全相关风险的早期检测。
- 该方法通过在不改变现有安全认证框架的前提下融入安全意识,增强了安全流程的鲁棒性。
- 该方法通过与现有安全标准和实践保持一致,支持工业界的采纳。
- 作者得出结论:即使仅部分整合安全到安全流程中,也能显著改善系统安全结果。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。