Logo des Repositoriums
 
Konferenzbeitrag

Risk-Oriented Security Engineering

Lade...
Vorschaubild

Volltext URI

Dokumententyp

Text/Conference Paper

Zusatzinformation

Datum

2017

Zeitschriftentitel

ISSN der Zeitschrift

Bandtitel

Verlag

Gesellschaft für Informatik, Bonn

Zusammenfassung

Virtually every connected system will be attacked sooner or later. A 100% secure solution is not feasible. Therefore, advanced risk assessment and mitigation is the order of the day. Risk-oriented security engineering for automotive systems helps in both designing for robust systems as well as effective mitigation upon attacks or exploits of vulnerabilities. Security must be integrated early in the design phase of a vehicle to understand the threats and risks to car functions. The security analysis provides requirements and test vectors and adequate measures can be derived for balanced costs and efforts. The results are useful in the partitioning phase when functionality is distributed to ECUs and networks. We will show with concrete examples how risk-oriented cyber security can be successfully achieved in automotive systems. Three levers for automotive security are addressed: (1) Product, i.e., designing for security for components and the system, (2) Process, i.e., implementing cyber security concepts in the development process and (3) Field, i.e., ensuring security concepts are applied during service activities and effective during regular operations.

Beschreibung

Ebert, Christof (2017): Risk-Oriented Security Engineering. Automotive - Safety & Security 2017 - Sicherheit und Zuverlässigkeit für automobile Informationstechnik. Gesellschaft für Informatik, Bonn. PISSN: 1617-5468. ISBN: 978-3-88579-663-3. pp. 27-44. Stuttgart. 30.-31. Mai 2017

Zitierform

DOI

Tags