Risk-Oriented Security Engineering
dc.contributor.author | Ebert, Christof | |
dc.contributor.editor | Dencker, Peter | |
dc.contributor.editor | Klenk, Herbert | |
dc.contributor.editor | Keller, Hubert B. | |
dc.contributor.editor | Plödererder, Erhard | |
dc.date.accessioned | 2017-06-16T19:03:37Z | |
dc.date.available | 2017-06-16T19:03:37Z | |
dc.date.issued | 2017 | |
dc.description.abstract | Virtually every connected system will be attacked sooner or later. A 100% secure solution is not feasible. Therefore, advanced risk assessment and mitigation is the order of the day. Risk-oriented security engineering for automotive systems helps in both designing for robust systems as well as effective mitigation upon attacks or exploits of vulnerabilities. Security must be integrated early in the design phase of a vehicle to understand the threats and risks to car functions. The security analysis provides requirements and test vectors and adequate measures can be derived for balanced costs and efforts. The results are useful in the partitioning phase when functionality is distributed to ECUs and networks. We will show with concrete examples how risk-oriented cyber security can be successfully achieved in automotive systems. Three levers for automotive security are addressed: (1) Product, i.e., designing for security for components and the system, (2) Process, i.e., implementing cyber security concepts in the development process and (3) Field, i.e., ensuring security concepts are applied during service activities and effective during regular operations. | |
dc.identifier.isbn | 978-3-88579-663-3 | |
dc.identifier.pissn | 1617-5468 | |
dc.language.iso | en | |
dc.publisher | Gesellschaft für Informatik, Bonn | |
dc.relation.ispartof | Automotive - Safety & Security 2017 - Sicherheit und Zuverlässigkeit für automobile Informationstechnik | |
dc.relation.ispartofseries | Lecture Notes in Informatics (LNI) - Proceedings, Volume P-269 | |
dc.subject | Cyber Security | |
dc.subject | Safety | |
dc.subject | embedded systems | |
dc.subject | quality requirements | |
dc.subject | risk management | |
dc.subject | validation | |
dc.title | Risk-Oriented Security Engineering | |
dc.type | Text/Conference Paper | |
gi.citation.endPage | 44 | |
gi.citation.startPage | 27 | |
gi.conference.date | 30.-31. Mai 2017 | |
gi.conference.location | Stuttgart |
Dateien
Originalbündel
1 - 1 von 1