Show simple item record

dc.contributor.advisorNancy G. Leveson.en_US
dc.contributor.authorHelfer, Jonasen_US
dc.contributor.otherMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Science.en_US
dc.date.accessioned2016-07-18T20:05:48Z
dc.date.available2016-07-18T20:05:48Z
dc.date.copyright2016en_US
dc.date.issued2016en_US
dc.identifier.urihttp://hdl.handle.net/1721.1/103744
dc.descriptionThesis: S.M., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2016.en_US
dc.descriptionCataloged from PDF version of thesis.en_US
dc.descriptionIncludes bibliographical references (pages 44-45).en_US
dc.description.abstractField Loadable Software in commercial aviation is indispensable for vital avionics functions yet its security has never been studied in depth. Due to the recent introduction of wireless software loading capabilities and Internet-connected in-flight entertainment systems along with several high-profile information security breaches in other sectors, the security of Field Loadable software has come under closer scrutiny. Conventional information systems security analysis approaches focus on finding and preventing vulnerabilities in the implementation of a system, but they are not designed to include the organizational "soft" components of a system. The aim of this thesis is to provide a comprehensive security analysis of Field Loadable Software that includes organizational aspects in order to find existing vulnerabilities and propose security constraints that would fix the vulnerabilities or prevent them from being exploited. A novel safety approach from safety engineering, called Systems Theoretic Process Analysis (STPA) was adapted and used to perform the security analysis of Field Loadable Software in commercial aviation. The analysis produced a simple systems model for Field Loadable Software and found that current regulations and practices are not sufficient: there several significant vulnerabilities in the way Field Loadable Software is currently designed and distributed. However, the analysis also showed that the vulnerabilities could be removed with the addition of simple technical measures and security constraints.en_US
dc.description.statementofresponsibilityby Jonas Helfer.en_US
dc.format.extent71, [1] pagesen_US
dc.language.isoengen_US
dc.publisherMassachusetts Institute of Technologyen_US
dc.rightsM.I.T. theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. See provided URL for inquiries about permission.en_US
dc.rights.urihttp://dspace.mit.edu/handle/1721.1/7582en_US
dc.subjectElectrical Engineering and Computer Science.en_US
dc.titleA systems approach to software security in aviationen_US
dc.typeThesisen_US
dc.description.degreeS.M.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
dc.identifier.oclc953582716en_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record