Show simple item record

dc.contributor.authorSuo, Dajiang
dc.contributor.authorSiegel, Joshua E
dc.contributor.authorSarma, Sanjay E
dc.date.accessioned2018-11-16T20:45:09Z
dc.date.available2018-11-16T20:45:09Z
dc.date.issued2018
dc.identifier.issn1751-956X
dc.identifier.issn1751-9578
dc.identifier.urihttp://hdl.handle.net/1721.1/119161
dc.description.abstractWhen developing cyber-physical systems such as automated vehicles, safety and cybersecurity analyses are often conducted separately. However, unlike in the IT world, safety hazards and cybersecurity threats converge in cyber-physical systems; a malicious party can exploit cyber-threats to create extremely hazardous situations, whether in autonomous vehicles or nuclear plants. We propose a framework for integrated system-level analyses for functional safety and cyber security. We present a generic model named Threat Identification and Refinement for Cyber-Physical Systems (TIRCPS) extending Microsoft’s six classes of threat modelling including Spoofing, Tampering, Repudiation, Information Disclosure, Denial-of-Service and Elevation Privilege (STRIDE). TIRCPS introduces three benefits for developing complex systems: first, it allows the refinement of abstract threats into specific ones as physical design information becomes available; Second, the approach provides support for constructing attack trees with traceability from high-level goals and hazardous events to threats. Third, TIRCPS formalizes the definition of threats such that intelligent tools can be built to automatically detect most of a system’s vulnerable components requiring protection. We present a case study on an automated-driving system to illustrate the proposed approach. The analysis results of a hierarchical attack tree with cyber threats traceable to highlevel hazardous events are used to design mitigation solutions.en_US
dc.language.isoen_US
dc.publisherInstitution of Electrical Engineers (IEE)en_US
dc.relation.isversionofhttp://dx.doi.org/10.1049/iet-its.2018.5323en_US
dc.rightsCreative Commons Attribution-Noncommercial-Share Alikeen_US
dc.rights.urihttp://creativecommons.org/licenses/by-nc-sa/4.0/en_US
dc.sourceSubirana, Brianen_US
dc.titleMerging safety and cybersecurity analysis in product designen_US
dc.typeArticleen_US
dc.identifier.citationSuo, Dajiang, et al. “Merging Safety and Cybersecurity Analysis in Product Design.” IET Intelligent Transport Systems, vol. 12, no. 9, Nov. 2018, pp. 1103–09.en_US
dc.contributor.departmentMassachusetts Institute of Technology. Department of Mechanical Engineeringen_US
dc.contributor.approverSanjay E. Sarmaen_US
dc.contributor.mitauthorSuo, Dajiang
dc.contributor.mitauthorSiegel, Joshua E
dc.contributor.mitauthorSarma, Sanjay E
dc.relation.journalIET Intelligent Transport Systemsen_US
dc.eprint.versionAuthor's final manuscripten_US
dc.type.urihttp://purl.org/eprint/type/JournalArticleen_US
eprint.statushttp://purl.org/eprint/status/PeerRevieweden_US
dspace.orderedauthorsSuo, Dajiang; Siegel, Joshua E.; Sarma, Sanjay E.en_US
dspace.embargo.termsNen_US
dc.identifier.orcidhttps://orcid.org/0000-0003-3748-6115
dc.identifier.orcidhttps://orcid.org/0000-0002-5540-7401
dc.identifier.orcidhttps://orcid.org/0000-0003-2812-039X
mit.licenseOPEN_ACCESS_POLICYen_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record