Software Security Assurance of Electrical Grid Systems Relating Mechatronics to Software Security Engineering

被引:0
|
作者
Axelrod, C. Warren [1 ]
机构
[1] Delta Risk LLC, Great Neck, NY 11023 USA
关键词
mechatronics; cyber-physical systems; industrial-control systems; cybersecurity; risk mitigation; system safety engineering; STPA-Sec; CMMI (R)-DEV plus SAFE and plus SECURE;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Mechatronics engineering addresses the design and development of correct and safe integrated mechanical, electronic control systems and embedded computers in the electrical energy and other industries. Many mechatronics engineers still concentrate on traditional approaches to the exclusion of security requirements for the gathering, processing, storing and distribution of data. This lack results in a dangerous gap in what engineers must address in order to ensure that modern electricity generation, transmission and distribution systems, such as comprise the smart grid, are properly protected. There is an increasing number of threats from inappropriate access to proprietary systems and data. Consequently, mechatronics engineers need to invoke software security assurance approaches, methods and tools to counteract these threats. Significant changes are needed in research, teaching and practice to ensure that systems are protected from external attackers as well as from inside staff with nefarious intentions. Unintentional actions are also damaging and must be addressed. Software security assurance is already established in the development lifecycles of many security-critical systems in other sectors, such as financial services. Within the electrical energy sector, however, while various authorities have stated the need to ensure that the sector's systems are secure from cyber attacks, the guidance given with such mandates is considered by some to be inadequate. Consequently, we need new, more effective models for securing the smart grid based on chains of command, team participation and the use of specific techniques. We first describe relevant research areas relating to the security of safety-critical systems. It is suggested that the lack of communication among these research areas is a major reason why progress has been so slow. We then suggest how various approaches might be applied to existing electrical grid software systems to achieve a higher level of cybersecurity assurance across current and new systems, such as those developed for electrical grids.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] Software Security Assurance of Telecommunication Systems
    Savola, Reijo M.
    [J]. 2009 INTERNATIONAL CONFERENCE ON MULTIMEDIA COMPUTING AND SYSTEMS (ICMCS 2009), 2009, : 138 - 143
  • [2] Towards Security Software Engineering the Smart Grid as a System of Systems
    Chiprianov, Vanea
    Gallon, Laurent
    Salameh, Khouloud
    Munier, Manuel
    El Hachem, Jamal
    [J]. 2015 10TH SYSTEM OF SYSTEMS ENGINEERING CONFERENCE (SOSE), 2015, : 77 - 82
  • [3] Software assurance for security
    McGraw, G
    [J]. COMPUTER, 1999, 32 (04) : 103 - 105
  • [4] Empirical Software Security Assurance
    Harper, Dave
    [J]. WEB APPLICATION SECURITY, 2010, 72 : 11 - 11
  • [5] Systems and Software Assurance - A Model Cyber Security Course
    Jovanovic, V.
    Harris, J. K.
    [J]. 2016 39TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2016, : 923 - 927
  • [6] Security requirements engineering for software systems: Case studies in support of software engineering education
    Mead, Nancy R.
    Hough, Eric D.
    [J]. 19TH CONFERENCE ON SOFTWARE ENGINEERING EDUCATION & TRAINING, PROCEEDINGS, 2006, : 149 - +
  • [7] Invited Talk: Software Engineering, AI and autonomous vehicles: Security assurance
    Zheng, James Xi
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS (PERCOM WORKSHOPS), 2020,
  • [8] Security in Software Engineering Requirement
    Al-Shorafat, Wafa Slaibi
    [J]. 2013 8TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2013, : 666 - 673
  • [9] Software Engineering, Smartphones and Health Systems, and Security Warnings
    Linden, Greg
    Ortega, Ruben
    Hong, Jason
    [J]. COMMUNICATIONS OF THE ACM, 2010, 53 (01) : 16 - 17
  • [10] A Special Issue for the Software Engineering and Software Security - Preface
    Shin, SY
    Gruner, S
    Kuo, TW
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2006, 22 (02)