Software Security Assurance of Electrical Grid Systems Relating Mechatronics to Software Security Engineering

被引:0
|
作者
Axelrod, C. Warren [1 ]
机构
[1] Delta Risk LLC, Great Neck, NY 11023 USA
关键词
mechatronics; cyber-physical systems; industrial-control systems; cybersecurity; risk mitigation; system safety engineering; STPA-Sec; CMMI (R)-DEV plus SAFE and plus SECURE;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Mechatronics engineering addresses the design and development of correct and safe integrated mechanical, electronic control systems and embedded computers in the electrical energy and other industries. Many mechatronics engineers still concentrate on traditional approaches to the exclusion of security requirements for the gathering, processing, storing and distribution of data. This lack results in a dangerous gap in what engineers must address in order to ensure that modern electricity generation, transmission and distribution systems, such as comprise the smart grid, are properly protected. There is an increasing number of threats from inappropriate access to proprietary systems and data. Consequently, mechatronics engineers need to invoke software security assurance approaches, methods and tools to counteract these threats. Significant changes are needed in research, teaching and practice to ensure that systems are protected from external attackers as well as from inside staff with nefarious intentions. Unintentional actions are also damaging and must be addressed. Software security assurance is already established in the development lifecycles of many security-critical systems in other sectors, such as financial services. Within the electrical energy sector, however, while various authorities have stated the need to ensure that the sector's systems are secure from cyber attacks, the guidance given with such mandates is considered by some to be inadequate. Consequently, we need new, more effective models for securing the smart grid based on chains of command, team participation and the use of specific techniques. We first describe relevant research areas relating to the security of safety-critical systems. It is suggested that the lack of communication among these research areas is a major reason why progress has been so slow. We then suggest how various approaches might be applied to existing electrical grid software systems to achieve a higher level of cybersecurity assurance across current and new systems, such as those developed for electrical grids.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Software Security Requirements Engineering: State of the Art
    Ramachandran, Muthu
    [J]. GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 313 - 322
  • [42] Vulnerabilities and Threats in Cloud Software Engineering Security
    Yu, Weider D.
    Runiassy, Maryam
    Yin, Yijun
    [J]. INTELLIGENT SYSTEMS AND APPLICATIONS (ICS 2014), 2015, 274 : 1822 - 1831
  • [43] The Study on Network Security based on Software Engineering
    Jia Shande
    Ao Qian
    [J]. FOURTH INTERNATIONAL CONFERENCE ON DIGITAL IMAGE PROCESSING (ICDIP 2012), 2012, 8334
  • [44] Capturing security requirements for software systems
    El-Hadary, Hassan
    El-Kassas, Sherif
    [J]. JOURNAL OF ADVANCED RESEARCH, 2014, 5 (04) : 463 - 472
  • [45] SOFTWARE SECURITY
    WALSH, S
    [J]. DATA PROCESSING, 1983, 25 (03): : 9 - 10
  • [46] SOFTWARE SECURITY
    PALME, J
    [J]. DATAMATION, 1974, 20 (01): : 51 - 55
  • [47] Software Security
    Sametinger, Johannes
    [J]. 2013 20TH ANNUAL IEEE INTERNATIONAL CONFERENCE AND WORKSHOPS ON THE ENGINEERING OF COMPUTER BASED SYSTEMS (ECBS 2013), 2013, : 216 - 216
  • [48] Software security
    McGraw, G
    [J]. IEEE SECURITY & PRIVACY, 2004, 2 (02) : 80 - 83
  • [49] SOFTWARE SECURITY
    WALSH, ME
    [J]. JOURNAL OF SYSTEMS MANAGEMENT, 1981, 32 (10): : 6 - 13
  • [50] Verified Hardware/Software Co-Assurance: Enhancing Safety and Security for Critical Systems
    Hardin, David S.
    [J]. 2020 14TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON2020), 2020,