A Security Engineering Process for Systems of Systems using Security Patterns

被引:0
|
作者
Ruiz, Jose Fran [1 ]
Rudolph, Carsten [1 ]
Mana, Antonio [2 ]
Arjona, Marcos [2 ]
机构
[1] Fraunhofer SIT, Darmstadt, Germany
[2] Univ Malaga, Malaga, Spain
关键词
security engineering process; engineering systems of systems; Model-based systems engineering; Research in systems engineering;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The creation of secure systems of systems is a complex process. A large variety of security expertise and knowledge specific for application domains is required. This is even more important if systems of systems span different application domains. Then, security threats specific to different application-domains need to be considered. One example is integrated systems for industrial production processes that interface office domains with supply chain management systems as well as a production environment. Such integrated systems of systems can perform very efficient and economic processes. However, due to the many and different domain-specific security requirements and threats security engineering needs to support requirements specification and architecture design very early in the development process in order to ensure resilience and safety of the complete system. Working with different domains implies that properties and its functionalities are specific and the engineering process used for modeling and designing the complete system has to be able to work in this context, covering all the possibilities and allowing the use of trusted solutions that are compatible with the ones of different domains. We present in this paper a security engineering process for creating secure systems of systems that cover the necessities presented above by using a series of security artifacts that contain the domain-specific security information (in terms of security properties) and provide security solutions in the form of security patterns. These patterns contain the definition of the software/hardware elements used for providing the required solution and the information of related patterns for different domains, which provides a very helpful functionality for creating a system of systems.
引用
收藏
页码:8 / 11
页数:4
相关论文
共 50 条
  • [21] Security patterns and secure systems design
    Fernandez, Eduardo B.
    [J]. Dependable Computing, Proceedings, 2007, 4746 : 233 - 234
  • [22] Providing security for automated process control systems at hydropower engineering facilities
    Vasiliev Y.S.
    Zegzhda P.D.
    Zegzhda D.P.
    [J]. Zegzhda, P.D. (zeg@ibks.ftk.spbstu.ru), 1600, Izdatel'stvo Nauka (63): : 948 - 956
  • [23] Integrated Vehicular Security Engineering Towards A Holistic Security-Integrated Development Process for Vehicular IT Systems
    Paus, Annika
    Vandersee, Daniel
    Wolf, Marko
    [J]. AUTOMOTIVE SECURITY, 2011, 2011, 2131 : 125 - 136
  • [24] Using Process Mining and Model-driven Engineering to Enhance Security of Web Information Systems
    Bernardi, Simona
    Piraces Alastuey, Raul
    Trillo-Lado, Raquel
    [J]. 2017 2ND IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW), 2017, : 160 - 166
  • [25] Quantitative evaluation of systems with security patterns using a fuzzy approach
    Halkidis, Spyros T.
    Chatzigeorgiou, Alexander
    Stephanides, George
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: OTM 2006 WORKSHOPS, PT 1, PROCEEDINGS, 2006, 4277 : 554 - +
  • [26] IT SYSTEMS SECURITY MANAGEMENT IN MIGRATION PROCESS
    Pieta, Sylwester
    [J]. FOUNDATIONS OF MANAGEMENT, 2010, 2 (02) : 63 - 80
  • [27] Trends in process control systems security
    Miller, A
    [J]. IEEE SECURITY & PRIVACY, 2005, 3 (05) : 57 - 60
  • [28] A network security architectural approach for systems integrity using multi agent systems engineering
    Torrellas, GAS
    [J]. I-SPAN 2004: 7TH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND NETWORKS, PROCEEDINGS, 2004, : 600 - 606
  • [29] The Security Process Model of Embedded Systems
    Choi, Shin-Hyeong
    [J]. GRID AND DISTRIBUTED COMPUTING, 2011, 261 : 329 - 334
  • [30] Security for Process Control Systems An Overview
    Brandle, Markus
    Naedele, Martin
    [J]. IEEE SECURITY & PRIVACY, 2008, 6 (06) : 24 - 29