Analysis of Systems Security Engineering Design Principles for the Development of Secure and Resilient Systems

被引:5
|
作者
Beach, Paul M. [1 ]
Mailloux, Logan O. [1 ]
Langhals, Brent T. [1 ]
Mills, Robert F. [2 ]
机构
[1] US Air Force, Dept Syst Engn & Management, Inst Technol, Wright Patterson AFB, OH 45385 USA
[2] US Air Force, Dept Elect & Comp Engn, Inst Technol, Wright Patterson AFB, OH 45385 USA
关键词
Design principles; systems security engineering; security engineering;
D O I
10.1109/ACCESS.2019.2930718
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The increasing prevalence of cyber-attacks highlights the need for improved systems security analysis and engineering in safety-critical and mission-essential systems. Moreover, the engineering challenge of developing secure and resilient systems that meet specified constraints of cost, schedule, and performance is progressively difficult given the trend toward increasing complexity, interrelated systems-of-systems. This paper analyzes the 18 design principles presented in the National Institute of Standards and Technology Special Publication (NIST SP) 800-160 Volume 1 and considers their applicability for the development of secure and resilient systems of interest. The purpose of this work is to better understand how these design principles can be consistently and effectively employed to meet stakeholder defined security and resiliency needs as part of a comprehensive systems security engineering approach. Specifically, this work uses the Design Structure Matrix (DSM) analysis to study the 18 design principles presented in NIST SP 800-160 Vol. 1, Appendix F, along with their intra- and inter-dependencies to develop complex cyber-physical systems that are secure, trustworthy, and resilient. The DSM analysis results increase understanding of the various relationships between the 18 design principles and identifies two clusters for secure systems design: Architecture and Trust. Lastly, this work provides a notional command and control system case study, along with a detailed listing of engineering considerations, to demonstrate how these principles and their groupings can be systematically applied as part of a comprehensive approach for developing cyber-physical systems which are designed to operate in hostile environments.
引用
收藏
页码:101741 / 101757
页数:17
相关论文
共 50 条
  • [1] SoSPa: A System of Security Design Patterns for Systematically Engineering Secure Systems
    Nguyen, Phu H.
    Yskout, Koen
    Heyman, Thomas
    Klein, Jacques
    Scandariato, Riccardo
    Le Traon, Yves
    [J]. 2015 ACM/IEEE 18TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS (MODELS), 2015, : 246 - 255
  • [2] Secure Information Systems development -: Based on a security requirements engineering process
    Mellado, Daniel
    Fernandez-Medina, Eduardo
    Piattini, Mario
    [J]. SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : 467 - +
  • [3] Security patterns and secure systems design
    Fernandez, Eduardo B.
    [J]. Dependable Computing, Proceedings, 2007, 4746 : 233 - 234
  • [4] Secure Collaboration in Engineering Systems Design
    Wang, Shumiao
    Bhandari, Siddharth
    Chaduvula, Siva Chaitanya
    Atallah, Mikhail J.
    Panchal, Jitesh H.
    Ramani, Karthik
    [J]. JOURNAL OF COMPUTING AND INFORMATION SCIENCE IN ENGINEERING, 2017, 17 (04)
  • [5] SECURE COLLABORATION IN ENGINEERING SYSTEMS DESIGN
    Wang, Shumiao
    Bhandari, Siddharth
    Atallah, Mikhail
    Panchal, Jitesh H.
    Ramani, Karthik
    [J]. PROCEEDINGS OF THE ASME INTERNATIONAL DESIGN ENGINEERING TECHNICAL CONFERENCES AND COMPUTERS AND INFORMATION IN ENGINEERING CONFERENCE, 2014, VOL 1B, 2014,
  • [6] Tools for secure systems development with UML:: Security analysis with ATPs
    Jürjens, J
    Shabalin, P
    [J]. FUNDAMENTAL APPROACHES TO SOFTWARE ENGINEERING, PROCEEDINGS, 2005, 3442 : 305 - 309
  • [7] Engineering Resilient Systems: Achieving Stakeholder Value Through Design Principles and System Operations
    Specking, Eric
    Parnell, Gregory S.
    Pohl, Edward
    Buchanan, Randy
    [J]. IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2022, 69 (06) : 3982 - 3993
  • [8] Integrating security and systems engineering: Towards the modelling of secure information systems
    Mouratidis, H
    Giorgini, P
    Manson, G
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING, PROCEEDINGS, 2003, 2681 : 63 - 78
  • [9] Robust Engineering for the Design of Resilient Manufacturing Systems
    Mourtzis, Dimitris
    Angelopoulos, John
    Panopoulos, Nikos
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (07):
  • [10] Security Interpretations and Elaborations on Systems Engineering Principles
    Winstead, Mark
    [J]. INCOSE International Symposium, 2024, 34 (01) : 2476 - 2488