Data-Flow-Based Extension of the System-Theoretic Process Analysis for Security (STPA-Sec)

06/04/2020
by   Jinghua Yu, et al.
0

Security analysis is an essential activity in security engineering to identify potential system vulnerabilities and achieve security requirements in the early design phases. Due to the increasing complexity of modern systems, traditional approaches, which only consider component failures and simple cause-and-effect linkages, lack the power to identify insecure incidents caused by complex interactions among physical systems, human and social entities. By contrast, a top-down System-Theoretic Process Analysis for Security (STPA-Sec) approach views losses as resulting from interactions, focuses on controlling system vulnerabilities instead of external threats and is applicable for complex socio-technical systems. In this paper, we proposed an extension of STPA-Sec based on data flow structures to overcome STPA-Sec's limitations and achieve security constraints of information-critical systems systematically. We analyzed a Bluetooth digital key system of a vehicle by using both the proposed and the original approach to investigate the relationship and differences between both approaches as well as their applicability and highlights. To conclude, the proposed approach can identify more information-related problems with technical details and be used with other STPA-based approaches to co-design systems in multi-disciplines under the unified STPA process framework.

READ FULL TEXT
research
06/16/2020

An STPA-based Approach for Systematic Security Analysis of In-vehicle Diagnostic and Software Update Systems

The in-vehicle diagnostic and software update system, which supports rem...
research
11/02/2017

A Systems Approach for Eliciting Mission-Centric Security Requirements

The security of cyber-physical systems is first and foremost a safety pr...
research
09/11/2022

Systems-theoretic Hazard Analysis of Digital Human-System Interface Relevant to Reactor Trip

Human-system interface is one of the key advanced design features applie...
research
11/30/2022

Quantitative Information Flow for Hardware: Advancing the Attack Landscape

Security still remains an afterthought in modern Electronic Design Autom...
research
09/06/2021

QFlow: Quantitative Information Flow for Security-Aware Hardware Design in Verilog

The enormous amount of code required to design modern hardware implement...
research
09/19/2021

Architecture and Its Vulnerabilities in Smart-Lighting Systems

Industry 4.0 embodies one of the significant technological changes of th...
research
08/03/2023

Tool-Supported Architecture-Based Data Flow Analysis for Confidentiality

Through the increasing interconnection between various systems, the need...

Please sign up or login with your details

Forgot password? Click here to reset