Safety-Focused Security Requirements Elicitation for Medical Device Software

被引:5
|
作者
Lindvall, Mikael [1 ]
Diep, Madeline [1 ]
Klein, Michele [1 ]
Jones, Paul [2 ]
Zhang, Yi [2 ]
Vasserman, Eugene [3 ]
机构
[1] Fraunhofer CESE, College Pk, MD USA
[2] US FDA, Silver Spring, MD USA
[3] Kansas State Univ, Manhattan, KS 66506 USA
关键词
Medical device safety and security; requirements elicitation; sequence based enumeration;
D O I
10.1109/RE.2017.21
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security attacks on medical devices have been shown to have potential safety concerns. Because of this, stakeholders (device makers, regulators, users, etc.) have increasing interest in enhancing security in medical devices. An effective means to approach this objective is to integrate systematic security requirements elicitation and analysis into the design and evaluation of medical device software. This paper extends the sequence-based enumeration approach, a systematic approach for defining the behavior of embedded software, to analyze the requirement documents of a medical device for the purpose of eliciting security requirements. As a proof of concept, we apply our approach on a concrete case study, which shows that the extended approach is useful for identifying sequences of medical device events that might be harmful to the patient, for example because the events are initiated by an active adversary trying to use the device in a malicious way. We then show how security requirements may be formulated based on the identified threats. By exploring these sequences systematically, the developers can reliably assess what, where, and how the security threats may manifest in their system, what the safety implications are, and finally they can evaluate the resulting requirements and mitigations.
引用
收藏
页码:134 / 143
页数:10
相关论文
共 50 条
  • [41] Security Requirements Elicitation from Airline Turnaround Processes
    Matulevicius, Raimundas
    Norta, Alex
    Samarutel, Silver
    BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2018, 60 (01): : 3 - 20
  • [42] A method of requirements elicitation and analysis for Global Software Development
    Ali, Naveed
    Lai, Richard
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2017, 29 (04)
  • [43] Use of Journey Maps and Personas in Software Requirements Elicitation
    Canedo, Edna Dias
    Calazans, Angelica Toffano Seidel
    Silva, Geovana Ramos Sousa
    Costa, Pedro Henrique Teixeira
    Masson, Eloisa Toffano Seidel
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2023, 33 (03) : 313 - 342
  • [44] Measuring Communication Gap in Software Requirements Elicitation Process
    Zin, Abdullah Mohd
    Pa, Noraini Che
    SEPADS'09: PROCEEDINGS OF THE 8TH WSEAS INTERNATIONAL CONFERENCE ON RECENT ADVANCES IN SOFTWARE ENGINEERING, PARALLEL AND DISTRIBUTED SYSTEMS, 2009, : 66 - 71
  • [45] Implementing web-surveys for software requirements elicitation
    Belani, H
    Pripuzic, K
    Kobas, K
    ConTEL 2005: Proceedings of the 8th International Conference on Telecommunications, Vols 1 and 2, 2005, : 465 - 469
  • [46] More on Elicitation of Software Requirements and Prioritization using AHP
    Sadiq, Mohd.
    Ahmed, Jawed
    Asim, Mohammad
    Qureshi, Aslam
    Suman, R.
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON DATA STORAGE AND DATA ENGINEERING (DSDE 2010), 2010, : 230 - 234
  • [47] Towards a Common Security and Privacy Requirements Elicitation Methodology
    Makri, Eleni-Laskarina
    Lambrinoudakis, Costas
    GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 151 - 159
  • [48] Security Requirements Elicitation from Airline Turnaround Processes
    Raimundas Matulevičius
    Alex Norta
    Silver Samarütel
    Business & Information Systems Engineering, 2018, 60 : 3 - 20
  • [49] Towards Goal-Oriented Software Requirements Elicitation
    Redouane, Abdesselam
    2021 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2021, : 596 - 599
  • [50] Data Security Challenges in AI-Enabled Medical Device Software
    Jayaneththi, Buddhika
    McCaffery, Fergal
    Regan, Gilbert
    2023 31ST IRISH CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COGNITIVE SCIENCE, AICS, 2023,