STAMP-based Approach to Analyze Safety, Security and Data Privacy

被引:5
|
作者
de Souza, Nivio Paula [1 ]
Castro Cesar, Cecilia de Azevedo [1 ]
Bezerra, Juliana de Melo [1 ]
Hirata, Celso Massaki [1 ]
机构
[1] Inst Tecnol Aeronaut, Dept Comp Sci, Sao Jose Dos Campos, Brazil
关键词
STAMP; STPA; safety; security; privacy;
D O I
10.1109/ladc48089.2019.8995717
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Security has been of paramount importance to organizations since its lack can result in financial and reputational losses. Privacy is gaining attention because of the increasing legal protection of the right to data privacy. Due to their complexity, in terms of technology, sociology and law, assuring both security and privacy is a major challenge in the development of cyber-physical systems. In general, both security and privacy concerns are addressed by security countermeasures. There is no approach that employs the systems theory model to jointly identify and analyze security and privacy issues. STAMP is a causation model, based on systems theory, that allows analyzing emergent properties in the concept stage of system development. STPA is the tool based on STAMP to analyze safety. STPA has been employed to analyze more recently security. In this work, we propose an approach based on STAMP to analyze safety, security and privacy concerns jointly for cyber-physical systems. The approach uses attributes and threats of security and privacy to identify losses and hazards. We employ the approach in an example of electronic voting system development and we show that the approach is effective in identifying hazardous control actions.
引用
收藏
页码:181 / 190
页数:10
相关论文
共 50 条
  • [1] A STAMP-based ontology approach to support safety and security analyses
    Pereira, Daniel Patrick
    Hirata, Celso
    Nadjm-Tehrani, Simin
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 47 : 302 - 319
  • [2] A STAMP-based approach for designing maritime safety management systems
    Banda, Osiris A. Valdez
    Goerlandt, Floris
    SAFETY SCIENCE, 2018, 109 : 109 - 129
  • [3] STAMP-based Software Safety Verification
    Zhang Hong
    Li Xiaoxun
    PROCEEDINGS OF 2009 INTERNATIONAL SYMPOSIUM ON AIRCRAFT AIRWORTHINESS, 2009, : 479 - 483
  • [4] STAMP-based analysis of deepwater well control safety
    Meng, Xiangkun
    Chen, Guoming
    Shi, Jihao
    Zhu, Gaogeng
    Zhu, Yuan
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2018, 55 : 41 - 52
  • [5] Constructing Safety Management Systems in Modern Industry and Trade Enterprises: A STAMP-Based Approach
    Xu, Xiaomeng
    Li, Donghui
    Huang, Guojun
    Wang, Ziheng
    Zhu, Lingjie
    Ni, Xinyi
    SUSTAINABILITY, 2024, 16 (24)
  • [6] What do STAMP-based analysts expect from safety investigations?
    Stoop, John
    Benner, Ludwig, Jr.
    PROCEEDINGS OF THE 3RD EUROPEAN STAMP WORKSHOP, 2015, 128 : 93 - 102
  • [7] Application of STAMP-Based Safety Analysis on Navigation Software Development Management
    Xu, Xiaojie
    Zhong, Deming
    Lu, Minyan
    Bao, Xiaohong
    2013 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCES AND APPLICATIONS (CSA), 2013, : 214 - 218
  • [8] A STAMP-based approach to quantitative resilience assessment of chemical process systems
    Sun, Hao
    Wang, Haiqing
    Yang, Ming
    Reniers, Genserik
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2022, 222
  • [9] A time stamp-based algorithm to improve security and performance of mobile ad hoc network
    Ubarhande, S. D.
    Doye, D. D.
    Nalwade, P. S.
    WIRELESS NETWORKS, 2019, 25 (04) : 1867 - 1874
  • [10] A time stamp-based algorithm to improve security and performance of mobile ad hoc network
    S. D. Ubarhande
    D. D. Doye
    P. S. Nalwade
    Wireless Networks, 2019, 25 : 1867 - 1874