{"title":"Secure Engineering and Modelling of a Metering Devices System","authors":"J. Ruiz, M. Arjona, A. Maña, N. Carstens","doi":"10.1109/ARES.2013.56","DOIUrl":null,"url":null,"abstract":"This paper presents a security engineering process for the modelling of security-sensitive systems using a real use case of metering devices. The process provides a security framework that can be used with other existing processes (such as the agile ones). It helps to develop and model systems bearing in mind their heterogeneity, real-time and dynamic behaviors. Besides, due to the critical nature of some of these systems (nuclear, emergency systems, military, etc.) it provides tools for identifying, working and solving security threats by using the knowledge of domain experts. This is very important because threats, properties, solutions, etc. that are valid or relevant in a given domain, are not applicable to other domains and are subject to constant changes. The security requirements of the systems are fulfilled by means of domain-specific security knowledge. These artefacts contain the specific information of a domain (security properties, elements, assumptions, threats, tests, etc.). The solutions are presented as Security Patterns. Each one describes an implementation solution by using one or several Security Building Blocks (SBBs). The security engineering process presented here describes how to model a security-enhanced system model using a library of domain security knowledge. The process has been developed along with a Magic Draw plugin that covers all the possible functionalities, making the work with the models and the security elements very simple and easy for the user.","PeriodicalId":302747,"journal":{"name":"2013 International Conference on Availability, Reliability and Security","volume":"2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-09-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 International Conference on Availability, Reliability and Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ARES.2013.56","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7
Abstract
This paper presents a security engineering process for the modelling of security-sensitive systems using a real use case of metering devices. The process provides a security framework that can be used with other existing processes (such as the agile ones). It helps to develop and model systems bearing in mind their heterogeneity, real-time and dynamic behaviors. Besides, due to the critical nature of some of these systems (nuclear, emergency systems, military, etc.) it provides tools for identifying, working and solving security threats by using the knowledge of domain experts. This is very important because threats, properties, solutions, etc. that are valid or relevant in a given domain, are not applicable to other domains and are subject to constant changes. The security requirements of the systems are fulfilled by means of domain-specific security knowledge. These artefacts contain the specific information of a domain (security properties, elements, assumptions, threats, tests, etc.). The solutions are presented as Security Patterns. Each one describes an implementation solution by using one or several Security Building Blocks (SBBs). The security engineering process presented here describes how to model a security-enhanced system model using a library of domain security knowledge. The process has been developed along with a Magic Draw plugin that covers all the possible functionalities, making the work with the models and the security elements very simple and easy for the user.
本文介绍了一种安全工程过程,用于使用计量设备的真实用例对安全敏感系统进行建模。该流程提供了一个安全框架,可以与其他现有流程(例如敏捷流程)一起使用。它有助于开发和建模系统记住他们的异质性,实时和动态行为。此外,由于其中一些系统(核,应急系统,军事等)的关键性质,它提供了利用领域专家的知识来识别,工作和解决安全威胁的工具。这一点非常重要,因为在给定领域中有效或相关的威胁、属性、解决方案等不适用于其他领域,并且会不断变化。系统的安全需求通过特定于领域的安全知识来实现。这些工件包含域的特定信息(安全属性、元素、假设、威胁、测试等)。解决方案以安全模式的形式呈现。每一个都通过使用一个或多个安全构建块(Security Building block, sbb)来描述一个实现解决方案。本文介绍的安全工程过程描述了如何使用领域安全知识库对安全增强的系统模型进行建模。这个过程是与Magic Draw插件一起开发的,它涵盖了所有可能的功能,使得模型和安全元素的工作对用户来说非常简单和容易。