现代供应链生态系统的持续安全保障及其在自动驾驶中的应用:安全自动驾驶领域的FISHY方法

George Hatzivasilis, S. Ioannidis, Grigoris Kalogiannis, Manolis Chatzimpyrros, G. Spanoudakis, Guillermo Jiménez Prieto, Araceli Rojas Morgan, Miguel Juaniz Lopez, C. Basile, J. F. Ruiz
{"title":"现代供应链生态系统的持续安全保障及其在自动驾驶中的应用:安全自动驾驶领域的FISHY方法","authors":"George Hatzivasilis, S. Ioannidis, Grigoris Kalogiannis, Manolis Chatzimpyrros, G. Spanoudakis, Guillermo Jiménez Prieto, Araceli Rojas Morgan, Miguel Juaniz Lopez, C. Basile, J. F. Ruiz","doi":"10.1109/CSR57506.2023.10224971","DOIUrl":null,"url":null,"abstract":"Cyber security always forms a significant aspect of ICT infrastructure, with threats on supply-chain networks gaining greater attention nowadays. The secure autonomous driving domain presents a unique set of challenges for supply-chain security. Autonomous vehicles rely on a complex ecosystem of hardware and software components, many of which are sourced from third-party suppliers. Ensuring the security and reliability of this supply-chain is essential to maintain the safety and viability of autonomous driving as a technology. To address these challenges, a continuous security assurance approach is necessary. This involves ongoing monitoring, assessment, and improvement of security measures to detect and mitigate potential vulnerabilities in the supply chain. Key measures may include regular vulnerability assessments, penetration testing, and security awareness training for employees and contractors, as well as the implementation of security controls such as secure communication protocols, access controls, and intrusion detection systems. By adopting a continuous security assurance approach for supply chain security in the secure autonomous driving domain, organizations can safeguard their operations and ensure the safety of passengers and other road users. This paper presents a security assurance and certification solution for supply-chain services. Security elements are continuously assessed based on AI operations. The proposal is implemented under the EU funded project FISHY and applied in the supply-chain of secure autonomous driving (SADE) pilot with REMOTIS smart vehicles. Nevertheless, it is a generic solution that can be applied in any domain.","PeriodicalId":354918,"journal":{"name":"2023 IEEE International Conference on Cyber Security and Resilience (CSR)","volume":"37 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-31","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Continuous Security Assurance of Modern Supply-Chain Ecosystems with Application in Autonomous Driving: The FISHY approach for the secure autonomous driving domain\",\"authors\":\"George Hatzivasilis, S. Ioannidis, Grigoris Kalogiannis, Manolis Chatzimpyrros, G. Spanoudakis, Guillermo Jiménez Prieto, Araceli Rojas Morgan, Miguel Juaniz Lopez, C. Basile, J. F. Ruiz\",\"doi\":\"10.1109/CSR57506.2023.10224971\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cyber security always forms a significant aspect of ICT infrastructure, with threats on supply-chain networks gaining greater attention nowadays. The secure autonomous driving domain presents a unique set of challenges for supply-chain security. Autonomous vehicles rely on a complex ecosystem of hardware and software components, many of which are sourced from third-party suppliers. Ensuring the security and reliability of this supply-chain is essential to maintain the safety and viability of autonomous driving as a technology. To address these challenges, a continuous security assurance approach is necessary. This involves ongoing monitoring, assessment, and improvement of security measures to detect and mitigate potential vulnerabilities in the supply chain. Key measures may include regular vulnerability assessments, penetration testing, and security awareness training for employees and contractors, as well as the implementation of security controls such as secure communication protocols, access controls, and intrusion detection systems. By adopting a continuous security assurance approach for supply chain security in the secure autonomous driving domain, organizations can safeguard their operations and ensure the safety of passengers and other road users. This paper presents a security assurance and certification solution for supply-chain services. Security elements are continuously assessed based on AI operations. The proposal is implemented under the EU funded project FISHY and applied in the supply-chain of secure autonomous driving (SADE) pilot with REMOTIS smart vehicles. Nevertheless, it is a generic solution that can be applied in any domain.\",\"PeriodicalId\":354918,\"journal\":{\"name\":\"2023 IEEE International Conference on Cyber Security and Resilience (CSR)\",\"volume\":\"37 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-07-31\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 IEEE International Conference on Cyber Security and Resilience (CSR)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CSR57506.2023.10224971\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE International Conference on Cyber Security and Resilience (CSR)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSR57506.2023.10224971","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

网络安全一直是信息通信技术基础设施的重要组成部分,供应链网络的威胁日益受到关注。安全自动驾驶领域对供应链安全提出了一系列独特的挑战。自动驾驶汽车依赖于一个由硬件和软件组件组成的复杂生态系统,其中许多组件来自第三方供应商。确保供应链的安全性和可靠性对于维持自动驾驶技术的安全性和可行性至关重要。为了应对这些挑战,需要一种持续的安全保证方法。这涉及对安全措施的持续监控、评估和改进,以检测和减轻供应链中的潜在漏洞。关键措施可能包括定期的漏洞评估、渗透测试和对雇员和承包商的安全意识培训,以及安全控制的实现,例如安全通信协议、访问控制和入侵检测系统。通过对安全自动驾驶领域的供应链安全采取持续的安全保障方法,组织可以保障其运营,并确保乘客和其他道路使用者的安全。本文提出了一种针对供应链服务的安全保证与认证解决方案。以人工智能操作为基础,持续评估安全要素。该提案由欧盟资助的FISHY项目实施,并应用于REMOTIS智能汽车的安全自动驾驶(SADE)供应链试点。然而,它是一个通用的解决方案,可以应用于任何领域。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Continuous Security Assurance of Modern Supply-Chain Ecosystems with Application in Autonomous Driving: The FISHY approach for the secure autonomous driving domain
Cyber security always forms a significant aspect of ICT infrastructure, with threats on supply-chain networks gaining greater attention nowadays. The secure autonomous driving domain presents a unique set of challenges for supply-chain security. Autonomous vehicles rely on a complex ecosystem of hardware and software components, many of which are sourced from third-party suppliers. Ensuring the security and reliability of this supply-chain is essential to maintain the safety and viability of autonomous driving as a technology. To address these challenges, a continuous security assurance approach is necessary. This involves ongoing monitoring, assessment, and improvement of security measures to detect and mitigate potential vulnerabilities in the supply chain. Key measures may include regular vulnerability assessments, penetration testing, and security awareness training for employees and contractors, as well as the implementation of security controls such as secure communication protocols, access controls, and intrusion detection systems. By adopting a continuous security assurance approach for supply chain security in the secure autonomous driving domain, organizations can safeguard their operations and ensure the safety of passengers and other road users. This paper presents a security assurance and certification solution for supply-chain services. Security elements are continuously assessed based on AI operations. The proposal is implemented under the EU funded project FISHY and applied in the supply-chain of secure autonomous driving (SADE) pilot with REMOTIS smart vehicles. Nevertheless, it is a generic solution that can be applied in any domain.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信