以计量应用程序为例的嵌入式设备风险管理

WESS '14 Pub Date : 2014-10-12 DOI:10.1145/2668322.2668328
O. Guillen, R. Brederlow, Ralph Ledwa, G. Sigl
{"title":"以计量应用程序为例的嵌入式设备风险管理","authors":"O. Guillen, R. Brederlow, Ralph Ledwa, G. Sigl","doi":"10.1145/2668322.2668328","DOIUrl":null,"url":null,"abstract":"Along with the rise in use of everyday life electronic products that collect and communicate personal data, there is an increasing need for adequate security. The use of ultra-low-power MCUs in such applications provides a clear advantage in terms of energy consumption. However, given their general-purpose nature and low-power needs, security has not been the main focus in the past. This work places emphasis on methodologically analyzing open security gaps at a system level and providing a score for each vulnerability found. Such vulnerability scores help prioritize the efforts towards building a secure system and balancing the trade-off between suitable protection and minimal cost. The work presented uses as an example an abstraction of metering applications implemented using a general purpose microcontroller. The presented approach makes use of the Common Vulnerability Scoring System open framework to quantify the impact of possible vulnerabilities and prioritize their remediation based on their relevancy.","PeriodicalId":434126,"journal":{"name":"WESS '14","volume":"64 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-10-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Risk management in embedded devices using metering applications as example\",\"authors\":\"O. Guillen, R. Brederlow, Ralph Ledwa, G. Sigl\",\"doi\":\"10.1145/2668322.2668328\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Along with the rise in use of everyday life electronic products that collect and communicate personal data, there is an increasing need for adequate security. The use of ultra-low-power MCUs in such applications provides a clear advantage in terms of energy consumption. However, given their general-purpose nature and low-power needs, security has not been the main focus in the past. This work places emphasis on methodologically analyzing open security gaps at a system level and providing a score for each vulnerability found. Such vulnerability scores help prioritize the efforts towards building a secure system and balancing the trade-off between suitable protection and minimal cost. The work presented uses as an example an abstraction of metering applications implemented using a general purpose microcontroller. The presented approach makes use of the Common Vulnerability Scoring System open framework to quantify the impact of possible vulnerabilities and prioritize their remediation based on their relevancy.\",\"PeriodicalId\":434126,\"journal\":{\"name\":\"WESS '14\",\"volume\":\"64 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2014-10-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"WESS '14\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/2668322.2668328\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"WESS '14","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2668322.2668328","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

随着日常生活中收集和传输个人数据的电子产品的使用越来越多,对足够安全的需求也越来越大。在此类应用中使用超低功耗mcu在能耗方面提供了明显的优势。然而,考虑到它们的通用性质和低功耗需求,安全性在过去并不是主要关注的焦点。这项工作强调在系统级别上从方法上分析开放的安全漏洞,并为发现的每个漏洞提供评分。这样的漏洞评分有助于对构建安全系统的努力进行优先排序,并在适当的保护和最小的成本之间取得平衡。该工作以使用通用微控制器实现的计量应用的抽象为例。提出的方法利用公共漏洞评分系统开放框架来量化可能的漏洞的影响,并根据其相关性对其修复进行优先级排序。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Risk management in embedded devices using metering applications as example
Along with the rise in use of everyday life electronic products that collect and communicate personal data, there is an increasing need for adequate security. The use of ultra-low-power MCUs in such applications provides a clear advantage in terms of energy consumption. However, given their general-purpose nature and low-power needs, security has not been the main focus in the past. This work places emphasis on methodologically analyzing open security gaps at a system level and providing a score for each vulnerability found. Such vulnerability scores help prioritize the efforts towards building a secure system and balancing the trade-off between suitable protection and minimal cost. The work presented uses as an example an abstraction of metering applications implemented using a general purpose microcontroller. The presented approach makes use of the Common Vulnerability Scoring System open framework to quantify the impact of possible vulnerabilities and prioritize their remediation based on their relevancy.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信