Architectures for Cyber-Security Incident Reporting in Safety-Critical Systems
نویسنده
چکیده
Cyber-attacks can have a devastating impact on safety-critical systems. The increasing reliance on mass market Commercial Off-The Shelf (COTS) infrastructures, including Linux and the IP stack, have created vulnerabilities in applications ranging from Air Traffic Management through to Railway signalling and Maritime surveillance. Once a system has been attacked, it is impossible to demonstrate that malware has been completely eradicated from a safety-related network. For instance, recent generations of malware use zero day exploits and process injection with command and control server architectures to circumvent existing firewalls and monitoring software. This creates enormous problems for regulators who must determine whether or not it is acceptably safe to resume operations. It is, therefore, important that we learn as much as possible from previous cyber-attacks without disclosing information that might encourage future attacks. This paper describes different architectures for encouraging the exchange of lessons learned from security incidents in safety-critical applications.
منابع مشابه
Assuring Industrial Control System (ICS) Cyber Security
Industrial Control Systems (ICS) are an integral part of the industrial infrastructure providing for the national good. These systems include Distributed Control Systems (DCS) Supervisory Control and Data Acquisition systems (SCADA), Programmable Logic Controllers (PLC), and devices such as remote telemetry units (RTU), smart meters, and intelligent field instruments including remotely programm...
متن کاملForensic Attacks Analysis and the Cyber Security of Safety-Critical Industrial Control Systems
Industrial Control Systems (ICS) and SCADA (Supervisory Control And Data Acquisition) applications monitor and control a wide range of safety-related functions. These include energy generation where failures could have significant, irreversible consequences. They also include the control systems that are used in the manufacture of safety-related products. In this case bugs in an ICS/SCADA syste...
متن کاملInvestigation of Incident Reporting System in Iranian Hospitals: A National Survey
Background and Aims: Incident reporting is a possible alternative for learning from errors. One of the barriers in this way is a deficit in, common standards for collecting, interpreting, and presenting data. In this research accordance with Iranchr('39')s incident reporting system with minimal information Model for Patient Safety Incident Reporting Systems (MIMPS)of WHO were compared. Methods:...
متن کاملWhy We Cannot (Yet) Ensure the Cyber-Security of Safety-Critical Systems
There is a growing threat to the cyber-security of safety-critical systems. The introduction of Commercial Off The Shelf (COTS) software, including Linux, specialist VOIP applications and Satellite Based Augmentation Systems across the aviation, maritime, rail and power-generation infrastructures has created common, vulnerabilities. In consequence, more people now possess the technical skills r...
متن کاملCyberSafety: CyberSecurity and Safety-Critical Software Engineering
A range of common software components are gradually being integrated into the infrastructures that support safety-critical systems. These include network management tools, operating systems – especially Linux, Voice Over IP (VOIP) communications technologies, and satellite based augmentation systems for navigation/timing data etc. The increasing use of these common components creates concerns t...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2013