Final published version
Licence: CC BY: Creative Commons Attribution 4.0 International License
Research output: Contribution to Journal/Magazine › Journal article › peer-review
Research output: Contribution to Journal/Magazine › Journal article › peer-review
}
TY - JOUR
T1 - STPA-SafeSec
T2 - Safety and security analysis for cyber-physical systems
AU - Friedberg, Ivo
AU - McLaughlin, Kieran
AU - Smith, Paul
AU - Laverty, David M.
AU - Sezer, Sakir
PY - 2017/6/30
Y1 - 2017/6/30
N2 - Cyber-physical systems tightly integrate physical processes and information and communication technologies. As today's critical infrastructures, e.g., the power grid or water distribution networks, are complex cyber-physical systems, ensuring their safety and security becomes of paramount importance. Traditional safety analysis methods, such as HAZOP, are ill-suited to assess these systems. Furthermore, cybersecurity vulnerabilities are often not considered critical, because their effects on the physical processes are not fully understood. In this work, we present STPA-SafeSec, a novel analysis methodology for both safety and security. Its results show the dependencies between cybersecurity vulnerabilities and system safety. Using this information, the most effective mitigation strategies to ensure safety and security of the system can be readily identified. We apply STPA-SafeSec to a use case in the power grid domain, and highlight its benefits.
AB - Cyber-physical systems tightly integrate physical processes and information and communication technologies. As today's critical infrastructures, e.g., the power grid or water distribution networks, are complex cyber-physical systems, ensuring their safety and security becomes of paramount importance. Traditional safety analysis methods, such as HAZOP, are ill-suited to assess these systems. Furthermore, cybersecurity vulnerabilities are often not considered critical, because their effects on the physical processes are not fully understood. In this work, we present STPA-SafeSec, a novel analysis methodology for both safety and security. Its results show the dependencies between cybersecurity vulnerabilities and system safety. Using this information, the most effective mitigation strategies to ensure safety and security of the system can be readily identified. We apply STPA-SafeSec to a use case in the power grid domain, and highlight its benefits.
KW - Smart grid
KW - Synchronous islanded generation
KW - STPA
KW - CPS
KW - Safety
KW - Cyber security
U2 - 10.1016/j.jisa.2016.05.008
DO - 10.1016/j.jisa.2016.05.008
M3 - Journal article
VL - 34
SP - 183
EP - 196
JO - Journal of Information Security and Applications
JF - Journal of Information Security and Applications
SN - 2214-2126
IS - 2
ER -