Authors:
Friedrich Köster
1
;
Michael Klaas
1
;
Hanh Quyen Nguyen
1
;
Walter Brenner
1
;
Markus Braendle
2
and
Sebastian Obermeier
2
Affiliations:
1
University of St. Gallen, Switzerland
;
2
ABB Research, Switzerland
Keyword(s):
Collaborative security assessment, ESSAF framework, Embedded systems security, Security knowledge management, Threat modeling.
Related
Ontology
Subjects/Areas/Topics:
Enterprise Information Systems
;
Formal Methods
;
Human Factors and Human Behaviour Recognition Techniques
;
Information and Systems Security
;
Information Assurance
;
Information Systems Analysis and Specification
;
Information Systems Auditing
;
Methodologies and Technologies
;
Operational Research
;
Planning Security
;
Risk Assessment
;
Security
;
Simulation and Modeling
Abstract:
The standardization of network protocols and software components in embedded systems development has introduced security threats that have been common before in e-commerce and office systems into the domain of critical infrastructures. The ESSAF framework presented in this paper lays the ground for collaborative, structured security assessments during the design and development phase of these systems. Its three phases system modeling, security modeling and mitigation planning guide software developers in the independent assessment of their product’s security, minimizing the burden on security experts in the collection of security relevant data.