IT security risk analysis and threat mitigation for railway applications - FAST-ABSTRACTS-SAFECOMP2016 Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

IT security risk analysis and threat mitigation for railway applications

Patric Birr
  • Fonction : Auteur
Martin Hetzer
  • Fonction : Auteur
Simon Petretti
  • Fonction : Auteur

Résumé

In this article, we present a best practise approach for the evaluation and assessment of IT security demands for railway applications. State-of-the-art standards and guidelines are used to identify and evaluate threats concerning the IT security of a given railway system and corresponding requirements are derived. Taking threat mitigation measures into account, the system under consideration is revised based on its technology and system architecture. Using combined " Top-Down " and " Bottom-Up " analysis techniques, the most relevant attack patterns and penetration paths are identified for each system component or function. The result of such an analysis may require iterative revisions and eventually extends IT security requirements as compared to the derivation from standards.
Fichier principal
Vignette du fichier
7-SafeComp_2016_Fast_Abstract_Birr_Hetzer_Petretti.pdf (223.75 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01370249 , version 1 (22-09-2016)

Identifiants

  • HAL Id : hal-01370249 , version 1

Citer

Patric Birr, Martin Hetzer, Simon Petretti. IT security risk analysis and threat mitigation for railway applications. Fast abstracts at International Conference on Computer Safety, Reliability, and Security (SAFECOMP), 2016, Trondheim, Norway. ⟨hal-01370249⟩

Collections

SAFECOMP2016
215 Consultations
28 Téléchargements

Partager

Gmail Facebook X LinkedIn More