【24h】

SAFETY VS. SECURITY?

机译:安全与安全?

获取原文

摘要

The concepts of safety and security have a lot in common, but nevertheless two faculties have developed with a certain degree of rivalry between them. Security people maintain that the safety people are just a gang of old men who are unwilling to learn something new, the safety people retaliate that the security people are youngsters who haven't realized that they're re-inventing the wheel! Certainly there is a communication problem between the two groups: each has developed its own vocabulary for similar - or even identical - concepts, which at least produces confusion. In this paper, some of the common properties and differences between terms and techniques in the two communities are discussed with the aim of reconciling potential conflicts and exploring potential for cooperation, convergence and mutual benefits. We concentrate on the context of information technology, i.e. safety related software and information security. The underlying concepts of safety and security are indeed not identical, they're complementary. In both cases we have a "system" in an environment. The system might be able to have an undesirable effect on its environment, but the environment can equally well have an undesirable effect on the system. The inability of the system to affect its environment in an undesirable way is usually called safety; the inability of the environment to affect the system in an undesirable way is usually called security. Depending on the type of system, its environment and the types of undesirable effects one can have on the other we get a multitude of definitions for safety and security. While safety related software aims at protecting life, health and the natural environment from any damage the system may cause, within information security the main goal is to protect the confidentiality, integrity and availability of information in the system. Safety focuses on unintentional events, while security also focuses on threats coming from outside the system, often caused by malicious parties. These differences result in different foundations for prioritizing solutions. A closer cooperation between safety and security experts will cover both unintentional and intentional events. When analyzing the risks for an IT-system one should focus on the whole picture - including both safety and security, not just one or the other. By doing so one obtains a complete overview of potential threats/hazards towards a system. The techniques used in software safety have been around for quite some time and are well established and tested. Some of these techniques may be useful also for security people who may thus benefit from the experiences of the safety community. On the other hand, there are also security techniques that will become significant for the safety community. For example, in the near future we will see more use of open communication networks for remote control of industrial and transportation applications. When vitally important commands are transmitted through such open networks, security techniques such as encryption and access control will become indispensable for safety. Security techniques will have to become an integral part of safety thinking. Software safety and information security are not separate issues. Information security breaches can compromise the ability of software to function safely, or they can enable misuse of safe software in an unsafe way. Safety breaches can make information security impossible. As such, both sides stand to benefit from closer cooperation. To enable cooperation one needs to reach an agreement on which terms to use and how to interpret them, and also on what techniques to use. Although the safety field has a longer track record, to be able to cover both aspects one needs to adopt techniques from both fields - or possibly merge existing techniques or create new ones.
机译:安全和安全的概念有很多共同之处,但是两个院系已经在它们之间具有一定程度的竞争。保安人员认为安全人士只是一群不愿意学习新的老人,安全人员将安全人士报复的人是年轻人没有意识到他们重新发明轮子!当然,两组之间存在沟通问题:每个人都开发了其自身的词汇,用于类似 - 甚至相同的 - 概念,至少产生混淆。在本文中,讨论了两个社区中的一些共同特性和差异,以促进潜在的冲突和探索合作,收敛和互利的潜力。我们专注于信息技术的背景,即安全相关软件和信息安全。安全性和安全性的潜在概念确实不相同,它们是互补的。在这两种情况下,我们在环境中有一个“系统”。系统可能能够对其环境产生不希望的影响,但环境同样可以很好地对系统产生不良影响。系统不能以不合需要的方式影响其环境的环境通常被称为安全;环境无法以不希望的方式影响系统,通常称为安全性。根据系统的类型,它的环境和不期望的效果类型可以对另一个人来说,我们得到了对安全和安全性的多种定义。虽然安全相关软件旨在保护生命,健康和自然环境,但在系统中可能导致的任何损坏,在信息安全中,主要目标是保护系统中信息的机密性,完整性和可用性。安全侧重于无意的事件,而安全性也侧重于来自系统以外的威胁,通常由恶意派对引起的。这些差异导致优先级解决方案的不同基础。安全和安全专家之间的仔细合作将涵盖无意和故意的事件。在分析IT系统的风险时,应该专注于整个图片 - 包括安全性和安全性,而不仅仅是一个或另一个。通过这样做,获得对系统的潜在威胁/危害的完整概述。软件安全中使用的技术已经存在了很长一段时间,并且已经建立并测试了。这些技术中的一些也可能是可供使安全社区的经验中受益的安全人员。另一方面,还有安全技术对于安全界会变得重要意义。例如,在不久的将来,我们将看到更多使用开放通信网络来远程控制工业和运输应用。当通过这种开放网络传输真正重要的命令时,诸如加密和访问控制之类的安全技术将是不可或缺的安全性。安全技术必须成为安全思维的一个组成部分。软件安全和信息安全不是单独的问题。信息安全漏洞可以危及软件功能安全功能,或者他们可以以不安全的方式误导安全软件。安全漏洞可以使信息安全不可能。因此,双方都能从更密切的合作中受益。为了实现合作,需要达到使用哪些术语的协议以及如何解释它们,以及还可以使用什么技术。虽然安全领域具有更长的轨道记录,但能够涵盖两个方面需要采用来自两个字段的技术 - 或者可能合并现有技术或创建新的技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号