首页> 外文会议>International Conference on Industrial Informatics >How to Quantify the Security Level of Embedded Systems? A Taxonomy of Security Metrics
【24h】

How to Quantify the Security Level of Embedded Systems? A Taxonomy of Security Metrics

机译:如何量化嵌入式系统的安全级别? 安全指标的分类

获取原文

摘要

Embedded Systems (ES) development has been historically focused on functionality rather than security, and today it still applies in many sectors and applications. However, there is an increasing number of security threats over ES, and a successful attack could have economical, physical or even human consequences, since many of them are used to control critical applications. A standardized and general accepted security testing framework is needed to provide guidance, common reporting forms and the possibility to compare the results along the time. This can be achieved by introducing security metrics into the evaluation or assessment process. If carefully designed and chosen, metrics could provide a quantitative, repeatable and reproducible value that would reflect the level of security protection of the ES. This paper analyzes the features that a good security metric should exhibit, introduces a taxonomy for classifying them, and finally, it carries out a literature survey on security metrics for the security evaluation of ES. In this review, more than 500 metrics were collected and analyzed. Then, they were reduced to 169 metrics that have the potential to be applied to ES security evaluation. As expected, the 77.5% of them is related exclusively to software, and only the 0.6% of them addresses exclusively hardware security. This work aims to lay the foundations for constructing a security evaluation methodology that uses metrics so as to quantify the security level of an ES.
机译:嵌入式系统开发已历史上专注于功能,而不是安全性,而今天它仍然适用于许多部门和应用程序。然而,越来越多的安全威胁在ES上,并且成功的攻击可能具有经济,身体甚至人为后果,因为其中许多用于控制关键应用。需要标准化和一般接受的安全测试框架,以提供指导,常见的报告表格以及沿着时间比较结果的可能性。这可以通过将安全指标引入评估或评估过程来实现。如果精心设计和选择,指标可以提供定量,可重复和可重复的值,这些值将反映ES的安全保护水平。本文分析了良好的安全公制应该表现出的特征,介绍了分类的分类,最后,它对es的安全评估进行了关于安全指标的文献调查。在本次审查中,收集并分析了500多个指标。然后,它们减少到169个度量标准,具有适用于ES安全评估的可能性。正如预期的那样,它们的77.5%专门与软件相关,只有0.6%的0.6%地解决了硬件安全性。这项工作旨在为构建使用指标来构建安全评估方法的基础,以便量化ES的安全级别。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号