首页> 外文期刊>Inventions >Determining Information Security Threats for an IoT-Based Energy Internet by Adopting Software Engineering and Risk Management Approaches
【24h】

Determining Information Security Threats for an IoT-Based Energy Internet by Adopting Software Engineering and Risk Management Approaches

机译:通过采用软件工程和风险管理方法来确定基于物联网能源互联网的信息安全威胁

获取原文
       

摘要

This paper introduces an information security threat modeling (ISTM) scheme, which leverages the strengths of software engineering and risk management approaches, called I-SERM. The proposed I-SERM scheme effectively and efficiently prioritizes information security threats for IT systems that utilize a large number of sensors, such as Internet of Things (IoT)-based energy systems. I-SERM operations include determining functional components, identifying associated threat types, analyzing threat items, and prioritizing key threats with the use of software engineering tools such as product flow diagrams, use case diagrams, and data flow diagrams. By simultaneously referring to a proposed STRIDE+p matrix and a defined threat breakdown structure with reference score (TBS+r) scheme, the I-SERM approach enables systematic ISTM. To demonstrate the usability of I-SERM, this study presents a practical case aimed at electricity load balancing on a smart grid. In brief, this study indicates a substantive research direction that combines the advantages of software engineering and risk management into a systematic ISTM process. In addition, the demonstration of I-SERM in practice provides a valuable and practical reference for I-SERM application, and contributes to research in the field of information security designs for IoT-based Energy Internet systems.
机译:本文介绍了一种信息安全威胁建模(ISTM)方案,它利用软件工程和风险管理方法的优势,称为I-SERM。所提出的I-SERM方案有效地有效地优先于IT系统的信息安全威胁,其利用大量传感器,例如物联网(IOT)的能量系统。 I-SERM操作包括确定功能组件,识别关联的威胁类型,分析威胁项目,以及使用软件工程工具(如产品流程图,用例图和数据流程图)的优先考虑关键威胁。通过同时参考提出的阶段+ P矩阵和具有参考评分(TBS + R)方案的定义威胁击穿结构,I-SERM方法使系统ISTM能够。为了证明I-SERM的可用性,本研究提出了一种实用的案例,旨在在智能电网上平衡电力负荷。简而言之,本研究表明了将软件工程和风险管理的优势结合到系统的ISTM过程中的实质性研究方向。此外,实践中的I-SERM的演示为I-SERM应用提供了有价值和实践的参考,并有助于研究信息安全设计领域的基于IOT的能源互联网系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号