首页> 外文期刊>European journal of navigation >Cyber security in shipping and navigation: a framework for ship design and compliance check
【24h】

Cyber security in shipping and navigation: a framework for ship design and compliance check

机译:航运和导航中的网络安全:船舶设计和合规性检查的框架

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Physical security and safety of ships and their systems as the most valuable assets of the shipping industry has been on its focus for many years. Due to the distributed architecture of this business and a very high usage of stand-alone and disconnected systems, no major efforts have been made on considering cyber security. Nowadays systems on board of ships have a higher automation and connection level and exchange a significant number of sensor data and other information in a very short time. Many of these computers and systems are an integral part of the critical onboard infrastructure, which is one of the main reasons why shipping industry should reprioritize cyber security for the future of intelligent and resilient ships. This fact is actually well known and many actions and guidelines on the management of cyber risks are being developed and published by different actors and authorities. Most of them encompass a very wide range of measures for managing cyber risk and cyber security at all three main relevant levels: personnel, processes and technology. The deployment of security measures is of course a management decision, but in order to be effective these measures must go hand in hand with the technical ones.Cyber security has not been part of the design criteria for most of the ships that are actually in operation. This makes it very challenging for shipping companies to comply and implement guidelines in a very wide range.In this contribution, we provide an overview of well-known technical aspects of computer security and categorize them based on their relevance for shipping industry and its most important use case: the ship and its critical systems on board. We will focus on the technical aspects of cyber security as done in the information technology and derive their suitability and importance for ships and their main systems. The main scope is to develop a framework for classification and definition of requirements on secure onboard systems and give decision support in the challenging subject of cyber security on board. For the requirement's definition following security levels (layers) will be considered.1. Physical layer (e.g. processor, sensor)2. Physical interfaces and low level protocols (e.g. USB)3. Operating systems (e.g. Windows-based, Unix-based other operating systems)4. Internal network and topology 5. Internal communication protocols between connected systems (e.g. ftp, http) 6. Communication layer and protocol with external systems (e.g. GPS, Internet, AIS) 7. Application layer (e.g. stand-alone and/or shared software, database security) This classification framework should enable and support a stronger influence of cyber security aspects as design criteria for ship's systems and their architecture. Furthermore, it can be used for cyber security compliance checks for all black box systems and software, integrated onboard and will support decision makers with technical knowledge "to design by security".
机译:作为航运业最有价值资产的船舶及其系统的物理安全性多年来一直是其关注的焦点。由于该业务的分布式体系结构以及独立和断开连接的系统的使用率很高,因此在考虑网络安全方面并未做出重大努力。如今,船上系统具有更高的自动化和连接级别,并且可以在很短的时间内交换大量传感器数据和其他信息。这些计算机和系统中的许多是关键的船上基础设施的组成部分,这是航运业应优先考虑网络安全以应对智能和弹性船舶的未来的主要原因之一。这个事实实际上是众所周知的,并且不同参与者和当局正在制定和发布许多有关网络风险管理的行动和指南。其中大多数包含在三个主要相关级别(人员,流程和技术)上管理网络风险和网络安全的非常广泛的措施。安全措施的部署当然是一项管理决定,但是为了使这些措施有效,必须与技术措施并驾齐驱。对于大多数实际运行的船舶,网络安全并不是设计标准的一部分。 。这给船运公司在广泛范围内遵守和实施指南带来了挑战。在此贡献中,我们概述了计算机安全的众所周知的技术方面,并根据它们与船运行业的相关性及其最重要的方面对其进行分类用例:船及其关键系统。我们将专注于信息技术中网络安全的技术方面,并得出它们对船舶及其主要系统的适用性和重要性。主要范围是建立一个框架,用于对机载安全系统的要求进行分类和定义,并为具有挑战性的机载网络安全主题提供决策支持。对于需求的定义,将考虑以下安全级别(层):1。物理层(例如处理器,传感器)2。物理接口和低级协议(例如USB)3。操作系统(例如,基于Windows,基于Unix的其他操作系统)4。内部网络和拓扑5.所连接系统之间的内部通信协议(例如ftp,http)6.与外部系统之间的通信层和协议(例如GPS,Internet,AIS)7.应用层(例如独立和/或共享软件,数据库安全性)此分类框架应启用并支持网络安全性方面作为船舶系统及其体系结构设计标准的更大影响力。此外,它还可以用于所有集成在机上的黑匣子系统和软件的网络安全合规性检查,并为决策者提供具有“按安全设计”的技术知识。

著录项

  • 来源
    《European journal of navigation》 |2019年第1期|11-18|共8页
  • 作者单位

    Fraunhofer Center for Maritime Logistics and Services Am Schwarzenberg-Campus,4 GebAEude D, 21073 Hamburg, Germany;

    Fraunhofer Center for Maritime Logistics and Services Am Schwarzenberg-Campus,4 GebAEude D, 21073 Hamburg, Germany;

    Fraunhofer Center for Maritime Logistics and Services Am Schwarzenberg-Campus,4 GebAEude D, 21073 Hamburg, Germany;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号