...
首页> 外文期刊>European journal of navigation >Cyber security in shipping and navigation: a framework for ship design and compliance check
【24h】

Cyber security in shipping and navigation: a framework for ship design and compliance check

机译:运输和导航中的网络安全:船舶设计和合规性检查的框架

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Physical security and safety of ships and their systems as the most valuable assets of the shipping industry has been on its focus for many years. Due to the distributed architecture of this business and a very high usage of stand-alone and disconnected systems, no major efforts have been made on considering cyber security. Nowadays systems on board of ships have a higher automation and connection level and exchange a significant number of sensor data and other information in a very short time. Many of these computers and systems are an integral part of the critical onboard infrastructure, which is one of the main reasons why shipping industry should reprioritize cyber security for the future of intelligent and resilient ships. This fact is actually well known and many actions and guidelines on the management of cyber risks are being developed and published by different actors and authorities. Most of them encompass a very wide range of measures for managing cyber risk and cyber security at all three main relevant levels: personnel, processes and technology. The deployment of security measures is of course a management decision, but in order to be effective these measures must go hand in hand with the technical ones.Cyber security has not been part of the design criteria for most of the ships that are actually in operation. This makes it very challenging for shipping companies to comply and implement guidelines in a very wide range.In this contribution, we provide an overview of well-known technical aspects of computer security and categorize them based on their relevance for shipping industry and its most important use case: the ship and its critical systems on board. We will focus on the technical aspects of cyber security as done in the information technology and derive their suitability and importance for ships and their main systems. The main scope is to develop a framework for classification and definition of requirements on secure onboard systems and give decision support in the challenging subject of cyber security on board. For the requirement's definition following security levels (layers) will be considered.1. Physical layer (e.g. processor, sensor)2. Physical interfaces and low level protocols (e.g. USB)3. Operating systems (e.g. Windows-based, Unix-based other operating systems)4. Internal network and topology 5. Internal communication protocols between connected systems (e.g. ftp, http) 6. Communication layer and protocol with external systems (e.g. GPS, Internet, AIS) 7. Application layer (e.g. stand-alone and/or shared software, database security) This classification framework should enable and support a stronger influence of cyber security aspects as design criteria for ship's systems and their architecture. Furthermore, it can be used for cyber security compliance checks for all black box systems and software, integrated onboard and will support decision makers with technical knowledge "to design by security".
机译:船舶及其作为航运业的最宝贵的资产系统的物理安全性和安全性一直是其重点多年。由于这项业务的分布式架构和独立和割裂的系统非常高的使用率,没有大的努力已做考虑网络安全。船舶的董事会目前系统具有自动化程度高,连接级别,并在很短的时间交换传感器数据和其他信息的显著数量。许多这些计算机和系统是关键的基础设施船上,这是主要的原因,航运业应该重新指定网络安全智能和弹性的船舶未来的一个不可分割的组成部分。这个事实实际上是众所周知的,很多动作和对网络风险管理指引正在研发中,由不同的演员和当局公布。他们中的大多数涵盖了非常广泛的,在所有三个主要的相关层面管理网络风险和网络安全的措施:人员,流程和技术。安全措施的部署当然是一个管理决策,但为了有效,这些措施必须齐头并进与技术ones.Cyber​​安全已经不是最实际的操作中的船舶被设计标准的一部分。这使得航运企业遵守和执行指引一个非常具有挑战性的很宽range.In这方面的贡献,我们提供的计算机安全的知名技术方面的概述和分类,根据它们的相关性,为航运业最重要的使用案例:船和船上的关键系统。我们将专注于在信息技术完成,获得他们的船舶,其主要系统的适宜性和重要性,网络安全技术方面。范围主要是开发用于分类和对安全的车载系统需求定义的框架,并在船上网络安全的挑战课题给予决策支持。对于需求的定义以下安全级别(层)将considered.1。物理层(例如处理器,传感器)2。物理接口和低电平协议(例如USB)3。操作系统(例如,基于Windows的,基于Unix的其他操作系统)4。内部网络和拓扑连接系统5之间的内部通信协议(例如FTP,HTTP)6.通讯层和协议与外部系统(例如GPS,因特网,AIS)7.应用层(例如独立和/或共享软件,数据库安全)这种分类框架应该允许和支持的网络安全方面的船舶系统及其架构的强大影响力的设计标准。此外,它可用于网络安全符合性检查的所有黑匣子系统和软件,板载集成并支持与技术知识“的安全设计”决策者。

著录项

  • 来源
    《European journal of navigation》 |2019年第1期|11-18|共8页
  • 作者单位

    Fraunhofer Center for Maritime Logistics and Services Am Schwarzenberg-Campus 4 GebAEude D 21073 Hamburg Germany;

    Fraunhofer Center for Maritime Logistics and Services Am Schwarzenberg-Campus 4 GebAEude D 21073 Hamburg Germany;

    Fraunhofer Center for Maritime Logistics and Services Am Schwarzenberg-Campus 4 GebAEude D 21073 Hamburg Germany;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号