About | Contact Us | Register | Login
ProceedingsSeriesJournalsSearchEAI
Science and Technologies for Smart Cities. 6th EAI International Conference, SmartCity360°, Virtual Event, December 2-4, 2020, Proceedings

Research Article

Automatic Generation of Security Requirements for Cyber-Physical Systems

Download(Requires a free EAI acccount)
3 downloads
Cite
BibTeX Plain Text
  • @INPROCEEDINGS{10.1007/978-3-030-76063-2_26,
        author={Jinghua Yu and Stefan Wagner and Feng Luo},
        title={Automatic Generation of Security Requirements for Cyber-Physical Systems},
        proceedings={Science and Technologies for Smart Cities. 6th EAI International Conference, SmartCity360°, Virtual Event, December 2-4, 2020, Proceedings},
        proceedings_a={SMARTCITY},
        year={2021},
        month={5},
        keywords={Security analysis STPA framework Pattern matching Empirical repository},
        doi={10.1007/978-3-030-76063-2_26}
    }
    
  • Jinghua Yu
    Stefan Wagner
    Feng Luo
    Year: 2021
    Automatic Generation of Security Requirements for Cyber-Physical Systems
    SMARTCITY
    Springer
    DOI: 10.1007/978-3-030-76063-2_26
Jinghua Yu1,*, Stefan Wagner2, Feng Luo1
  • 1: Tongji University, Caoan Highway 4800
  • 2: University of Stuttgart, Universitätsstraße 38
*Contact email: yujinghua@tongji.edu.cn

Abstract

Security is one of the essential properties in Cyber-Physical Systems (CPS). Attacking systems like autonomous vehicles and health-care systems may lead to financial or privacy losses of stakeholders or even life threats. Security analysis, as an early activity in the system design, addresses security issues and identifies system vulnerabilities in advance to guide further security design. However, the security analysis is mostly performed manually requiring a high workload with human oversight. Besides, the manual analysis is not flexible for modification in later design stages and largely depends on expert knowledge and experience. Therefore, a new security analysis approach has been proposed in this paper to generate security requirements automatically, which is based on the System-Theoretic Process Analysis (STPA) framework and is applicable for data-flow-based CPSs. We have also developed a software prototype to support the implementation of this automatic approach and used it to obtain the security requirements of two CPSs in the automotive domain. Finally, we compared the automatically generated outcomes with the manually obtained ones and evaluated the proposed approach. Based on the experiment results, we found that the automatic way is efficient, effective and flexible. Furthermore, the proposed approach is also extensible. Analysts in a team can establish their own empirical repository to achieve accurate security requirements for their specific systems.

Keywords
Security analysis STPA framework Pattern matching Empirical repository
Published
2021-05-22
Appears in
SpringerLink
http://dx.doi.org/10.1007/978-3-030-76063-2_26
Copyright © 2020–2025 ICST
EBSCOProQuestDBLPDOAJPortico
EAI Logo

About EAI

  • Who We Are
  • Leadership
  • Research Areas
  • Partners
  • Media Center

Community

  • Membership
  • Conference
  • Recognition
  • Sponsor Us

Publish with EAI

  • Publishing
  • Journals
  • Proceedings
  • Books
  • EUDL