DocumentCode :
3590264
Title :
Tools and techniques for reporting and analysing the causes of cyber-security incidents in safety-critical systems
Author :
Johnson, C.W.
Author_Institution :
Sch. of Comput. Sci., Univ. of Glasgow, Glasgow, UK
fYear :
2014
Firstpage :
1
Lastpage :
7
Abstract :
Incident reporting is a component of safety management systems across many industries. Their perceived success has led to the development of similar approaches in cyber security; information about previous attacks can be used to identify wider vulnerabilities and to inform future threat assessments. However, it can be difficult to integrate safety and security reporting within a single system. For example, in safety reporting systems the aim is often to disseminate lessons as widely as possible. In cyber security, there is a concern that this might motivate and inform further attacks. This paper identifies the challenges that arise in developing reporting schemes for security incidents in safety-critical applications. In particular we focus on the problems of implementing intrusion detection systems and coordinating forensic analysis without undermining system safety. These problems are exacerbated because existing cyber-security reporting guidelines focus more on office based systems than complex, command and control applications.
Keywords :
digital forensics; safety-critical software; Cyber attack; Cyber-security incidents; coordinating forensic analysis; information vulnerabilities; intrusion detection systems; office based systems; reporting scheme; safety management systems; safety-critical systems; security incidents; threat assessment; Cyber-Security; Forensics; Incident Reporting; Intrusion Detection Systems; Safety-Critical Systems;
fLanguage :
English
Publisher :
iet
Conference_Titel :
System Safety and Cyber Security (2014), ??????9th IET International Conference on
Print_ISBN :
978-1-84919-940-7
Type :
conf
Filename :
7111733
Link To Document :
بازگشت