Publication:
About the Security Assessment of Embedded Software in Automated Process Control System

Дата
2020
Авторы
Journal Title
Journal ISSN
Volume Title
Издатель
Научные группы
Организационные подразделения
Организационная единица
Институт интеллектуальных кибернетических систем
Цель ИИКС и стратегия развития - это подготовка кадров, способных противостоять современным угрозам и вызовам, обладающих знаниями и компетенциями в области кибернетики, информационной и финансовой безопасности для решения задач разработки базового программного обеспечения, повышения защищенности критически важных информационных систем и противодействия отмыванию денег, полученных преступным путем, и финансированию терроризма.
Выпуск журнала
Аннотация
© 2020, Springer Nature Switzerland AG.This work explores theoretical related to the assessment of the embedded software security of programmable logic controllers (PLC) of industrial cyber-physical systems, which are the basic components of automated process control systems. Analysis of the relevance of the problem of evaluating software security has performed, correlation between software complexity and number of vulnerabilities has elucidated. The key features of embedded software affecting information security has identified. A formal approach to the assessment of security, based on the achievement of two indicators, modern software research methods for the presence of vulnerabilities and undeclared capabilities has been considered their shortcomings have covered, in particular, dependence on expert qualifications and open source orientation on vulnerability information. The use of a risk-based approach to the assessment of security, based on the family of standards ISO 29119-2013 has proposed. The proposed refinement and expansion of the basic methods of software in terms of assessing the security of software. Refinements and extensions of the basic software methodology in terms of software security assessment have proposed. The characteristic features and benefits of a risk-based approach have formulated.
Описание
Ключевые слова
Цитирование
Korsakov, I. A. About the Security Assessment of Embedded Software in Automated Process Control System / Korsakov, I.A., Durakovskiy, A.P. // Mechanisms and Machine Science. - 2020. - 80. - P. 387-394. - 10.1007/978-3-030-33491-8_46
Коллекции