skip to main content
10.1145/3613372.3613373acmotherconferencesArticle/Chapter ViewAbstractPublication PagessbesConference Proceedingsconference-collections
research-article

Toward a Method for Safety and Security Requirements Alignment in Critical IoT Systems

Published: 25 September 2023 Publication History

Abstract

The complexity of critical IoT systems demands the joint treatment of safety and security requirements from the early system life cycle stages. Dealing with multiple (and sometimes conflicting) relationships between such requirements has been a great research need. We present a preliminary version of a method for the alignment of safety and security requirements for critical IoT systems based on the System Theoretic Process Analysis (STPA) technique. A simple use case of our method shows how those requirements are handled during the conception and elicitation phases. When fully defined, our method will help analysts handle safety and security as first-class concerns from conception to specification of critical IoT systems, including requirements dependencies and conflicts.

References

[1]
Christoph Binder 2021. Enabling Model-Based Requirements Engineering in a Complex Industrial System of Systems Environment. In 2021 26th IEEE Int. Conf. on Emerging Technologies and Factory Automation (ETFA). IEEE Press, 1–6.
[2]
Donald G Firesmith. 2003. Common concepts underlying safety security and survivability engineering. Technical Report. Carnegie-Mellon University.
[3]
Ivo Friedberg 2017. STPA-SafeSec: Safety and security analysis for cyber-physical systems. Journal of Information Security and Applications 34 (2017), 183–196.
[4]
Simon Fritz 2019. A Guideline for the Requirements Engineering Process of SMEs Regarding to the Development of CPS. In 2019 8th International Conference on Industrial Technology and Management (ICITM). 85–94.
[5]
Jon Arne Glomsrud and J Xie. 2019. A structured STPA safety and security co-analysis framework for autonomous ships. In European Safety and Reliability conference, Germany, Hannover.
[6]
Vaira Gromule 2017. Safety and Security of Passenger Terminal: the Case Study of Riga International Coach Terminal. Procedia Engineering 178 (2017), 147–154.
[7]
Georgios Kavallieratos 2020. SafeSec Tropos: Joint security and safety requirements elicitation. Computer Standards & Interfaces 70 (2020), 103429.
[8]
Shaharyar Khan and Stuart Madnick. 2022. Protecting Chiller Systems from Cyberattack Using a Systems Thinking Approach. Network 2, 4 (2022), 606–627.
[9]
Siwar Kriaa 2015. A survey of approaches combining safety and security for industrial control systems. Reliability Engineering & System Safety 139 (2015), 156–178.
[10]
Samantha Lautieri 2005. SafSec: Commonalities Between Safety and Security Assurance. In Safety-critical Systems Symposium.
[11]
Nancy G Leveson and John Thomas. 2018. STPA Handbook. MIT.
[12]
Elena Lisova 2019. Safety and Security Co-Analyses: A Systematic Literature Review. IEEE Systems Journal 13, 3 (2019), 2189–2200.
[13]
Anh Nguyen-Duc 2019. Minimum Viable Products for Internet of Things Applications: Common Pitfalls and Practices. Future Internet 11, 2 (2019).
[14]
Sara Sadvandi 2012. Safety and Security Interdependencies in Complex Systems and SoS: Challenges and Perspectives. In Complex Systems Design & Management. Springer Berlin Heidelberg, Berlin, Heidelberg, 229–241.
[15]
Ernesto Fonseca Veiga. 2023. Uma Abordagem para Alinhamento de Requisitos de Segurança e Proteção de Sistemas IoT Críticos. In Anais do XXVI Congresso Ibero-Americano em Engenharia de Software.
[16]
Ernesto Fonseca Veiga and Renato Freitas Bulcão-Neto. 2022. Engenharia de Requisitos de Sistemas IoT e Ciber-Físicos: Resultados Preliminares. In Anais do WER22 - Workshop em Engenharia de Requisitos.
[17]
Marilyn Wolf and Dimitrios Serpanos. 2018. Safety and Security in Cyber-Physical Systems and Internet-of-Things Systems. Proc. IEEE 106, 1 (2018), 9–20. https://doi.org/10.1109/JPROC.2017.2781198
[18]
Z. L. Yang and Z. Qu. 2016. Quantitative maritime security assessment: a 2020 vision. IMA Journal of Management Mathematics 27, 4 (05 2016), 453–470.
[19]
Xiang-Yu Zhou 2021. A system-theoretic approach to safety and security co-analysis of autonomous ships. Ocean Engineering 222 (2021), 108569.

Cited By

View all
  • (2024)Linking Agile Planning and Safety and Security Analysis in Critical IoT Systems: An Approach based on ISO/IEC/IEEE 15288Proceedings of the XXIII Brazilian Symposium on Software Quality10.1145/3701625.3701648(81-91)Online publication date: 5-Nov-2024

Recommendations

Comments

Information & Contributors

Information

Published In

cover image ACM Other conferences
SBES '23: Proceedings of the XXXVII Brazilian Symposium on Software Engineering
September 2023
570 pages
ISBN:9798400707872
DOI:10.1145/3613372
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].

Publisher

Association for Computing Machinery

New York, NY, United States

Publication History

Published: 25 September 2023

Permissions

Request permissions for this article.

Check for updates

Author Tags

  1. IoT
  2. critical
  3. requirements
  4. safety
  5. security
  6. system
  7. traceability

Qualifiers

  • Research-article
  • Research
  • Refereed limited

Funding Sources

  • Coordenação de Aperfeiçoamento de Pessoal de Nível Superior - Brasil (CAPES)

Conference

SBES 2023
SBES 2023: XXXVII Brazilian Symposium on Software Engineering
September 25 - 29, 2023
Campo Grande, Brazil

Acceptance Rates

Overall Acceptance Rate 147 of 427 submissions, 34%

Contributors

Other Metrics

Bibliometrics & Citations

Bibliometrics

Article Metrics

  • Downloads (Last 12 months)25
  • Downloads (Last 6 weeks)3
Reflects downloads up to 05 Mar 2025

Other Metrics

Citations

Cited By

View all
  • (2024)Linking Agile Planning and Safety and Security Analysis in Critical IoT Systems: An Approach based on ISO/IEC/IEEE 15288Proceedings of the XXIII Brazilian Symposium on Software Quality10.1145/3701625.3701648(81-91)Online publication date: 5-Nov-2024

View Options

Login options

View options

PDF

View or Download as a PDF file.

PDF

eReader

View online with eReader.

eReader

HTML Format

View this article in HTML Format.

HTML Format

Figures

Tables

Media

Share

Share

Share this Publication link

Share on social media