Understanding, Implementing, and Supporting Security Assurance Cases in Safety-Critical Domains
Doctoral thesis, 2023

The increasing demand for connectivity in safety-critical domains has made security assurance a crucial consideration. In safety-critical industry, software, and connectivity have become integral to meeting market expectations. Regulatory bodies now require security assurance cases (SAC) to verify compliance, as demonstrated in ISO/SAE-21434 for automotive. However, existing approaches for creating SACs do not adequately address industry-specific constraints and requirements. In this thesis, we present CASCADE, an approach for creating SACs that aligns with ISO/SAE-21434 and integrates quality assurance measures. CASCADE is developed based on insights from industry needs and a systematic literature review. We explore various factors driving SAC adoption, both internal and external to companies in safety-critical domains, and identify gaps in the existing literature. Our approach addresses these gaps and focuses on asset-driven methodology and quality assurance. We provide an illustrative example and evaluate CASCADE’s suitability and scalability in an automotive OEM. We evaluate the generalizability of CASCADE in the medical domain, high-lighting its benefits and necessary adaptations. Furthermore, we support the creation and management of SACs by developing a machine-learning model to classify security-related requirements and investigating the management of security evidence. We identify deficiencies in evidence management practices and propose potential areas for automation. Finally, our work contributes to the advancement of security assurance practices and provides practical support for practitioners in creating and managing SACs.

Assurance case

Evidence

Automotive systems

Safety-critical

Security claims

Arguments

Security

Rum Alfa, Hus Saga, Institutionen för Data- och informationsteknik, Hörselgången 4, Campus Lindholmen, Göteborg
Opponent: Professor Arosha K. Bandara, The Open University, Great Britain

Author

Mazen Mohamad

Chalmers, Computer Science and Engineering (Chalmers), Interaction Design and Software Engineering

CASCADE: An Asset-driven Approach to Build Security Assurance Cases for Automotive Systems

ACM Transactions on Cyber-Physical Systems,;Vol. 7(2023)

Journal article

Security Assurance Cases – State of the Art of an Emerging Approach

Empirical Software Engineering,;Vol. 26(2021)

Journal article

Identifying security-related requirements in regulatory documents based on cross-project classification

PROMISE 2022 - Proceedings of the 18th International Conference on Predictive Models and Data Analytics in Software Engineering, co-located with ESEC/FSE 2022,;(2022)p. 82-91

Paper in proceeding

Assurance Cases for Road Vehicles: an Industry Perspective

ARES '20: Proceedings of the 15th International Conference on Availability, Reliability and Security,;(2020)

Paper in proceeding

CASUS: Building Security Assurance Cases in Automotive Open Systems

VINNOVA, -- .

Subject Categories (SSIF 2011)

Software Engineering

Computer Science

Computer Systems

ISBN

978-91-8069-330-1

Doktorsavhandlingar vid Chalmers tekniska högskola. Ny serie

Publisher

University of Gothenburg

Rum Alfa, Hus Saga, Institutionen för Data- och informationsteknik, Hörselgången 4, Campus Lindholmen, Göteborg

Opponent: Professor Arosha K. Bandara, The Open University, Great Britain

More information

Latest update

2/15/2024