WP7 – Security and Privacy Claims
Coordinated by
UMU (M01-M12)
Objective
The main objective of this work package is to develop a security certification methodology combining risk assessment and testing to evaluate a system over a series of security and privacy claims based on objective metrics, allowing harmonisation and mutual recognition based on evidence that quantify the level of trust.
The specific goals of WP7 are to:
- Identify suitable security and privacy metrics and claims to evaluate the security and privacy of a system
- Develop a security certification methodology using the identified security and privacy metrics and claims.
Deliverables
- D7.1 Report on the identified security and privacy metrics and security claims to evaluate the security of a system WP7 (6 – UMU) Report Public M12
- D7.2 Security certification methodology definition WP7 (6 – UMU) Report Public M18
- D7.3 Security certification methodology development WP7 (6 – UMU) Report Public M24
Outcomes
Extension of the approach to the communications within the whole supply chain of the Microfactory
Once the secure communication with a vehicle has been demonstrated for remote FW update, it is straightforward to extend it to a general Service-Over-the-Air architecture and even further.
Ontology Manager Tool
Ontology Manager is a Framework responsible for managing the Core Ontology used in BIECO, called DAEMON. It aims to support organizing concepts and their relationships related to System of Systems (SoS), Internet of Things (IoT), and System Components management and Monitoring.
Vulnerabilities Forecasting Tool
The Vulnerabilities Forecasting Tool (VFT) provides historical vulnerability data and projections for time intervals of 1, 2, 3, 6, and 12 months for several major software components.
Failure Prediction Tool
The Failure Prediction Tool (FPT) performs failure predictions by monitoring the logs of the applications that make up a system. It has a REST interface through which it receives in real time the log messages from the monitored applications.
safeTbox
The pre-existing tool safeTbox (www.safetbox.de) has been extended to support interoperation with the ResilBlockly tool for combined safety and security analysis.
Conditional Safety Certificates for ICT
Conditional Safety Certificates (ConSerts) have been applied to support resiliency of ICT infrastructures. Support for deployment and execution of ConSerts in ICT infrastructure according to use case needs was provided additionally.