Providing Security Assurance & Hardening for Open Source Software/Hardware: The SecOPERA approach

2023 IEEE 28th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD)(2023)

引用 0|浏览0
暂无评分
摘要
Rapid open-source software and hardware prototyping fueled by the significant expansion of the development community, led to the deployment of highly sophisticated frameworks, solutions and products. However, as the provided open-source solutions are managed in all aspects by their designers/engineers, they lack professional evaluation of their security level. The absence of comprehensive security assessment as well as a consolidated and ubiquitous roadmap for vulnerability patching and security hardening, makes open-source solution a risk for widespread enterprise use. This paper introduces a security assurance approach which addresses open-source hardware and software shortcoming in an end-to-end manner, by providing a logical decomposition of any such module into four distinct component layers: device, network, application and cognitive. This allows highly focused security assessment, taking into consideration the specific characteristics of each layer. In addition, the paper provides an approach on how open-source solution security can be improved, through decomposition, layered vulnerability mitigation and specialized security hardening techniques. The proposed framework which is the main research and innovation focus of the SecOPERA Project intends to transform an open source solution to a protected one, as well as provide security guarantees of its overall security status.
更多
查看译文
关键词
Security Assessment,Security Hardening,Open Source Software,Open Source Hardware
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要