An In-Depth Security Assessment of Maritime Container Terminal Software Systems

An In-Depth Security Assessment of Maritime Container Terminal Software Systems
复制标题

DOI:
10.1109/access.2020.3008395
复制
发表时间:
2020-06
期刊:
影响因子:
3.9
通讯作者:
Joseph O. Eichenhofer;E. Heymann;B. Miller;Arnold Kang
Joseph O. Eichenhofer;E. Heymann;B. Miller;Arnold Kang
中科院分区:
计算机科学3区
文献类型:
--
作者:
Joseph O. Eichenhofer;E. Heymann;B. Miller;Arnold Kang

文献摘要

被引文献

相似文献

对软件系统的攻击每天都在世界范围内发生,目标包括个人、公司和政府。促进海运的系统面临严重中断的风险,这些中断可能源于这些系统中使用的软件和流程的漏洞。这些漏洞使这些系统容易受到网络攻击。对海运系统安全的评估侧重于确定风险,但没有采取关键的(和昂贵的)下一步,即实际确定这些系统中存在的漏洞。虽然这种风险评估很重要,但没有详细查明控制这些港口及其码头的系统中的安全问题。作为回应,我们在一个经验丰富的学术网络安全团队和一个管理海运的知名商业软件提供商之间建立了一个重要的合作关系。我们对海运过程中涉及的信息流进行了分析,然后对管理货运系统的软件进行了深入的脆弱性评估。在本文中,我们展示了货运过程中涉及的信息流,并解释了我们如何进行深入评估,总结了我们的发现。与所有大型软件系统一样,海运系统也存在漏洞。
Attacks on software systems occur world-wide on a daily basis targeting individuals, corporations, and governments alike. The systems that facilitate maritime shipping are at risk of serious disruptions, and these disruptions can stem from vulnerabilities in the software and processes used in these systems. These vulnerabilities leave such systems open to cyber-attack. Assessments of the security of maritime shipping systems have focused on identifying risks but have not taken the critical (and expensive) next step of actually identifying vulnerabilities present in these systems. While such risk assessments are important, they have not provided the detailed identification of security issues in the systems that control these ports and their terminals. In response, we formed a key collaboration between an experienced academic cybersecurity team and a well-known commercial software provider that manages maritime shipping. We performed an analysis of the information flow involved in the maritime shipping process, and then executed an in-depth vulnerability assessment of the software that manages freight systems. In this paper, we show the flow of information involved in the freight shipping process and explain how we performed the in-depth assessment, summarizing our findings. Like every large software system, maritime shipping systems have vulnerabilities.