
@article{ref1,
title="Cybersecurity and its integration with safety for transport systems: not a formal fulfillment but an actual commitment",
journal="Transportation research procedia",
year="2020",
author="Pizzi, Giorgio",
volume="45",
number="",
pages="250-257",
abstract="Vulnerabilities and hacking cases in transport systems are already documented. In the last two or three years guidelines and methods for cybersecurity in transport systems have been drafted and the importance of convergence of safety and cybersecurity has been stressed. Many companies today offer products and services for this field. There is the risk, however, that such an important matter will be considered as a formal fulfillment. In order to promote a real awareness about vulnerabilities affecting transport systems technologies, which rely mostly on embedded devices, and about the attacks that can exploit them, we use as an example a real incident involving a safety-critical subsystem of a railway vehicle (that we think of as a &quot;cyber-physical system&quot;) to develop a case study concerning a cyberattack, aiming to show that devices and technological systems vulnerabilities must not be neglected in risk analysis. Conversely, they must be taken into account the same way as hazards in safety assessments for an effective integration between cybersecurity and safety. Therefore we propose an attack-fault tree for the case study as an example of integrated risk analysis.<p /> <p>Language: en</p>",
language="en",
issn="2352-1465",
doi="10.1016/j.trpro.2020.03.014",
url="http://dx.doi.org/10.1016/j.trpro.2020.03.014"
}