Andre Bröring

dblp:248/8742 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2023
0000-0002-4656-8836ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2023 Evaluation Concept for Prototypical Implementation towards Automated Security Risk Assessments
abstract
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of systems necessitate continuous security engineering. Therefore, this work in progress presents the specification and prototypical implementation for automated security risk assessments. In addition, an outlook towards the associated validation, verification, evaluation, and hypothesis testing is given.
Marco Ehrlich, Andre Bröring, Henning Trsek, Jürgen Jasperneite, Christian Diedrich
ETFA2
2023 Determining the Target Security Level for Automated Security Risk Assessments
abstract
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of system structures necessitate a continuous and automated security engineering, especially by application of the mandatory security risk assessments. Collecting the required information for these assessments and formalising expert knowledge shall improve the security of modular manufacturing systems in the future. In order to automate the security risk assessment process, this work proposes a method to determine the Target Security Level (SL-T) in conformance to the IEC 62443 standard based on the MITRE ATT&CK framework and the Intel Threat Agent Library (TAL).
Marco Ehrlich, Andre Bröring, Christian Diedrich, Jürgen Jasperneite, Wolfgang Kastner, Henning Trsek
INDIN2
2022 Towards an Asset Administration Shell Integrity Verification Scheme
abstract
Integrity as one property of trustworthiness is an important aspect for the adoption of the Asset Administration Shell (AAS) as a data exchange format and source for data driven services. Until now, the AAS offers an access control solution as a preventive integrity measure. Nevertheless, preventive methods lack in detecting integrity violations due to accidental or malicious modifications from access permitted endpoints. This work in progress paper proposes a concept to complement the access control with a detective integrity measure. By signing submodels of the AAS, business partners along the life cycle can verify the integrity of the data inside the AAS. Therefore, a Certificates Submodel and a Signature Submodel are proposed in the concept to enable a flexible and interoperable integrity verification. In future work, the concept will be implemented and evaluated.
Andre Bröring, Marco Ehrlich, Lukasz Wisniewski, Henning Trsek, Stefan Heiss
ETFA1