EDBT 2026 Demo / reviewers in the wild / expert
Siegfried Hollerer
dblp:297/4816
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2024
0000-0002-3814-6019ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 3 first-author · 5 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Integrated Safety and Security by Design in the IT/OT Convergence of Industrial Systems: A Graph-Based ApproachabstractThe convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 poses fresh challenges, demanding innovative strategies to ensure the safe execution of production processes. With the increasing significance of production system integrity, any security breaches can lead to severe consequences like production downtime, equipment damage, or human harm. Our prior research on Austrian industrial automation stakeholders highlighted the necessity for a cost-effective, all-encompassing approach to the integrated safety and security. We introduced an extensive ontology for safety, security, and operational requirements in IT/OT convergence. This paper presents an approach of Model-Based Systems Engineering (MBSE) for the integrated safety and security by design of industrial systems. We employ the Systems Modeling Language (SysML) 2.0 for precise modeling. We define metadata information that are used as tags for SysML 2.0 model instances. Afterwards, we create a graph-based model of the system. These graphs are used to validate safety and security standards and requirements. Finally, we automatically generate artifacts, such as code or documentation, which adhere to the standards. Our approach is extensible and supports reusability already after covering two standards. Having provided support for the standards IEC 62443-3-3 and IEC 61508, we reuse our approach to validate the standard ISO 13850:2015. Amirali Amiri, Gernot Steindl, Ian Gorton, Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
SSE | 4 |
| 2023 | Towards a Comprehensive Ontology Considering Safety, Security, and Operation Requirements in OTabstractThe convergence of Information Technology (IT) and Operational Technology (OT) increases the interdependencies of operation, safety, and security requirements of OT systems. Cyber attacks may interfere with safety functionality which may lead to severe injuries. A possible conflict between safety and security is the usage of authentication. A safety requirement for machinery is violated if a safety function is not accessible at all times (e.g., due to the usage of authentication). There is a variety of standards and best practices on how to implement security or safety from an isolated viewpoint. Some standards even consider safety and security or link at least to other standards when the other domain has to be considered. However, there is no integrated approach to address conflicts between safety and security. Other relevant domains needed for risk or site managers (e.g., operation, product quality, risk evaluation, and risk treatment) are not addressed in a single holistic standard or approach. Without holistic guidance, risk managers are forced to solve this issue manually on best effort or include knowledge of domain experts who provide their expertise which is typically bound to a single domain in scope of the manager’s interest. Due to the complex interdisciplinary interplay of these domains, knowledge representation using ontologies may be key to model all relations and constraints needed for risk or state managers to consider in their risk managing business process. Therefore, this work presents the results of a literature survey analyzing several ontologies considering at least one relevant domain to address when performing risk management at OT systems. Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
ETFA | 1 |
| 2023 | Safety and Security: A Field of Tension in Industrial PracticeabstractThe convergence of Information Technology (IT) and Operational Technology (OT) leads to an increasing interdependence between the protection goals of security and safety. A cyber-attack targeting safety functions may in turn lead to hazards endangering people and the environment. Furthermore, misusing safety functions may impact availability by causing a machine or production line to stop working. This work analyzes how Austrian stakeholders of industrial automation enterprises address security and safety risks to mitigate undesired situations. The stakeholder analysis performed considers vendors of products or components, integrators, and asset owners of industrial systems. Secure infrastructures, system architectures, and risk management are subject areas of this analysis. The analysis was conducted in two phases. First, an online survey was created where the involved stakeholder offered their answer simultaneously. Considering the results of the survey, individual stakeholder workshops were carried out to obtain additional, more specific perceptions about the stakeholder’s OT system and components with respect to security and safety considerations. The obtained results provide insights into the current practices in the industry regarding safety and security. Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
INDIN | 1 |
| 2023 | Combining Models for Safety and Security Concerns in Automating Digital ProductionabstractThe IEC 62061:2021 standard requires production owners to ensure both functional safety and information security for their industrial applications. Unfortunately, traditional models of functional safety and information security have been designed in isolation and are difficult to combine. This paper introduces the Safety & Security Combination (SafeSecCombi) approach to combine models for functional safety and security concerns in automating digital production. SafeSecCombi (i) validates causes for desired and undesired effects regarding safety in an industrial production process by linking these causes to products, production processes, and production resources; (ii) identifies Industrial Internet of Things (IIoT) assets that can cause unsafe behavior in case of a successful security attack; and (iii) analyzes risks of security attacks to these IIoT assets. Therefore, SafeSecCombi provides a model for the combined analysis of safety and security concerns regarding a Cyber-Physical Production System (CPPS). In a feasibility study on an industrial work cell for metal processing with a collaborative robot, we evaluated the effectiveness and efficiency of the SafeSecCombi approach. Results indicate that the SafeSecCombi approach is feasible and effective, and provides safety and security experts with actionable, context-specific causes for security-related safety issues and countermeasures that are well grounded in engineering models, as a foundation to address the IEC 62061:2021 requirements. Sebastian Kropatschek, Siegfried Hollerer, David Hoffman, Dietmar Winkler 0001, Arndt Lüder, Thilo Sauter, Wolfgang Kastner, Stefan Biffl |
INDIN | 2 |
| 2022 | Risk Assessments Considering Safety, Security, and Their Interdependencies in OT EnvironmentsabstractInformation Technology (IT) and Operational Technology (OT) are converging further, which increases the number of interdependencies of safety and security risks arising in industrial architectures. Cyber attacks interfering safety functionality may lead to serious injuries as a consequence. Intentionally triggering a safety function may introduce a security vulnerability during the emergency procedure, e.g., by opening emergency exit doors leading to enabling unauthorized physical access. This paper introduces a risk evaluation methodology to prioritize and manage identified threats considering security, safety, and their interdepedencies. The presented methodology uses metrics commonly used in the industry to increase its applicability and enable the combination with other risk assessment approaches. These metrics are Common Vulnerability Scoring System (CVSS), Security Level (SL) from the standard IEC 62443 and Safety Integrity Level (SIL) from the standard IEC 61508. Conceptional similarities of those metrics are considered during the risk calculation, including an identified relation between CVSS and SL. Besides this relation, the skill level and resources of threat actors, threats enabling multiple identified attacks, the SIL of safety-relevant components affected, business criticality of the targeted asset, and the SL-T of the zone targeted by the attack are considered for risk evaluation. The industrial architecture to be analyzed is separated into zones and conduits according to IEC 62443, enabling the analyzed system to be compliant with its requirements. Siegfried Hollerer, Thilo Sauter, Wolfgang Kastner |
ARES | 1 |
| 2022 | Combined Modeling Techniques for Safety and Security in Industrial Automation: A Case StudyabstractThe interconnection of automation technology with IT systems, also referred to as Industry 4.0, enables cyber attacks to impact safety (e.g., TRITON malware). Conversely, installed safety functions and requirements may also affect security requirements (e.g., the emergency stop function has to be avail-able without prior authentication and authorization). Therefore, threat modeling (TM) methods considering security, safety, and their interdependence are needed to get a comprehensive view of potential flaws of an industrial architecture. This paper presents a case study of the TM methods STRIDE-LM and Failure-Attack-CounTermeasure (FACT) graph w.r.t. the identification of safety and security flaws and their interdependence, with the aim to provide an impression of possible solutions to the described problem. The study was applied to a use case derived from a stakeholder analysis showing common characteristics and requirements of industrial automation systems. As STRIDE-LM was designed only to consider security flaws, it was extended to cover safety aspects as well. Preliminary results of the application of the TM methods show differences in efficiency, precision, and the granularity of information provided. Siegfried Hollerer, Marta Chabrová, Thilo Sauter, Wolfgang Kastner |
SIN | 1 |
| 2021 | Identification of security threats, safety hazards, and interdependencies in industrial edge computing
Patrick Denzler, Siegfried Hollerer, Thomas Frühwirth, Wolfgang Kastner |
SEC | 2 |
| 2021 | Towards a Threat Modeling Approach Addressing Security and Safety in OT EnvironmentsabstractIn Industry 4.0, Information Technology (IT) and Operational Technology (OT) tend to converge further with an increasing interdependence of safety and security issues to be considered. On one hand, cyber attacks are possible which can alter implemented safety functionality leading to situations where people are harmed, serious injuries may occur or the environment gets damaged. On the other side, safety can also impact security. For instance, the misuse of a Safety Instrumented System (SIS) may force a machine or a production line to shut down resulting in a denial of service. To prevent or mitigate risks from such scenarios, this paper proposes a threat modeling technique which addresses an integrated view on safety and security. The approach is tailored to the industrial automation domain considering plausible attacks and evaluating risks based on three different metrics. The metrics selected consist of Common Vulnerability Scoring System (CVSS) used as an international standard for rating cyber security vulnerabilities, Security Level (SL) from IEC 62443 to rate cyber security risks in OT environments w.r.t. the underlying architecture, and Safety Integrity Level (SIL) from IEC 61508 to rate safety risks. Due to the variety of use cases involving the chosen metrics, the approach is also feasible for followup analyses, such as integrated safety and security assessments or audits. Siegfried Hollerer, Wolfgang Kastner, Thilo Sauter |
WFCS | 1 |