{"title":"The Fuzzy Integrated Evaluation of Embedded System Security","authors":"Shaolong Zhang, N. Zhou, Jiaxin Wu","doi":"10.1109/ICESS.2008.49","DOIUrl":null,"url":null,"abstract":"Today, the embedded systems field is growing rapidly, ranging from low-end systems such as cellular phones, PDAs, smart cards to high-end systems such as gateways, firewalls, storage servers, and web server. Security of embedded system becomes a paramount issue in embedded system design. Compared to an embedded system's functionality and other design metric (e.g., area, performance, power), security is currently specified by system architects in a vague and imprecise manner. This paper proposes a fuzzy integrated security evaluation method based on man-computer combined data collection and fuzzy expert evaluation in Delphi method. The method could reduce the subjectivity of expert evaluation and alleviate the difficulty of data collection and makes possible a better combination of qualitative and quantitative evaluations. Firstly, the hierarchy structure model of embedded system security is constructed. Secondly, according to data collected and the evaluation comment of each expert, the subjection degree matrix is constructed. Finally, a new concept of ldquodegree of assurancerdquo is presented for the quantificational evaluation of embedded system security. In this paper a study of a wireless biometric authentication device is also shown. The case illustrates that the method can be easily used and its results conform to the actual situation.","PeriodicalId":278372,"journal":{"name":"2008 International Conference on Embedded Software and Systems","volume":"40 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-07-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 International Conference on Embedded Software and Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICESS.2008.49","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Today, the embedded systems field is growing rapidly, ranging from low-end systems such as cellular phones, PDAs, smart cards to high-end systems such as gateways, firewalls, storage servers, and web server. Security of embedded system becomes a paramount issue in embedded system design. Compared to an embedded system's functionality and other design metric (e.g., area, performance, power), security is currently specified by system architects in a vague and imprecise manner. This paper proposes a fuzzy integrated security evaluation method based on man-computer combined data collection and fuzzy expert evaluation in Delphi method. The method could reduce the subjectivity of expert evaluation and alleviate the difficulty of data collection and makes possible a better combination of qualitative and quantitative evaluations. Firstly, the hierarchy structure model of embedded system security is constructed. Secondly, according to data collected and the evaluation comment of each expert, the subjection degree matrix is constructed. Finally, a new concept of ldquodegree of assurancerdquo is presented for the quantificational evaluation of embedded system security. In this paper a study of a wireless biometric authentication device is also shown. The case illustrates that the method can be easily used and its results conform to the actual situation.