论文部分内容阅读
0.引言飞机信息网络系统日益复杂化的同时也带来了飞行安全边界不断被威胁的负面影响,包括:内部失效,设计或者研制的失误以及使用不当。安全性分析过程一直被用来应对此类影响,颁布的相应标准也对安全性评估过程和研制保证提供指导。然而,由于机载网络的高度集成化也使得关键系统与外界的接触机会明显变大。尤其是一些充满挑战性的旨在提供新的服务,减轻空管压力,缩短研制和维护时间,节约成本等方面的创新都给网络安保带来了巨大挑战。与此同时,一种负面影响也逐渐暴露并日益引起审定方的关注,那就是对于故意或偶然攻击的脆弱性。实际上,EUROCAE和RTCA也对此定义了新的适航安保标准:ED202,旨在提出对于信息安全问题的适航安保过程中的数据
0. INTRODUCTION The growing complexity of aircraft information network systems also poses the constant threat of negative impacts on flight safety boundaries, including internal failures, design or development failures, and misuse. The safety analysis process has been used to address such effects and the corresponding standards promulgated provide guidance on safety assessment processes and development assurances. However, due to the high degree of integration of airborne networks, access to critical systems and the outside world is also significantly increased. In particular, some challenging innovations aimed at providing new services, reducing air traffic control pressure, shortening the development and maintenance time, and saving costs have posed tremendous challenges to cyber security. In the meantime, a negative impact is also gradually exposed and increasingly aroused the concern of certifying parties as the vulnerability to deliberate or accidental attacks. In fact, EUROCAE and RTCA have also defined a new airworthiness security standard: ED202, designed to propose data on airworthiness security for information security issues