<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="client.xsl" type="text/xsl"?>
<article article-type="other">
<front>
<journal-meta>
<journal-id/>
<issn/>
<banner>
<href>banner.jpg</href>
<size width="100%"/>
</banner>
</journal-meta>
<doi>0207-cd</doi>
<article-meta>
<title-group>
<article-title>Improving Security and Safety Co-analysis of STPA</article-title>
</title-group>

<author>Erik Nilsen Torkildson<sup>1</sup>, Jingyue Li<sup>2</sup> and Stig Ole Johnsen<sup>3</sup></author>

<aff><sup>1</sup>Wise Consulting, Molde, Norway</aff>
<email><a href="mailto:ent@wise.no">ent@wise.no</a></email>
<aff><sup>2</sup>Department of Computer Science, Norwegian University of Science and Technology, Norway</aff>
<email><a href="mailto:jingyue.li@ntnu.no">jingyue.li@ntnu.no</a></email>
<aff><sup>3</sup>SINTEF Digital, Norway</aff>
<email><a href="mailto:Stig.O.Johnsen@sintef.no">Stig.O.Johnsen@sintef.no</a></email>

</article-meta></front>
<body>
<abstract>
<title>ABSTRACT</title>
<p>Many safety and security co-analysis methods have been proposed to assure the safety of critical systems, including autonomous systems. One example of safety and security co-analysis approach is Systems-Theoretic Process Analysis (STPA) plus STPA-Sec. When using STPA combined with STPA-Sec, the security analysis is performed as part of the causal factor analysis, which is after the safety risk analysis. Few studies have questioned whether such an approach can be improved and how to improve it. In our study, we tried to answer two research questions (RQs): RQ1) Could we improve STPA-Sec by complementing it with threat modeling approaches? RQ2) Could we find more safety risks if we perform security analysis before safety analysis? We performed safety and security co-analysis of an autonomous boat to answer these research questions. Results of the study show that performing security analysis before safety analysis identifies more safety risks than the other way around. To be combined with STPA-Sec, threat modeling based on the data flow diagram outperforms other threat modeling approaches we evaluated.</p>
<p><italic>Keywords: </italic>Cyber Security, Safety, Threat Modelling, Autonomous Systems, STPA</p>
</abstract>
<fpdf>
<href>pdflogo.jpg</href>
<hpdf>0207</hpdf>
</fpdf>
</body>
</article>