Dear all,
We submitted the paper "Incremental Common Criteria Certification
Processes using DevSecOps Practices" to EuroSPW 2021. We request to
acknowledge SPARTA if the paper is accepted.
Abstract:
The growing digitalisation of our economies and societies is driving the
need for increased connectivity of critical applications and
infrastructures to the point where failures can lead to important
disruptions and consequences to our lives. One growing source of
failures for critical applications and infrastructures originates from
cybersecurity threats and vulnerabilities that can be exploited in
attacks. One approach to mitigating these risks is verifying that
critical applications and infrastructures are sufficiently protected by
certification of products and services. However, reaching sufficient
assurance levels for product certification may require detailed
evaluation of product properties. An important challenge for product
certification is dealing with product evolution: now that critical
applications and infrastructures are connected they are being updated on
a more frequent basis. To ensure continuity of certification, updates
must be analysed to verify the impact on certified cybersecurity
properties. Impacted properties need to be re-certified. This paper
proposes a lightweight and flexible incremental certification process
that can be integrated with DevSecOps practices to automate as much as
possible evidence gathering and certification activities. The approach
is illustrated on the Common Criteria product certification scheme and a
firewall update on an automotive case study. Only the impact analysis
phase of the incremental certification process is illustrated.
Best Regards,
--
Sebastien Dupont
Expert Research Engineer
Model-Based Engineering and Distributed Systems
CETIC
Avenue Jean Mermoz 28
B-6041 Charleroi
Tel: +32 488 237 483
Dear members of SPARTA dissemination WP,
I would like to inform you that the below list SPARTA papers have been published or under publication:
The DOI is indicated for the access of the published journal and I will give you the DOI of the paper under publication soon. They will be in the WP6 publications directory.
Best regards,
Jean-Luc Danger
Papers already published in 2021:
* V. Khuat, J. -M. Dutertre and J. -L. Danger, "Analysis of a Laser-induced Instructions Replay Fault Model in a 32-bit Microcontroller," 2021 24th Euromicro Conference on Digital System Design (DSD) , 2021, pp. 363-370,
DOI: 10.1109/DSD53832.2021.00061
* V. Khuat, J. -L. Danger and J. -M. Dutertre, "Laser Fault Injection in a 32-bit Microcontroller: from the Flash Interface to the Execution Pipeline," 2021 Workshop on Fault Detection and Tolerance in Cryptography (FDTC) , 2021, pp. 74-85,
DOI: 10.1109/FDTC53659.2021.00020
* J.-M. Dutertre, A. Menu, O. Potin, J.-B. Rigaud, and J.-L. Danger, "Experimental analysis of the electro-magnetic instruction skip fault model and consequences for software countermeasures."cMicroelectronics Reliability, 121, 2021.
[ https://doi.org/10.1016/j.microrel.2021.114133 ]
DOI:10.1016/j.microrel.2021.114133
Papers under publication in 2021:
* V. Khuat, O. Trabelsi, L. Sauvage, J-L. Danger. "Multiple and Reproducible Fault Models on Micro-Controller using Electromagnetic Fault Injection". 2021 JOINT IEEE INTERNATIONAL SYMPOSIUM ON ELECTROMAGNETIC COMPATIBILITY, SIGNAL & POWER INTEGRITY, AND EMC EUROPE , Jul 2021 , Virtuel, France.
* Tebelmann, L., Kühne, U., Danger, J. L., & Pehl, M. (2021). Analysis and Protection of the Two-metric Helper Data Scheme. COSADE Workshop, oct 2021 , Lugano
--
[ https://www.telecom-paris.fr/ ]
Jean-Luc DANGER
Enseignant-Chercheur
01 75 31 93 19
Nouvelle adresse :
19 place Marguerite Perey
CS 20031
91123 Palaiseau Cedex
[ https://www.telecom-paris.fr/ ] [ https://twitter.com/TelecomParis_ ] [ https://www.facebook.com/TelecomParis ] [ https://www.linkedin.com/school/telecom-paris/ ] [ https://www.instagram.com/telecom_paris/ ] [ https://blogrecherche.wp.imt.fr/ ]
Une école de [ https://www.imt.fr/ | l'IMT ]
Dear All,
New OA paper (announced some time ago) is now published by ITTI - it
results and acknowledges SPARTA and it is relevant to SAFAIR and ELSA (as
requested by reviewers):
Choraś, M., Woźniak, M. The double-edged sword of AI: Ethical Adversarial
Attacks to counter artificial intelligence for crime. AI Ethics (2021).
It is available online here:
https://doi.org/10.1007/s43681-021-00113-9
or as a PDF here:
https://link.springer.com/content/pdf/10.1007/s43681-021-00113-9.pdf.
Kind Regards,
Prof. Michal Choras
Dear All,
Two new papers by ITTI resulting from SPARTA (SAFAIR programme) are now
published:
1.
The proposition of balanced and explainable surrogate method for
network intrusion detection in streamed real difficult data
By: Szczepanski, Komisarek, Pawlicki, Kozik, Choras.
Venue: ICCCI 2021 conference (core B)
Link:
https://link.springer.com/chapter/10.1007/978-3-030-88113-9_19
2.
paper in JCR journal ENTROPY:
Preprocessing Pipelines Including Block-Matching Convolutional Neural
Network for Image Denoising to Robustify Deep Reidentification against
Evasion Attacks
Link:
https://www.mdpi.com/1099-4300/23/10/1304
Kind Regards,
Prof. Michal Choras