Thinking in Systems, Sifting Through Simulations: A Way Ahead for Cyber Resilience Assessment

被引:11
作者
Simone, Francesco [1 ]
Akel, Antonio Javier Nakhal [1 ]
Di Gravio, Giulio [1 ]
Patriarca, Riccardo [1 ]
机构
[1] Sapienza Univ Rome, Dept Mech & Aerosp Engn, I-00184 Rome, Italy
基金
中国国家自然科学基金;
关键词
Computer security; Accidents; Analytical models; Resilience; Modeling; Water pollution; Hazards; Industrial engineering; System dynamics; Cyber security; cyber-socio-technical systems; hazard analysis; industrial systems engineering; resilience management; systems modeling; RISK-MANAGEMENT; ACCIDENT MODEL; SAFETY; STAMP;
D O I
10.1109/ACCESS.2023.3241552
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The interaction between the physical world and information technologies creates advantages and novel emerging threats. Cyber-physical systems (CPSs) result vulnerable to cyber-related disruptive scenarios, and, for some critical systems, cyber failures may have fallouts on society and environment. Traditional risk analysis in no more sufficient to deal with these problems. New techniques are gaining increasing consensus, especially those based on systems theory. In this context, the System-Theoretic Process Analysis for Security (STPA-Sec) extends the Systems-Theoretic Accident Modelling and Processes (STAMP) model considering cyber threats, and identifying unsafe and unsecure controls throughout a cyber socio-technical system. Despite its large usage as a descriptive tool, there is still limited use of STPA-Sec in (semi-)quantitative terms. This article presents System-Theoretic Process Analysis for Security with Simulations (STPA-Sec/S), a methodological interface between STPA-Sec and quantitative resilience assessment based on simulation models. The methodology is instantiated in a demonstrative case study of a water treatment plant, and its critical CPSs which may impact both community health, and environment. The obtained results show how STPA-Sec/S foster systems understanding, allow a systematic identification of its major criticalities, and the respective quantification.
引用
收藏
页码:11430 / 11450
页数:21
相关论文
共 76 条
[1]   Integrated Safety Analysis Using Systems-Theoretic Process Analysis and Software Model Checking [J].
Abdulkhaleq, Asim ;
Wagner, Stefan .
COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2015, 2015, 9337 :121-134
[2]   Electronic medical records and risk management in hospitals of Saudi Arabia [J].
Al-Barnawi, Abdullah ;
He, Ying ;
Maglaras, Leandros A. ;
Janicke, Helge .
INFORMATICS FOR HEALTH & SOCIAL CARE, 2019, 44 (02) :189-203
[3]   Practical Resilience Metrics for Planning, Design, and Decision Making [J].
Ayyub, Bilal M. .
ASCE-ASME JOURNAL OF RISK AND UNCERTAINTY IN ENGINEERING SYSTEMS PART A-CIVIL ENGINEERING, 2015, 1 (03)
[4]  
Beaumont P., 2019, Critical Infrastructure Security and Resilience: Theories, Methods, Tools and Technologies, P159, DOI [10.1007/978-3-030-00024-0_9, DOI 10.1007/978-3-030-00024-0_9]
[5]   Bridging the Macro and the Micro by Considering the Meso: Reflections on the Fractal Nature of Resilience [J].
Bergstrom, Johan ;
Dekker, Sidney W. A. .
ECOLOGY AND SOCIETY, 2014, 19 (04)
[6]   Cyber Resilience - Fundamentals for a Definition [J].
Bjorck, Fredrik ;
Henkel, Martin ;
Stirna, Janis ;
Zdravkovic, Jelena .
NEW CONTRIBUTIONS IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 1, PT 1, 2015, 353 :311-316
[7]  
Blanchard K., 1983, The one minute manager
[8]   Organizational and institutional factors affecting high-speed rail safety in Japan [J].
Bugalia, Nikhil ;
Maemura, Yu ;
Ozawa, Kazumasa .
SAFETY SCIENCE, 2020, 128
[9]   Performance Error Estimation and Elastic Integral Event Triggering Mechanism Design for T-S Fuzzy Networked Control System Under DoS Attacks [J].
Cai, Xiao ;
Shi, Kaibo ;
She, Kun ;
Zhong, Shouming ;
Soh, Yeng Chai ;
Yu, Yue .
IEEE TRANSACTIONS ON FUZZY SYSTEMS, 2023, 31 (04) :1327-1339
[10]  
Cardenas A.A., 2011, P 6 ACM S INFORM COM, P355