Threat Analysis in Systems-of-Systems: An Emergence-Oriented Approach

被引:9
|
作者
Ceccarelli, Andrea [1 ]
Zoppi, Tommaso [1 ]
vasenev, Alexandr [2 ]
Mori, Marco [1 ]
Ionita, Dan [2 ]
Montoya, Lorena [2 ]
Bondavalli, Andrea [1 ]
机构
[1] Univ Florence, Viale Morgagni 65, Florence, Italy
[2] Univ Twente, Drienerlolaan 5, NL-7522 NB Enschede, Netherlands
基金
欧盟第七框架计划;
关键词
Emergent properties; systems-of-systems; cyber-physical systems; threat analysis; security; evolution; user assessment; DESIGN;
D O I
10.1145/3234513
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cyber-physical Systems of Systems (SoSs) are large-scale systems made of independent and autonomous cyber-physical Constituent Systems (CSs) which may interoperate to achieve high-level goals also with the intervention of humans. Providing security in such SoSs means, among other features, forecasting and anticipating evolving SoS functionalities, ultimately identifying possible detrimental phenomena that may result from the interactions of CSs and humans. Such phenomena, usually called emergent phenomena, are often complex and difficult to capture: the first appearance of an emergent phenomenon in a cyber-physical SoS is often a surprise to the observers. Adequate support to understand emergent phenomena will assist in reducing both the likelihood of design or operational flaws, and the time needed to analyze the relations amongst the CSs, which always has a key economic significance. This article presents a threat analysis methodology and a supporting tool aimed at (i) identifying (emerging) threats in evolving SoSs, (ii) reducing the cognitive load required to understand an SoS and the relations among CSs, and (iii) facilitating SoS risk management by proposing mitigation strategies for SoS administrators. The proposed methodology, as well as the tool, is empirically validated on Smart Grid case studies by submitting questionnaires to a user base composed of 3 stakeholders and 18 BSc and MSc students.
引用
收藏
页数:24
相关论文
共 50 条
  • [21] A modeling framework for the resilience analysis of networked systems-of-systems based on functional dependencies
    Filippini, Roberto
    Silva, Andres
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2014, 125 : 82 - 91
  • [22] STRIPED: A Threat Analysis Method for IoT Systems
    Srikumar, Kamakshi
    Kashish, Komal
    Eggers, Kolja
    Ferreyra, Nicolas E. Diaz
    Koch, Julian
    Schueppstuhl, Thorsten
    Scandariato, Riccardo
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [23] Modelling Resilient Systems-of-Systems in Event-B
    Laibinis, Linas
    Pereverzeva, Inna
    Troubitsyna, Elena
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, 2014, 8696 : 157 - 166
  • [24] Towards a Modelling and Design Framework for Mixed-Criticality SoCs and Systems-of-Systems
    Herrera, Fernando
    Attarzadeh-Niaki, Seyed-Hosein
    Sander, Ingo
    16TH EUROMICRO CONFERENCE ON DIGITAL SYSTEM DESIGN (DSD 2013), 2013, : 989 - 996
  • [25] A Systematic Mapping on Discovery and Composition Mechanisms for Systems-of-Systems
    Gomes, Porfirio
    Cavalcante, Everton
    Maia, Pedro
    Batista, Thais
    Oliveira, Kamilla
    PROCEEDINGS 41ST EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS SEAA 2015, 2015, : 191 - 198
  • [26] Taming Missions and Architecture in Software Intensive Systems-of-Systems
    Silva, Eduardo
    11TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE (ECSA 2017) - COMPANION VOLUME, 2017, : 46 - 50
  • [27] Systems Assurance, Complexity and Emergence: The Need for a Systems Based Approach
    Hessami, Ali
    Karcanias, Nicos
    GLOBAL SECURITY, SAFETY, AND SUSTAINABILITY, 2010, 92 : 202 - 215
  • [28] Emergence as Innovation in Systems of Systems - a Three Systems Model
    McDermott, Tom
    Nadolski, Molly
    2017 12TH SYSTEM OF SYSTEMS ENGINEERING CONFERENCE (SOSE), 2017,
  • [29] Evolving robust networks for systems-of-systems: is it viable for large networks?
    Jonathan M. Aitken
    Rob Alexander
    Tim Kelly
    Simon Poulding
    Empirical Software Engineering, 2014, 19 : 1502 - 1530
  • [30] A Systems-of-Systems Security Framework for Requirements Definition in Cloud Environment
    Gennari Carturan, Sara B. O.
    Goya, Denise Hideko
    13TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE (ECSA 2019), VOL 2, 2019, : 235 - 240