Quantitative security and safety analysis with attack-fault trees

被引:78
作者
Kumar, Rajesh [1 ]
Stoelinga, Marielle [1 ]
机构
[1] Univ Twente, Enschede, Netherlands
来源
2017 IEEE 18TH INTERNATIONAL SYMPOSIUM ON HIGH ASSURANCE SYSTEMS ENGINEERING (HASE 2017) | 2017年
关键词
D O I
10.1109/HASE.2017.12
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber physical systems, like power plants, medical devices and data centers have to meet high standards, both in terms of safety (i. e. absence of unintentional failures) and security (i. e. no disruptions due to malicious attacks). This paper presents attack fault trees (AFTs), a formalism that marries fault trees (safety) and attack trees (security). We equip AFTs with stochastic model checking techniques, enabling a rich plethora of qualitative and quantitative analyses. Qualitative metrics pinpoint to root causes of the system failure, while quantitative metrics concern the likelihood, cost, and impact of a disruption. Examples are: (1) the most likely attack path; (2) the most costly system failure; (3) the expected impact of an attack. Each of these metrics can be constrained, i. e., we can provide the most likely disruption within time t and/or budget B. Finally, we can use sensitivity analysis to find the attack step that has the most influence on a given metric. We demonstrate our approach through three realistic cases studies.
引用
收藏
页码:25 / 32
页数:8
相关论文
共 44 条
[1]  
[Anonymous], 2014, LNCS, DOI DOI 10.1007/978-3-642-54792-816
[2]  
[Anonymous], 2015, DET INV SPEC TEST PR
[3]  
[Anonymous], 2021, EFFECTIVE FMEAS ACHI
[4]  
[Anonymous], 2015, Complex Systems Design and Management Asia
[5]  
[Anonymous], DOBBS J
[6]  
[Anonymous], COMPUTER SCI REV
[7]  
[Anonymous], 2016, Tech. rep.
[8]  
Arnold Florian, 2015, Computer Safety, Reliability and Security. SAFECOMP 2015 Workshops, ASSURE, DECSoS, ISSE, ReSA4CI and SASSUR. Proceedings: LNCS 9338, P291, DOI 10.1007/978-3-319-24249-1_25
[9]  
Arnold Florian, 2013, Computer Safety, Reliability and Security. 32nd International Conference, SAFECOMP 2013. Proceedings: LNCS 8153, P293, DOI 10.1007/978-3-642-40793-2_27
[10]  
Baier C, 2008, PRINCIPLES OF MODEL CHECKING, P1