Model-Based Cyber Security at the Enterprise and Systems Level

被引:1
|
作者
Brooks, Mitchell [1 ]
Hause, Matthew [2 ]
机构
[1] SSI, 229 Manzanita Dr, Orinda,CA, United States
[2] Principal, SSI, 3208 Misty Oaks Way, Round Rock,TX, United States
关键词
Modeling languages;
D O I
10.1002/iis2.13044
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Model-Based Engineering (MBE) has transformed the worlds of mechanical, electrical, chemical, software, systems engineering, and now cybersecurity. Model based cybersecurity allows this concern to be addressed as an integrated part of the solution as opposed to being a separate solution. To best take advantage of this, we must examine which modeling practices, languages, and standards are best suited to handle cybersecurity. Currently, UAF is the most effective tool being used to provide Model-Based Cyber Security at the Enterprise and Systems Level. It achieves this largely through its integrated security viewpoint as well as by facilitating capability-based engineering. Furthermore, it allows modelers to integrate with other cybersecurity-focused modeling tools to include cybersecurity in the digital thread. The INCOSE Future of Systems Engineering (FuSE) Initiative defined 12 key concepts including Capability-Based Security Engineering and Security as a Functional Requirement. This paper discusses these FuSE concepts and demonstrates how they can be effectively realized via the use of UAF and shows how UAF coupled with complementary tools and standards provides powerful verification and validation capabilities. Note that this paper is derived from INCOSE Insight articles Brooks, Hause (2022) and Hause, Brooks (2022) published in a special issue on FuSE Security. References are included below. Copyright © 2023 by M Brooks, M Hause. Permission granted to INCOSE to publish and use.
引用
收藏
页码:649 / 665
相关论文
共 50 条
  • [1] Model-based cyber security
    Rasche, Galen
    Allwein, Erin
    Moore, Michael
    Abbott, Ben
    ECBS 2007: 14TH ANNUAL IEEE INTERNATIONAL CONFERENCE AND WORKSHOPS ON THE ENGINEERING OF COMPUTER-BASED SYSTEMS, PROCEEDINGS: RAISING EXPECTATIONS OF COMPUTER-BASES SYSTEMS, 2007, : 405 - 412
  • [2] Model-based risk assessment for cyber physical systems security
    Tantawy, Ashraf
    Abdelwahed, Sherif
    Erradi, Abdelkarim
    Shaban, Khaled
    COMPUTERS & SECURITY, 2020, 96
  • [3] A Model-based Approach for Assessing the Security of Cyber-Physical Systems
    Teixeira De Castro, Hugo
    Hussain, Ahmed
    El Hachem, Jamal
    Blanc, Gregory
    Blouin, Dominique
    Leneutre, Jean
    Papadimitratos, Panos
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [4] A Model-Based Approach to Security Analysis for Cyber-Physical Systems
    Bakirtzis, Georgios
    Carter, Bryan T.
    Elks, Carl R.
    Fleming, Cody H.
    12TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON2018), 2018, : 496 - 503
  • [5] A Semantic Model-based Security Engineering Framework for Cyber-Physical Systems
    Aigner, Andreas
    Khelil, Abdelmajid
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1826 - 1833
  • [6] Model-based risk assessment to improve enterprise security
    Aagedal, JO
    den Braber, F
    Dimitrakos, T
    Gran, BA
    Raptis, D
    Stolen, K
    SIXTH INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2002, : 51 - 62
  • [7] Model-based security engineering for cyber-physical systems: A systematic mapping study
    Nguyen, Phu H.
    Ali, Shaukat
    Yue, Tao
    INFORMATION AND SOFTWARE TECHNOLOGY, 2017, 83 : 116 - 135
  • [8] Model-Based Systems Security Quantification
    Ouchani, Samir
    Jarraya, Yosr
    Mohamed, Otmane Ait
    2011 NINTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2011, : 142 - 149
  • [9] A Model-Based Approach for Aviation Cyber Security Risk Assessment
    Kiesling, Tobias
    Niederl, Josef
    Ziegler, Juergen
    Krempel, Matias
    PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 517 - 525
  • [10] Model-based autonomic security management for cyber-physical infrastructures
    Chen, Qian
    Trivedi, Madhulika
    Abdelwahed, Sherif
    Morris, Thomas
    Sheldon, Frederick
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2016, 12 (04) : 273 - 294