Formal analysis of safety and security requirements of critical systems supported by an extended STPA methodology

被引:26
|
作者
Howard, Giles [1 ]
Butler, Michael [1 ]
Colley, John [1 ]
Sassone, Vladimiro [1 ]
机构
[1] Univ Southampton, Dept Elect & Comp Sci, Southampton, Hants, England
关键词
System analysis and design; systems modeling; cyber-physical systems; formal verification;
D O I
10.1109/EuroSPW.2017.68
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Cyber-physical systems represent an engineering challenge due to their safety and security concerns, particularly those systems involved in critical infrastructure which require some of the highest standards of safety, availability, integrity and security. The complexity of these systems makes the identification and analysis of safety and security requirements challenging. In this paper, we present a methodology for identifying and formally analysing safety and security requirements, based on the STPA methodology and combined with modelling, traceability and formal verification through use of the Event-B formal method. Our STPA approach is then leveraged to generate 'critical requirements' to mitigate against undesirable system states, which are subsequently translated into constraints on an Event-B representation of the system. The Rodin toolset allows us to demonstrate that these critical requirements fully mitigate against the undesirable system states and therefore provide automated verification of the critical requirements.
引用
收藏
页码:174 / 180
页数:7
相关论文
共 50 条
  • [21] Limitation and Improvement of STPA-Sec for Safety and Security Co-analysis
    Schmittner, Christoph
    Ma, Zhendong
    Puschner, Peter
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2016, 2016, 9923 : 195 - 209
  • [22] A subjective methodology for safety analysis of safety requirements specifications
    Wang, J
    IEEE TRANSACTIONS ON FUZZY SYSTEMS, 1997, 5 (03) : 418 - 430
  • [23] FORMAL METHODS FOR SAFETY-CRITICAL SYSTEMS
    MCARTHUR, N
    CONTROL AND INSTRUMENTATION, 1994, 26 (05): : 59 - 60
  • [24] A State-based Extension to STPA for Safety-Critical System-of-Systems
    Baumgart, Stephan
    Froberg, Joakim
    Punnekkat, Sasikumar
    2019 4TH INTERNATIONAL CONFERENCE ON SYSTEM RELIABILITY AND SAFETY (ICSRS 2019), 2019, : 246 - 254
  • [25] Identification of Security Requirements in Systems of Systems by Functional Security Analysis
    Fuchs, Andreas
    Rieke, Roland
    ARCHITECTING DEPENDABLE SYSTEMS VII, 2010, 6420 : 74 - 96
  • [26] Applying System-Theoretic Process Analysis (STPA)-based methodology supported by Systems Engineering models to a UK rail project
    Oginni, Dapo
    Camelia, Fanny
    Chatzimichailidou, Mikela
    Ferris, Timothy L. J.
    SAFETY SCIENCE, 2023, 167
  • [27] Formal Requirements Specification in Safety-critical Railway Signaling System
    Jo, Hyun-Jeong
    Hwang, Jong-Gyu
    Yoon, Yong-Ki
    T& D ASIA: 2009 TRANSMISSION & DISTRIBUTION CONFERENCE & EXPOSITION: ASIA AND PACIFIC, 2009, : 731 - 734
  • [28] Formal Support for Quantitative Analysis of Residual Risks in Safety-Critical Systems
    Elmqvist, Jonas
    Nadim-Tehrani, Simin
    11TH IEEE HIGH ASSURANCE SYSTEMS ENGINEERING SYMPOSIUM, PROCEEDINGS, 2008, : 154 - 164
  • [29] Critical water requirements for food, methodology and policy consequences for food security
    Gerbens-Leenes, PW
    Nonhebel, S
    FOOD POLICY, 2004, 29 (05) : 547 - 564
  • [30] Security requirements specification by formal methods: a research metadata analysis
    Aditya Dev Mishra
    Khurram Mustafa
    Multimedia Tools and Applications, 2024, 83 : 41847 - 41866