Threat Analysis in Systems-of-Systems: An Emergence-Oriented Approach

被引:9
|
作者
Ceccarelli, Andrea [1 ]
Zoppi, Tommaso [1 ]
vasenev, Alexandr [2 ]
Mori, Marco [1 ]
Ionita, Dan [2 ]
Montoya, Lorena [2 ]
Bondavalli, Andrea [1 ]
机构
[1] Univ Florence, Viale Morgagni 65, Florence, Italy
[2] Univ Twente, Drienerlolaan 5, NL-7522 NB Enschede, Netherlands
基金
欧盟第七框架计划;
关键词
Emergent properties; systems-of-systems; cyber-physical systems; threat analysis; security; evolution; user assessment; DESIGN;
D O I
10.1145/3234513
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cyber-physical Systems of Systems (SoSs) are large-scale systems made of independent and autonomous cyber-physical Constituent Systems (CSs) which may interoperate to achieve high-level goals also with the intervention of humans. Providing security in such SoSs means, among other features, forecasting and anticipating evolving SoS functionalities, ultimately identifying possible detrimental phenomena that may result from the interactions of CSs and humans. Such phenomena, usually called emergent phenomena, are often complex and difficult to capture: the first appearance of an emergent phenomenon in a cyber-physical SoS is often a surprise to the observers. Adequate support to understand emergent phenomena will assist in reducing both the likelihood of design or operational flaws, and the time needed to analyze the relations amongst the CSs, which always has a key economic significance. This article presents a threat analysis methodology and a supporting tool aimed at (i) identifying (emerging) threats in evolving SoSs, (ii) reducing the cognitive load required to understand an SoS and the relations among CSs, and (iii) facilitating SoS risk management by proposing mitigation strategies for SoS administrators. The proposed methodology, as well as the tool, is empirically validated on Smart Grid case studies by submitting questionnaires to a user base composed of 3 stakeholders and 18 BSc and MSc students.
引用
收藏
页数:24
相关论文
共 50 条
  • [21] Using Bayesian Networks for a Cyberattacks Propagation Analysis in Systems-of-Systems
    El Hachem, Jamal
    Sedaghatbaf, Ali
    Lisova, Elena
    Causevic, Aida
    2019 26TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC), 2019, : 363 - 370
  • [22] Dynamic-SoS: An Approach for the Simulation of Systems-of-Systems Dynamic Architectures
    Manzano, Wallace
    Graciano Neto, Valdemar Vicente
    Nakagawa, Elisa Yumi
    COMPUTER JOURNAL, 2020, 63 (05): : 709 - 731
  • [23] Systems-of-Systems Enterprise Architecture CONOPS Assessment Approach and Preliminary Results
    Nguyen, Tien M.
    Lee, Charles
    Freeze, Tom
    Guillen, Andy T.
    SENSORS AND SYSTEMS FOR SPACE APPLICATIONS XIII, 2020, 11422
  • [24] Enabling Systems and the Adaptability of Complex Systems-of-Systems
    Adler, Charles O.
    Dagli, Cihan H.
    COMPLEX ADAPTIVE SYSTEMS 2012, 2012, 12 : 31 - 36
  • [25] Promoting Trust in Interoperability of Systems-of-Systems
    Allian, Ana Paula
    13TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE (ECSA 2019), VOL 2, 2019, : 67 - 70
  • [26] The Dependable Systems-of-Systems Design Challenge
    Haverkort, Boudewijn R.
    IEEE SECURITY & PRIVACY, 2013, 11 (05) : 62 - 65
  • [27] Systems-of-systems engineering and the pragmatics of demand
    Boxer, Philip
    Morris, Edwin
    Anderson, William
    Cohen, Bernard
    2008 2ND ANNUAL IEEE SYSTEMS CONFERENCE, 2008, : 482 - 488
  • [28] Software-intensive Systems-of-Systems
    Drira, Khalil
    Cuesta, Carlos E.
    SCIENCE OF COMPUTER PROGRAMMING, 2021, 212 (212)
  • [29] A framework for equipment systems-of-systems effectiveness evaluation using parallel experiments approach
    Zilong Cheng
    Li Fan
    Yulin Zhang
    Journal of Systems Engineering and Electronics, 2015, 26 (02) : 292 - 300
  • [30] BIM cube and systems-of-systems framework
    Cerovsek, T.
    EWORK AND EBUSINESS IN ARCHITECTURE, ENGINEERING AND CONSTRUCTION, 2012, : 421 - 428