Parametric Analyses of Attack-fault Trees

被引:6
|
作者
Andre, Etienne [1 ]
Lime, Didier [2 ]
Ramparison, Mathias [3 ]
Stoelinga, Marielle [4 ]
机构
[1] Univ Lorraine, CNRS, INRIA, LORIA, F-54000 Nancy, France
[2] Ecole Cent Nantes, LS2N, CNRS, UMR 6004, Nantes, France
[3] Univ Sorbonne Paris Nord, LIPN, CNRS, F-93430 Villetaneuse, France
[4] Univ Twente, Formal Methods & Tools, Enschede, Netherlands
关键词
security; attack-fault trees; parametric timed automata; IMITATOR;
D O I
10.3233/FI-2021-2066
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Risk assessment of cyber-physical systems, such as power plants, connected devices and IT-infrastructures has always been challenging: safety (i. e., absence of unintentional failures) and security (i. e., no disruptions due to attackers) are conditions that must be guaranteed. One of the traditional tools used to consider these problems is attack trees, a tree-based formalism inspired by fault trees, a well-known formalism used in safety engineering. In this paper we define and implement the translation of attack-fault trees (AFTs) to a new extension of timed automata, called parametric weighted timed automata. This allows us to parameterize constants such as time and discrete costs in an AFT and then, using the model-checker IMITATOR, to compute the set of parameter values such that a successful attack is possible. Moreover, we add the possibility to define counter-measures. Using the different sets of parameter values computed, different attack and fault scenarios can be deduced depending on the budget, time or computation power of the attacker, providing helpful data to select the most efficient counter-measure.
引用
收藏
页码:69 / 94
页数:26
相关论文
共 50 条
  • [41] Generating Cyber-Physical System Risk Overlays for Attack and Fault Trees using Systems Theory
    Jablonski, Matthew
    Wijesekera, Duminda
    Singhal, Anoop
    SAT-CPS'22: PROCEEDINGS OF THE 2022 ACM WORKSHOP ON SECURE AND TRUSTWORTHY CYBER-PHYSICAL SYSTEMS, 2022, : 13 - 20
  • [42] From Attack Trees to Attack-Defense Trees with Generative AI & Natural Language Processing
    De Allende, Alan Birchler
    Sultan, Bastien
    Apvrille, Ludovic
    ACM/IEEE 27TH INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS: COMPANION PROCEEDINGS, MODELS 2024, 2024, : 561 - 569
  • [43] Temporal fault trees
    Palshikar, GK
    INFORMATION AND SOFTWARE TECHNOLOGY, 2002, 44 (03) : 137 - 150
  • [44] ANALYSIS OF FAULT TREES
    BENNETTS, RG
    IEEE TRANSACTIONS ON RELIABILITY, 1975, 24 (03) : 175 - 185
  • [45] Configurable Fault Trees
    Jakobs, Christine
    Troeger, Peter
    Werner, Matthias
    SOFTWARE ENGINEERING FOR RESILIENT SYSTEMS, (SERENE 2016), 2016, 9823 : 13 - 27
  • [46] Fault Trees.
    Barbet, J.F.
    Bulletin de la Direction des etudes et recherches. Serie A, Nucleaire, hydraulique, thermique, 1982, (02): : 31 - 48
  • [47] FAULT TREES REVISITED
    WOLFE, WA
    MICROELECTRONICS AND RELIABILITY, 1978, 17 (01): : 117 - 128
  • [48] Continuum fault trees
    Taylor, John Robert
    Kozine, Igor
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2023, 237 (06) : 1209 - 1222
  • [49] Fault Template Attack Based on Fault Probability
    Wu, Tong
    Zhou, Dawei
    Du, Lei
    Wang, Shiwei
    IEEE ACCESS, 2023, 11 : 71705 - 71713
  • [50] Parametric alignment of ordered trees
    Wang, LS
    Zhao, JY
    BIOINFORMATICS, 2003, 19 (17) : 2237 - 2245