Parametric analyses of attack-fault trees

02/12/2019
by   Étienne André, et al.
0

Risk assessment of cyber-physical systems, such as power plants, connected devices and IT-infrastructures has always been challenging: safety (i.e. absence of unintentional failures) and security (i.e. no disruptions due to attackers) are conditions that must be guaranteed. One of the traditional tools used to help considering these problems is attack trees, a tree-based formalism inspired by fault trees, a well-known formalism used in safety engineering. In this paper we define and implement the translation of attack-fault trees (AFTs) to a new extension of timed automata, called parametric weighted timed automata. This allows us to parametrize constants such as time and discrete costs in an AFT and then, using the model-checker IMITATOR, to compute the set of parameter values such that a successful attack is possible. Using the different sets of parameter values computed, different attack and fault scenarios can be deduced depending on the budget, time or computation power of the attacker, providing helpful data to select the most efficient counter-measure.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/18/2023

Model-Based Generation of Attack-Fault Trees

Joint safety and security analysis of cyber-physical systems is a necess...
research
09/28/2022

Extending Attack-Fault Trees with Runtime Verification

Autonomous systems are often complex and prone to software failures and ...
research
06/12/2019

Hackers vs. Security: Attack-Defence Trees as Asynchronous Multi-Agent Systems

Attack-Defence Trees (ADTs) are well-suited to assess possible attacks t...
research
06/07/2021

Verification of Component Fault Trees Using Error Effect Simulations

The growing complexity of safety-relevant systems causes an increasing e...
research
05/30/2020

Cyber LOPA: A New Approach for CPS Safety Design in the Presence of Cyber Attacks

Safety risk assessment is an essential process to ensure a dependable Cy...
research
07/16/2020

MaxSAT Evaluation 2020 – Benchmark: Identifying Maximum Probability Minimal Cut Sets in Fault Trees

This paper presents a MaxSAT benchmark focused on the identification of ...
research
02/26/2021

Yoneda Hacking: The Algebra of Attacker Actions

Our work focuses on modeling security of systems from their component-le...

Please sign up or login with your details

Forgot password? Click here to reset