Model-driven risk analysis of evolving critical infrastructures
نویسندگان
چکیده
The protection and security of critical infrastructures are important parts of Homeland Defense. Adequate means for analyzing the security risks of such infrastructures is a prerequisite for properly understanding the security needs and for maintaining appropriate incident preparedness. Risk management is coordinated activities to direct and control an organization with regard to risk, and includes the identification, analysis and mitigation of unacceptable risks. For critical infrastructures consisting of interdependent systems, risk analysis and mitigation is challenging because the overall risk picture may be strongly affected by changes in only a few of the systems. In order to continuously manage risks and maintain an adequate level of protection, there is a need to continuously maintain the validity of risk models while systems change and evolve. This paper addresses these challenges by presenting an approach to model-driven security risk analysis of changing and evolving systems. The approach is a tool-supported method with techniques and modeling support for traceability of system changes to risk models, as well as the explicit modeling of the impact of changes on the current risk picture. The presented This work has been partially funded by the European Commission via the NESSoS (256980) network of excellence and the RASEN (316853) project. B. Solhaug SINTEF ICT, p.o. box 124, Blindern, 0314 Oslo, Norway Tel.: +47 22067547 Fax: +47 22067350 E-mail: [email protected] F. Seehusen SINTEF ICT, p.o. box 124, Blindern, 0314 Oslo, Norway Tel.: +47 22067949 Fax: +47 22067350 E-mail: [email protected] artifacts are exemplified and validated in the domain of air traffic management (ATM).
منابع مشابه
Tool-Supported Risk Modeling and Analysis of Evolving Critical Infrastructures
Risk management is coordinated activities to direct and control an organization with regard to risk, and includes the identification, analysis and mitigation of unacceptable risks. For critical infrastructures consisting of interdependent systems, risk analysis and mitigation is challenging because the overall risk picture can be strongly affected by changes in only a few of the systems. In ord...
متن کاملTowards Model-Driven Evolution of Performance Critical Business Information Systems to Cloud Computing Architectures
Migrating legacy applications to todays emerging cloud infrastructures is still challenging. In this paper, we sketch an approach, that combines reverse engineering and performance analyses for applications evolving to the cloud.
متن کاملScenario Based Approach for Risks Analysis in Critical Infrastructures
This paper proposes a Cross Impact Analysis for supporting critical infrastructures risk analysis. This methodology contributes to decision-makers and planners with analytical tools for modeling complex situations. These features are generally useful in emergency management and particularly within the critical infrastructures scope, where complex scenarios for risk analysis and emergency plans ...
متن کاملCritical infrastructures and risk analysis of electricity supply
Failures in critical infrastructures can cause major damage to society, and thus there is a need for a common approach to cross-sector risk analyses. This paper presents such an approach, which includes an extended preliminary hazard analysis and detailed risk analysis of electricity supply, carried out in a case study. The risk analysis approach constitutes an important basis for analyzing int...
متن کاملCascading Effects of Common-Cause F on ailures Critical Infrastructures
One of the most challenging problems in Critical Infrastructure Protection is the assessment and mitigation of cascading failures across infrastructures. In previous research we have proposed a method for assessing the cumulative security risk of cascading threats due to multi-order dependencies between infrastructures. However, recent empirical studies indicate that common mode failures may re...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- J. Ambient Intelligence and Humanized Computing
دوره 5 شماره
صفحات -
تاریخ انتشار 2014