Model-driven risk analysis of evolving critical infrastructures

نویسندگان

  • Bjørnar Solhaug
  • Fredrik Seehusen
چکیده

The protection and security of critical infrastructures are important parts of Homeland Defense. Adequate means for analyzing the security risks of such infrastructures is a prerequisite for properly understanding the security needs and for maintaining appropriate incident preparedness. Risk management is coordinated activities to direct and control an organization with regard to risk, and includes the identification, analysis and mitigation of unacceptable risks. For critical infrastructures consisting of interdependent systems, risk analysis and mitigation is challenging because the overall risk picture may be strongly affected by changes in only a few of the systems. In order to continuously manage risks and maintain an adequate level of protection, there is a need to continuously maintain the validity of risk models while systems change and evolve. This paper addresses these challenges by presenting an approach to model-driven security risk analysis of changing and evolving systems. The approach is a tool-supported method with techniques and modeling support for traceability of system changes to risk models, as well as the explicit modeling of the impact of changes on the current risk picture. The presented This work has been partially funded by the European Commission via the NESSoS (256980) network of excellence and the RASEN (316853) project. B. Solhaug SINTEF ICT, p.o. box 124, Blindern, 0314 Oslo, Norway Tel.: +47 22067547 Fax: +47 22067350 E-mail: [email protected] F. Seehusen SINTEF ICT, p.o. box 124, Blindern, 0314 Oslo, Norway Tel.: +47 22067949 Fax: +47 22067350 E-mail: [email protected] artifacts are exemplified and validated in the domain of air traffic management (ATM).

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Tool-Supported Risk Modeling and Analysis of Evolving Critical Infrastructures

Risk management is coordinated activities to direct and control an organization with regard to risk, and includes the identification, analysis and mitigation of unacceptable risks. For critical infrastructures consisting of interdependent systems, risk analysis and mitigation is challenging because the overall risk picture can be strongly affected by changes in only a few of the systems. In ord...

متن کامل

Towards Model-Driven Evolution of Performance Critical Business Information Systems to Cloud Computing Architectures

Migrating legacy applications to todays emerging cloud infrastructures is still challenging. In this paper, we sketch an approach, that combines reverse engineering and performance analyses for applications evolving to the cloud.

متن کامل

Scenario Based Approach for Risks Analysis in Critical Infrastructures

This paper proposes a Cross Impact Analysis for supporting critical infrastructures risk analysis. This methodology contributes to decision-makers and planners with analytical tools for modeling complex situations. These features are generally useful in emergency management and particularly within the critical infrastructures scope, where complex scenarios for risk analysis and emergency plans ...

متن کامل

Critical infrastructures and risk analysis of electricity supply

Failures in critical infrastructures can cause major damage to society, and thus there is a need for a common approach to cross-sector risk analyses. This paper presents such an approach, which includes an extended preliminary hazard analysis and detailed risk analysis of electricity supply, carried out in a case study. The risk analysis approach constitutes an important basis for analyzing int...

متن کامل

Cascading Effects of Common-Cause F on ailures Critical Infrastructures

One of the most challenging problems in Critical Infrastructure Protection is the assessment and mitigation of cascading failures across infrastructures. In previous research we have proposed a method for assessing the cumulative security risk of cascading threats due to multi-order dependencies between infrastructures. However, recent empirical studies indicate that common mode failures may re...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • J. Ambient Intelligence and Humanized Computing

دوره 5  شماره 

صفحات  -

تاریخ انتشار 2014