Towards Model Co-evolution Across Self-Adaptation Steps for Combined Safety and Security Analysis

Thomas E. F. Witte, Raffaela Groner, Alexander Raschke, Matthias Tichy, Irdin Pekaric, M. Felderer
{"title":"Towards Model Co-evolution Across Self-Adaptation Steps for Combined Safety and Security Analysis","authors":"Thomas E. F. Witte, Raffaela Groner, Alexander Raschke, Matthias Tichy, Irdin Pekaric, M. Felderer","doi":"10.1145/3524844.3528062","DOIUrl":null,"url":null,"abstract":"Self-adaptive systems offer several attack surfaces due to the communication via different channels and the different sensors required to observe the environment. Often, attacks cause safety to be compromised as well, making it necessary to consider these two aspects together. Furthermore, the approaches currently used for safety and security analysis do not sufficient take into account the intermediate steps of an adaptation. Current work in this area ignores the fact that a self-adaptive system also reveals possible vulnerabilities (even if only temporarily) during the adaptation. To address this issue, we propose a modeling approach that takes into account the different relevant aspects of a system, its adaptation process, as well as safety hazards and security attacks. We present several models that describe different aspects of a self-adaptive system and we outline our idea of how these models can then be combined into an Attack-Fault Tree. This allows modeling aspects of the system on different levels of abstraction and co-evolve the models using transformations according to the adaptation of the system. Finally, analyses can then be performed as usual on the resulting Attack-Fault Tree.CCS CONCEPTS• Software and its engineering → System description languages; Fault tree analysis; • Computer systems organization → Embedded and cyber-physical systems; Dependable and fault-tolerant systems and networks.","PeriodicalId":227173,"journal":{"name":"2022 International Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3524844.3528062","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

Self-adaptive systems offer several attack surfaces due to the communication via different channels and the different sensors required to observe the environment. Often, attacks cause safety to be compromised as well, making it necessary to consider these two aspects together. Furthermore, the approaches currently used for safety and security analysis do not sufficient take into account the intermediate steps of an adaptation. Current work in this area ignores the fact that a self-adaptive system also reveals possible vulnerabilities (even if only temporarily) during the adaptation. To address this issue, we propose a modeling approach that takes into account the different relevant aspects of a system, its adaptation process, as well as safety hazards and security attacks. We present several models that describe different aspects of a self-adaptive system and we outline our idea of how these models can then be combined into an Attack-Fault Tree. This allows modeling aspects of the system on different levels of abstraction and co-evolve the models using transformations according to the adaptation of the system. Finally, analyses can then be performed as usual on the resulting Attack-Fault Tree.CCS CONCEPTS• Software and its engineering → System description languages; Fault tree analysis; • Computer systems organization → Embedded and cyber-physical systems; Dependable and fault-tolerant systems and networks.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于自适应步骤的组合安全分析模型协同进化研究
由于通过不同的通信通道和观察环境所需的不同传感器,自适应系统提供了多个攻击面。通常,攻击还会损害安全性,因此有必要同时考虑这两个方面。此外,目前用于安全和保障分析的方法没有充分考虑到适应的中间步骤。目前在这一领域的工作忽略了一个事实,即自适应系统在适应过程中也会暴露出可能的脆弱性(即使只是暂时的)。为了解决这个问题,我们提出了一种建模方法,该方法考虑了系统的不同相关方面、其适应过程以及安全隐患和安全攻击。我们提出了几个描述自适应系统不同方面的模型,并概述了如何将这些模型组合成攻击-故障树的想法。这允许在不同的抽象层次上对系统的各个方面进行建模,并根据系统的适应性使用转换来共同发展模型。最后,可以像往常一样对生成的攻击-故障树执行分析。•软件及其工程→系统描述语言;故障树分析;•计算机系统组织→嵌入式和网络物理系统;可靠和容错的系统和网络。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Towards Self-Adaptive Peer-to-Peer Monitoring for Fog Environments Self-adaptive Testing in the Field: Are We There Yet? From Systems to Ecosystems: Rethinking Adaptive Safety Taming Model Uncertainty in Self-adaptive Systems Using Bayesian Model Averaging Emergent Web Server: An Exemplar to Explore Online Learning in Compositional Self-Adaptive Systems
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1