Modeling, analyzing and predicting security cascading attacks in smart buildings systems-of-systems

被引:17
|
作者
EL Hachem, Jamal [1 ]
Chiprianov, Vanea [1 ]
Babar, Muhammad Ali [2 ]
AL Khalil, Tarek [3 ]
Aniorte, Philippe [1 ]
机构
[1] Univ Pau & Pays, ADOUR, E2S UPPA, LIUPPA, F-40000 Mont De Marsan, France
[2] Univ Adelaide, Sch Comp Sci, Software Engn, Adelaide, SA, Australia
[3] Antonine Univ, Baabda, Lebanon
关键词
Systems-of-systems; Security modeling and analysis; Model driven engineering; Software architecture; Multi-agent systems simulation; Smart buildings;
D O I
10.1016/j.jss.2019.110484
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Software systems intelligence and complexity have been continuously increasing to deliver more and more features to support business critical and mission critical processes in numerous domains such as defense, health-care, and smart cities. Contemporary software-based solutions are composed of several software systems, that form System-of-Systems (SoS). SoS differentiating characteristics, such as emergent behavior, introduce specific issues that render their security modeling, simulation and analysis a critical challenge. The aim of this work is to investigate how Software Engineering (SE) approaches can be leveraged to model and analyze secure SoS solutions for predicting high impact (cascading) attacks at the architecture stage. In order to achieve this objective, we propose a Model Driven Engineering method, Systems-of-Systems Security (SoSSec), that comprises: (1) a modeling language (SoSSecML) for secure SoS modeling and (2) Multi-Agent Systems (MAS) for security analysis of SoS architectures. To illustrate our proposed approach in terms of modeling, simulating, and discovering attacks, we have conducted a case study on a real-life smart building SoS, the Adelaide University Health and Medical School (AHMS). The results from this case study demonstrate that our proposed method discovers cascading attacks comprising of a number of individual attacks, such as a Denial of Service, that arise from a succession of exploited vulnerabilities through interactions among the constituent systems of SoS. In future work, we intend to extend SoSSec to address diverse unknown emergent behaviors and non-functional properties such as safety and trust. (C) 2019 Elsevier Inc. All rights reserved.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] A Security Framework for Systems-of-Systems
    Abou-Tair, Dhiah el Diehn I.
    Alouneh, Sahel
    Khalifeh, Ala
    Obermaisser, Roman
    [J]. ADVANCES IN COMPUTER SCIENCE AND UBIQUITOUS COMPUTING, 2018, 474 : 427 - 432
  • [2] Modeling and Analyzing Systems-of-Systems in the Multi-Attribute Prediction Language (MAPL)
    Johnson, Pontus
    Lagerstrom, Robert
    Ekstedt, Mathias
    Franke, Ulrik
    [J]. 2016 IEEE/ACM 4TH INTERNATIONAL WORKSHOP ON SOFTWARE ENGINEERING FOR SYSTEMS-OF-SYSTEMS (SESOS), 2016, : 1 - 7
  • [3] Communications, information, and cyber security in Systems-of-Systems: Assessing the impact of attacks through interdependency analysis
    Guariniello, Cesare
    DeLaurentis, Daniel
    [J]. 2014 CONFERENCE ON SYSTEMS ENGINEERING RESEARCH, 2014, 28 : 720 - 727
  • [4] Testing Challenges of Maritime Safety and Security Systems-of-Systems
    Gonzalez, Alberto
    Piel, Eric
    Gross, Hans-Gerhard
    Glandrup, Maurice
    [J]. TACI PART 2008:TESTING: ACADEMIC AND INDUSTRIAL CONFERENCE PRACTICE AND RESEARCH TECHNIQUES, PROCEEDINGS, 2008, : 35 - +
  • [5] Modeling Security Policies for Mitigating The Risk Of Load Altering Attacks On Smart Grid Systems
    Ryutov, Tatyana
    AlMajali, Anas
    Neuman, Clifford
    [J]. 2015 WORKSHOP ON MODELING AND SIMULATION OF CYBER-PHYSICAL ENERGY SYSTEMS (MSCPES), 2015,
  • [6] Formal Modeling Systems-of-Systems Missions with mKAOS
    Silva, Eduardo
    Batista, Thais
    [J]. 33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1674 - 1679
  • [7] Model Driven Software Security Architecture of Systems-of-Systems
    El Hachem, Jamal
    Pang, Zi Yang
    Chiprianov, Vanea
    Babar, Ali
    Aniorte, Philippe
    [J]. 2016 23RD ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2016), 2016, : 89 - 96
  • [8] Analyzing Cyber-Physical Attacks on Smart Grid Systems
    Wadhawan, Yatin
    Neuman, Clifford
    AlMajali, Anas
    [J]. 2017 WORKSHOP ON MODELING AND SIMULATION OF CYBER-PHYSICAL ENERGY SYSTEMS (MSCPES), 2017,
  • [9] Imperceptible Attacks on Fault Detection and Diagnosis Systems in Smart Buildings
    Alkhouri, Ismail R.
    Awad, Akram S.
    Sun, Qun Z.
    Atia, George K.
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (02) : 2167 - 2176
  • [10] Measuring, analyzing and predicting security vulnerabilities in software systems
    Alhazmi, O. H.
    Malaiya, Y. K.
    Ray, I.
    [J]. COMPUTERS & SECURITY, 2007, 26 (03) : 219 - 228