Security Property Modeling

被引:1
|
作者
Hnaini, Hiba [1 ]
Le Roux, Luka [1 ]
Champeau, Joel [1 ]
Teodorov, Ciprian [1 ]
机构
[1] ENSTA Bretagne, Lab STICC, SL Dept, Brest, France
关键词
Cyber-security; Modeling; Attacker; Methodology; Formal Methods; Model-checking; Property Specification; Case Study; SYSTEMS;
D O I
10.5220/0010388206940701
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the increasing number of cyber-attacks on cyber-physical systems, many security precautions and solutions have been suggested. However, most of these solutions aim to prevent the access of an adversary to the system. Though, with the increasing number of elements used in a system, and thus vulnerabilities, it is essential to study the risks introduced to the system to make the system itself efficient enough to react to the attacks once an attacker has obtained access. Analyzing and discovering the risks is the first step to making the system more resilient. This paper proposes a methodology that combines the qualitative risk analysis with formal methods (model checking) to identify the risks that were not recognized during testing or functional modeling phases. To examine this methodology, a car reservation system is modeled with an attacker, and then its security properties are verified using UPPAAL model checking tool. As a result, some risks were identified and tested for the possibility of them occurring and their effects on the system.
引用
收藏
页码:694 / 701
页数:8
相关论文
共 50 条