Model-Based Generation of Attack-Fault Trees


연구 분야: Verification



학회: International Conference on Computer Safety, Reliability, and Security


초록

Joint safety and security analysis of cyber-physical systems is a necessary step to correctly capture inter-dependencies between these properties. Attack-Fault Trees represent a combination of dynamic Fault Trees and Attack Trees and can be used to model and model-check a holistic view on both safety and security. Manually creating a complete AFT for the whole system is, however, a daunting task. It needs to span multiple abstraction layers, e.g., abstract application architecture and data flow as well as system and library dependencies that are affected by various vulnerabilities. We present an AFT generation tool-chain that facilitates this task using partial Fault and Attack Trees that are either manually created or mined from vulnerability databases. We semi-automatically create two system models that provide the necessary information to automatically combine these partial Fault and Attack Trees into complete AFTs using graph transformation rules.


Author Profile
Raffaela Groner

Institute of Software Engineering and Programming Languages Ulm University Ulm Germany

Andorra
Author Profile
Thomas Witte

Institute of Software Engineering and Programming Languages Ulm University Ulm Germany

Andorra
Author Profile
Alexander Raschke

Institute of Software Engineering and Programming Languages Ulm University Ulm Germany

Andorra

📄 논문 정보

발행 연도 2023년
인용수 0
출판 국가 Andorra, Austria
사이트 Springer
좋아요 수 0

연관 논문 목록 (221건)