[论文解读] Model-Based Safety and Security Engineering
本白皮书提出了一种基于模型的集成方法,通过将安全模型(GSN)转换为安全模型(ADT),实现使用答案集编程(Answer-Set Programming)自动检测安全与安全需求之间的矛盾。其主要贡献是一个支持自动化冲突检测与解决的协作式、基于模型的安全与安全分析框架,从而提升互联系统的系统保障能力。
By exploiting the increasing surface attack of systems, cyber-attacks can cause catastrophic events, such as, remotely disable safety mechanisms. This means that in order to avoid hazards, safety and security need to be integrated, exchanging information, such as, key hazards/threats, risk evaluations, mechanisms used. This white paper describes some steps towards this integration by using models. We start by identifying some key technical challenges. Then we demonstrate how models, such as Goal Structured Notation (GSN) for safety and Attack Defense Trees (ADT) for security, can address these challenges. In particular, (1) we demonstrate how to extract in an automated fashion security relevant information from safety assessments by translating GSN-Models into ADTs; (2) We show how security results can impact the confidence of safety assessments; (3) We propose a collaborative development process where safety and security assessments are built by incrementally taking into account safety and security analysis; (4) We describe how to carry out trade-off analysis in an automated fashion, such as identifying when safety and security arguments contradict each other and how to solve such contradictions. We conclude pointing out that these are the first steps towards a wide range of techniques to support Safety and Security Engineering. As a white paper, we avoid being too technical, preferring to illustrate features by using examples and thus being more accessible.
研究动机与目标
- 应对互联系统中安全与安全日益增长的集成挑战,尤其是攻击面扩大的问题。
- 通过促进安全与安全评估之间的信息互换,弥合安全与安全工程之间的鸿沟。
- 开发一种协作式、增量式开发流程,支持联合的安全与安全论证。
- 实现对安全与安全需求之间逻辑与行为矛盾的自动化检测。
- 通过提供可追溯的、基于模型的安全与安全论证,支持认证流程。
提出的方法
- 将目标结构符号(GSN)模型转换为攻击防御树(ADT),以从安全评估中提取与安全相关的信息。
- 使用答案集编程(ASP)正式检测安全与安全需求之间的逻辑矛盾。
- 应用定量评估技术,将安全评估结果整合到安全论证中。
- 为GSN节点定义领域特定的语义,以支持自动化模型转换与一致性检查。
- 提出一种协作式开发流程,使安全与安全工程师能够使用各自的建模技术,逐步构建并完善论证。
- 在逻辑编程中编码系统不变量与约束,以验证一致性并解决冲突。
实验结果
研究问题
- RQ1如何自动将安全模型(如GSN)转换为安全模型(如ADT),以提取与安全相关的信息?
- RQ2安全评估结果在何种程度上会影响对安全论证的信心?
- RQ3安全与安全工程师如何在一种增量式、基于模型的流程中协作构建并完善安全与安全论证?
- RQ4哪些自动化技术可以检测安全与安全需求之间的逻辑矛盾?
- RQ5如何在基于模型的工程中形式化并支持安全与安全之间的权衡分析?
主要发现
- 从GSN模型到ADT的正式映射,实现了从安全评估中自动提取与安全相关的信息。
- 答案集编程成功检测到门锁需求与火灾信号条件之间的逻辑矛盾,证实了冲突假设的存在。
- 通过一个逻辑程序识别出仅包含冲突条件的单一答案集,成功实现了矛盾检测,证明了该方法的可行性。
- 通过添加一个在锁定前检查火灾状态的系统不变量,成功解决了该矛盾,恢复了系统的一致性。
- 该方法支持自动化冲突检测,并可扩展用于检测其他类型的冲突,如时序相关或资源相关的权衡。
- 该框架支持可追溯的协作式安全与安全论证,有助于未来支持ISO 26262和SAE J3061等认证流程。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。