Quantitative Security and Safety Analysis with Attack-Fault Trees

dc.contributor.authorKumar, Rajesh
dc.date.accessioned2023-01-09T07:21:48Z
dc.date.available2023-01-09T07:21:48Z
dc.date.issued2017
dc.description.abstractCyber physical systems, like power plants, medical devices and data centers have to meet high standards, both in terms of safety (i.e. absence of unintentional failures) and security(i.e. no disruptions due to malicious attacks). This paper presents attack fault trees (AFTs), a formalism thatmarries fault trees (safety) and attack trees (security). We equipAFTs with stochastic model checking techniques, enabling a rich plethora of qualitative and quantitative analyses. Qualitative metrics pinpoint to root causes of the system failure, while quantitative metrics concern the likelihood, cost, and impact of a disruption. Examples are: (1) the most likely attack path, (2) the most costly system failure, (3) the expected impact of an attack. Each of these metrics can be constrained, i.e., we can provide the most likely disruption within time t and/or budget B. Finally, we can use sensitivity analysis to find the attack step that has the most influence on a given metric. We demonstrate our approach through three realistic cases studies.en_US
dc.identifier.urihttps://ieeexplore.ieee.org/document/7911867
dc.identifier.urihttp://dspace.bits-pilani.ac.in:8080/xmlui/handle/123456789/8393
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.subjectComputer Scienceen_US
dc.subjectSafety-security risk analysisen_US
dc.subjectModel-checkingen_US
dc.subjectAttack treesen_US
dc.subjectIndustrial case studiesen_US
dc.titleQuantitative Security and Safety Analysis with Attack-Fault Treesen_US
dc.typeArticleen_US

Files

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: