Abstract
Safety and security can be heavily intertwined. Measures that increase safety may decrease security and vice versa: smart IoT sensors offer ample opportunities to monitor the safety of power plants and wind turbines, but their many access points are notorious for enabling hackers to enter the system. When considering the intertwined nature of safety-security risk management, one overarching challenge stands out: decision making. How to effectively evaluate which risks are most threatening, and which countermeasures are most (cost-)effective? These decisions are notoriously hard to take: it is well-understood – e.g., from research by Nobel prize winner Daniel Kahneman – that people have very poor intuitions for risks and probability, especially when taking decisions in a hurry.
In this thesis, we foster transparent, systematic and objective decision making by developing a compositional framework to reason about safety-, security- and joint safety-security risks. We empower practitioners with the ability to 1. model systems with sufficient expressiveness; 2. query their models with flexible yet powerful languages; and 3. check whether their models exhibit (un)desirable characteristics. To do so, we leverage already established formal models for risk assessment – such as fault trees and attack trees – and develop powerful yet understandable logics that can reason about qualitative and quantitative aspects of risk, such as failure probabilities, success, cost and time of (cyber)attacks. In addition, we develop intermediate query languages to propel usability, and state-of-the-art model checking algorithms to verify safety-security properties of these models. Finally, we explore cross-fertilization between this framework and conceptual analyses from the field of risk ontology and offer prototypical tool support to promote usage of our methods.
| Original language | English |
|---|---|
| Qualification | Doctor of Philosophy |
| Awarding Institution |
|
| Supervisors/Advisors |
|
| Award date | 26 Nov 2024 |
| Place of Publication | Enschede |
| Publisher | |
| Print ISBNs | 978-90-365-6342-0 |
| Electronic ISBNs | 978-90-365-6343-7 |
| DOIs | |
| Publication status | Published - Nov 2024 |
Keywords
- Logic
- Fault Tree Analysis
- Attack trees
- Fault Trees
- Risk Management
- Query languages
- Model Checking
- Ontological Analysis
- Property specification
Fingerprint
Dive into the research topics of 'If a Tree Falls in the Forest: Risk Logics for Safety-Security Analysis'. Together they form a unique fingerprint.Prizes
-
Best Paper Award at the 21st International Conference on Software Engineering and Formal Methods
Nicoletti, S. M. (Recipient), Lopuhaä - Zwakenberg, M. A. (Recipient), Hahn, E. M. (Recipient) & Stoelinga, M. I. A. (Recipient), 10 Nov 2023
Prize
File
Datasets
-
Quantitative Comparisons of MITRE ATT&CK Campaigns
Nicoletti, S. M. (Creator), Lopuhaä - Zwakenberg, M. A. (Creator), Stoelinga, M. (Creator), Massacci, F. (Creator) & Budde, C. (Creator), 4TU.Centre for Research Data, 30 Aug 2024
DOI: 10.4121/779a6a17-ed5e-4bfc-9068-6a16e3f7d10d, https://data.4tu.nl/datasets/779a6a17-ed5e-4bfc-9068-6a16e3f7d10d and 2 more links, https://data.4tu.nl/datasets/779a6a17-ed5e-4bfc-9068-6a16e3f7d10d/1, https://doi.org/10.4121/779a6a17-ed5e-4bfc-9068-6a16e3f7d10d.v1 (show fewer)
Dataset
-
Artifact for the paper Solving Queries for Boolean Fault Tree Logic via Quantified SAT
Saaltink, C. (Creator), Nicoletti, S. M. (Creator), Volk, M. (Creator), Hahn, E. M. (Creator) & Stoelinga, M. (Creator), Zenodo, 21 Jul 2023
DOI: 10.5281/zenodo.8172548, https://zenodo.org/record/8172549 and 3 more links, https://zenodo.org/record/10940255, https://doi.org/10.5281/zenodo.8172549, https://doi.org/10.5281/zenodo.10940255 (show fewer)
Dataset
-
Querying Fault and Attack Trees: Property Specification on a Water Network
Nicoletti, S. M., Lopuhaä-Zwakenberg, M., Hahn, E. M. & Stoelinga, M., 2024, 2024 Annual Reliability and Maintainability Symposium (RAMS). IEEE, 6 p. (Proceedings, Annual Reliability and Maintainability Symposium).Research output: Chapter in Book/Report/Conference proceeding › Conference contribution › Academic › peer-review
Open AccessFile3 Link opens in a new tab Citations (Scopus)24 Downloads (Pure) -
ATM: A Logic for Quantitative Security Properties on Attack Trees
Nicoletti, S. M., Lopuhaä-Zwakenberg, M., Hahn, E. M. & Stoelinga, M., 2023, Software Engineering and Formal Methods: 21st International Conference, SEFM 2023, Eindhoven, The Netherlands, November 6-10, 2023, Proceedings. Ferreira, C. & Willemse, T. A. C. (eds.). Cham: Springer, p. 205-225 21 p. (Lecture Notes in Computer Science; vol. 14323).Research output: Chapter in Book/Report/Conference proceeding › Conference contribution › Academic › peer-review
Open AccessFile2 Link opens in a new tab Citations (Scopus)83 Downloads (Pure) -
Model-Based Joint Analysis of Safety and Security: Survey and Identification of Gaps
Nicoletti, S. M., Peppelman, M., Kolb, C. & Stoelinga, M., Nov 2023, In: Computer science review. 50, 16 p., 100597.Research output: Contribution to journal › Article › Academic › peer-review
Open AccessFile10 Link opens in a new tab Citations (Scopus)162 Downloads (Pure)
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver