2017
DOI: 10.4236/ijcns.2017.105005
|View full text |Cite
|
Sign up to set email alerts
|

A Systems-Theoretic Security Model for Large Scale, Complex Systems Applied to the US Air Transportation System

Abstract: Classical risk-based or game-theoretic security models rely on assumptions from reliability theory and rational expectations economics that are not applicable to security threats. Additionally, these models suffer from serious deficiencies when they are applied to software-intensive, socio-technical systems. A new approach is proposed in this paper that applies principles from control theory to enforce constraints on security threats thereby extending techniques used in system safety engineering. It is applied… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
3
2
1

Relationship

1
5

Authors

Journals

citations
Cited by 8 publications
(3 citation statements)
references
References 24 publications
0
3
0
Order By: Relevance
“…Laracy [27], [28] recognized the similarities between safety and security and proposed an extension of STAMP to security problems of critical infrastructure, such as the Air Transportation System. This approach was called STAMP-Sec [27].…”
Section: System-theoretic Accident Model and Processes (Stamp)mentioning
confidence: 99%
“…Laracy [27], [28] recognized the similarities between safety and security and proposed an extension of STAMP to security problems of critical infrastructure, such as the Air Transportation System. This approach was called STAMP-Sec [27].…”
Section: System-theoretic Accident Model and Processes (Stamp)mentioning
confidence: 99%
“…Although originally developed for safety, many of the theory's constructs are applicable to security. David Zipkin has shown the applicability of the model on policies for managing malicious software [45] while Joseph R. Laracy has explored its use for bio-defense planning [46] and air transportation [47]. The model with security extensions that will be defined in this paper is referred to as STAMP-Sec.…”
Section: A New Approachmentioning
confidence: 99%
“…Unlike system safety models in which hazards are often "generated" endogenously within the socio-technical system, security threats may develop exogenously. While the "insider-threat" risk must be addressed, malicious actors outside of the system under discussion must be also modeled [47].…”
Section: Auditabilitymentioning
confidence: 99%