2016 23rd Asia-Pacific Software Engineering Conference (APSEC) 2016
DOI: 10.1109/apsec.2016.023
|View full text |Cite
|
Sign up to set email alerts
|

Model Driven Software Security Architecture of Systems-of-Systems

Abstract: Recently, there is a growing interest in Systems of Systems (SoS), their architecture, security and application domains. However, their specific characteristics such as the operational independence of SoS constituent systems (CS), the absence of central authority and their emergent behavior make the modeling of their structure, behavior and security a complex task. One of the current main security challenges in the context of SoS is the cascading attack problem. The challenge is to predict the concatenation/se… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
12
0

Year Published

2018
2018
2024
2024

Publication Types

Select...
4
3
2

Relationship

2
7

Authors

Journals

citations
Cited by 24 publications
(12 citation statements)
references
References 26 publications
0
12
0
Order By: Relevance
“…He/she cannot rely on existing secure system development methodologies such as Microsoft SDL [13], OWASP [21], Secure i* [10] or SysML-Sec [3], as they are not always well adapted to SoS. There are some specific methodologies in securing SoS, such as SoSSec [12] or Security Framework Architecture [22], but these methodologies take a long time and require the strong security skill. Thus, the domain expert must interact with security experts but such a collaboration is not always possible because security experts are not necessarily available in an emergency.…”
Section: Problem Statementmentioning
confidence: 99%
See 1 more Smart Citation
“…He/she cannot rely on existing secure system development methodologies such as Microsoft SDL [13], OWASP [21], Secure i* [10] or SysML-Sec [3], as they are not always well adapted to SoS. There are some specific methodologies in securing SoS, such as SoSSec [12] or Security Framework Architecture [22], but these methodologies take a long time and require the strong security skill. Thus, the domain expert must interact with security experts but such a collaboration is not always possible because security experts are not necessarily available in an emergency.…”
Section: Problem Statementmentioning
confidence: 99%
“…Unfortunately, the domain experts generally do not have any security skills. They cannot rely on existing SoS security methodologies such as SoSSec [12]. Indeed, such methods require a long time and interactions with security experts, which is not always possible when in an emergency.…”
Section: Introductionmentioning
confidence: 99%
“…This shall also be covered in forthcoming advances on this research. Other future work lines include (i) comparison among coalitions through the substitution of constituents that offer the same capability for better decision-making between different brands, (ii) adoption of cosimulation to accurately reproduce the scenarios required for other quality attributes such as security [Hachem et al 2016], and (iii) establishment of a mechanism for automation of the cost estimation through the integration between the simulator, a mechanism for querying and comparing market prices, and some model-checker mechanism to automatically deliver the best coalition, without the need to manually collect and analyze data. We also consider that, for large volumes of data, we can apply search-based software engineering to support the selection of constituents from criteria related to technical and economic aspects of software.…”
Section: Final Remarksmentioning
confidence: 99%
“…Additionally, we defined and implemented a matching mechanism that helps identifying the possible concatenation/sequence of triggered vulnerabilities in order to discover emergent unknown security cascading attacks. Finally, we used Model-Driven Engineering (MDE) to implement a generator tool (a set of Model-To-Text transformation rules) to (semi)automatically map the secure SoS architectures modeled using an SysML-based modeling language, the SoSSecML [10], to the extended MAS platform.…”
Section: Introductionmentioning
confidence: 99%