DACH: Österreich - Deutschland - Schweiz
Disciplines
Computer Sciences (100%)
Keywords
-
Safety Engineering,
Self-Adaptive Systems,
Security Engineering,
Model-Based Software Engineering,
Empirical Software Engineering
Modern cyber-physical systems, such as connected cars, connected factories in the 4.0 age industry or quadrocopter swarms are typically safety-critical systems that may harm their environment. They increasingly make decisions autonomously and, thus, adapt their behavior to changes in the system itself and the environment by performing self-adaptation. Due to the connectedness of these systems, security has become the key influence factor for their safety with the possibility of severe consequences for the health or even the life of affected people. Therefore, the integration of security aspects into modern safety analysis is a must in order to be able to employ the appropriate techniques to ensure that hazards are eliminated, reduced, or controlled. However, suitable approaches for integrated safety and security modeling and analysis are still rare. The project SafeSec: Integrated Safety and Security Model Generation and Analysis of Self- Adaptive Systems will overcome this issue and provides for the first time a combined safety and security engineering approach for self-adaptive systems. For that purpose, SafeSec develops a novel hazard analysis approach that integrates system and fault models with attack models. To enable this novel hazard analysis approach attacks to self-adaptive systems are systematically analyzed and a suitable attack modeling language is developed. Modeling security attacks is essential for the provided new hazard analysis approach, but requires specific knowledge and is time consuming. Therefore, SafeSec additionally contributes a novel approach to mine attack models based on the available system and fault models, system structure as well as additional empirical data sources like vulnerability databases or forums. The evaluation of SafeSec is based on a quadrocopter lab case as well as industrial aerospace and plant control systems.
Modern cyber-physical systems, such as connected cars, connected factories in the 4.0 age industry or quadrocopter swarms are typically safety-critical systems that may harm their environment. They increasingly make decisions autonomously and, thus, adapt their behavior to changes in the system itself and the environment by performing self-adaptation. Due to the connectedness of these systems, security has become the key influence factor for their safety with the possibility of severe consequences for the health or even the life of affected people. Therefore, the integration of security aspects into modern safety analysis is a must in order to be able to employ the appropriate techniques to ensure that hazards are eliminated, reduced, or controlled. However, suitable approaches for integrated safety and security modeling and analysis are still rare. The project "SafeSec: Integrated Safety and Security Model Generation and Analysis of Self-Adaptive Systems" will overcome this issue and provides for the first time a combined safety and security engineering approach for self-adaptive systems. For that purpose, SafeSec develops a novel hazard analysis approach that integrates system and fault models with attack models. To enable this novel hazard analysis approach attacks to self-adaptive systems are systematically analyzed and a suitable attack modeling language is developed. Modeling security attacks is essential for the provided new hazard analysis approach, but requires specific knowledge and is time consuming. Therefore, SafeSec additionally contributes a novel approach to mine attack models based on the available system and fault models, system structure as well as additional empirical data sources like vulnerability databases or forums. The evaluation of SafeSec is based on a quadrocopter lab case.
- Universität Innsbruck - 100%
- Matthias Tichy, Universität Ulm - Germany
Research Output
- 181 Citations
- 27 Publications
- 3 Datasets & models
- 1 Software
-
2023
Title Guiding the retraining of convolutional neural networks against adversarial inputs DOI 10.60692/yg71h-w8v08 Type Other Author Francisco Durán Link Publication -
2023
Title Guiding the retraining of convolutional neural networks against adversarial inputs DOI 10.60692/djr3y-nd073 Type Other Author Francisco Durán Link Publication -
2022
Title Guiding the retraining of convolutional neural networks against adversarial inputs DOI 10.48550/arxiv.2207.03689 Type Preprint Author López F -
2022
Title Metamorphic Testing in Autonomous System Simulations DOI 10.48550/arxiv.2209.11031 Type Preprint Author Adigun J -
2023
Title A systematic review on security and safety of self-adaptive systems DOI 10.1016/j.jss.2023.111716 Type Journal Article Author Pekaric I Journal Journal of Systems and Software Pages 111716 Link Publication -
2023
Title Model-Based Generation of Attack-Fault Trees DOI 10.48550/arxiv.2309.09941 Type Preprint Author Groner R -
2023
Title Towards Model Co-evolution Across Self-Adaptation Steps for Combined Safety and Security Analysis DOI 10.48550/arxiv.2309.09653 Type Preprint Author Witte T -
2023
Title VULNERLIZER: Cross-analysis Between Vulnerabilities and Software Libraries DOI 10.48550/arxiv.2309.09649 Type Preprint Author Pekaric I -
2023
Title Simulation of Sensor Spoofing Attacks on Unmanned Aerial Vehicles Using the Gazebo Simulator DOI 10.48550/arxiv.2309.09648 Type Preprint Author Pekaric I -
2023
Title Model-Based Generation of Attack-Fault Trees DOI 10.1007/978-3-031-40923-3_9 Type Book Chapter Author Groner R Publisher Springer Nature Pages 107-120 -
2023
Title Risk-driven Online Testing and Test Case Diversity Analysis for ML-enabled Critical Systems DOI 10.1109/issre59848.2023.00017 Type Conference Proceeding Abstract Author Adigun J Pages 344-354 Link Publication -
2023
Title Streamlining Attack Tree Generation: A Fragment-Based Approach DOI 10.48550/arxiv.2310.00654 Type Preprint Author Pekaric I -
2023
Title Guiding the retraining of convolutional neural networks against adversarial inputs DOI 10.7717/peerj-cs.1454 Type Journal Article Author Durán F Journal PeerJ Computer Science Link Publication -
2024
Title Towards Real-time Object Detection for Safety Analysis in an ML-Enabled System Simulation Type Journal Article Author Adigun J G Journal WiPiEC Journal-Works in Progress in Embedded Computing Journal Link Publication -
2024
Title Streamlining Attack Tree Generation: A Fragment-Based Approach Type Conference Proceeding Abstract Author Frick M. Conference Hawaii International Conference on System Sciences (HICSS 2024) Pages 7447-7456 Link Publication -
2022
Title What is software quality for AI engineers? DOI 10.1145/3522664.3528599 Type Conference Proceeding Abstract Author Golendukhina V Pages 1-9 Link Publication -
2022
Title Towards model co-evolution across self-adaptation steps for combined safety and security analysis DOI 10.1145/3524844.3528062 Type Conference Proceeding Abstract Author Witte T Pages 106-112 Link Publication -
2022
Title Collaborative Artificial Intelligence Needs Stronger Assurances Driven by Risks DOI 10.1109/mc.2021.3131990 Type Journal Article Author Adigun J Journal Computer Pages 52-63 Link Publication -
2022
Title What is Software Quality for AI Engineers? Towards a Thinning of the Fog DOI 10.48550/arxiv.2203.12697 Type Preprint Author Golendukhina V -
2022
Title Attack Model Mining for Security Assurance of Self-Adaptive Systems Type PhD Thesis Author Irdin Pekaric -
2022
Title Metamorphic Testing in Autonomous System Simulations DOI 10.1109/seaa56994.2022.00059 Type Conference Proceeding Abstract Author Adigun J Pages 330-337 Link Publication -
2022
Title Simulation of Sensor Spoofing Attacks on Unmanned Aerial Vehicles using the Gazebo Simulator DOI 10.1109/qrs-c57518.2022.00016 Type Conference Proceeding Abstract Author Pekaric I Pages 44-53 Link Publication -
2021
Title Collaborative Artificial Intelligence Needs Stronger Assurances Driven by Risks DOI 10.48550/arxiv.2112.00740 Type Preprint Author Adigun J -
2021
Title Controlled Experimentation in Continuous Experimentation: Knowledge and Challenges DOI 10.48550/arxiv.2102.05310 Type Preprint Author Auer F -
2021
Title Controlled experimentation in continuous experimentation: Knowledge and challenges DOI 10.1016/j.infsof.2021.106551 Type Journal Article Author Auer F Journal Information and Software Technology Pages 106551 Link Publication -
2021
Title VULNERLIZER: Cross-analysis Between Vulnerabilities and Software Libraries DOI 10.24251/hicss.2021.843 Type Conference Proceeding Abstract Author Pekaric I Link Publication -
2021
Title From monolithic systems to Microservices: An assessment framework DOI 10.1016/j.infsof.2021.106600 Type Journal Article Author Auer F Journal Information and Software Technology Pages 106600 Link Publication
-
2023
Link
Title Risk-driven Online Testing and Test Case Diversity Analysis for ML-enabled Critical Systems (Replication Package) DOI 10.5281/zenodo.8152294 Type Database/Collection of data Public Access Link Link -
2023
Link
Title cais_rtod Type Computer model/algorithm Public Access Link Link -
2021
Link
Title A Systematic Review on Security and Safety of Self-adaptive Systems (Supplementary Materials) DOI 10.5281/zenodo.5799781 Type Database/Collection of data Public Access Link Link