首页> 外文期刊>Systems Engineering >A model-based systems engineering approach to critical infrastructure vulnerability assessment and decision analysis
【24h】

A model-based systems engineering approach to critical infrastructure vulnerability assessment and decision analysis

机译:基于模型的系统工程方法进行关键基础架构漏洞评估和决策分析

获取原文
获取原文并翻译 | 示例
           

摘要

Securing critical infrastructure against attack presents significant challenges. As new infrastructure is built and existing infrastructure is maintained, a method to assess the vulnerabilities and support decision makers in determining the best use of security resources is needed. In response to this need, this research develops a methodology for performing vulnerability assessment and decision analysis of critical infrastructure using model-based systems engineering, an approach that has not been applied to this problem. The approach presented allows architects to link regulatory requirements, system architecture, subject matter expert opinion and attack vectors to a Department of Defense Architecture Framework (DoDAF)-based model that allows decision makers to evaluate system vulnerability and determine alternatives to securing their systems based on their budget constraints. The decision analysis is done using an integer linear program that is integrated with DoDAF to provide solutions for how to allocate scarce security resources. Securing an electrical substation is used as an illustrative case study to demonstrate the methodology. The case study shows that the method presented here can be used to answer key questions, for example, what security resources should a decision maker invest in based on their budget constraints? Results show that the modeling and analysis approach provides a means to effectively evaluate the infrastructure vulnerability and presents a set of security alternatives for decision makers to choose from, based on their vulnerabilities and budget profile.
机译:保护关键基础架构免受攻击带来了巨大挑战。随着新基础架构的建立和现有基础架构的维护,需要一种方法来评估漏洞并支持决策者确定最佳使用安全资源的方法。为满足这种需求,本研究开发了一种方法,该方法使用基于模型的系统工程来对关键基础架构进行漏洞评估和决策分析,而该方法尚未应用于此问题。提出的方法使架构师可以将法规要求,系统架构,主题专家的意见和攻击媒介链接到基于国防部架构框架(DoDAF)的模型,该模型使决策者可以评估系统漏洞并确定基于以下方法保护其系统的备选方案他们的预算限制。使用与DoDAF集成在一起的整数线性程序来完成决策分析,以提供有关如何分配稀缺安全性资源的解决方案。以变​​电站的固定为例来说明这种方法。案例研究表明,此处介绍的方法可用于回答关键问题,例如,决策者应根据预算约束来投资哪些安全资源?结果表明,建模和分析方法提供了一种有效评估基础结构漏洞的方法,并根据决策者的漏洞和预算状况为决策者提供了一组安全选择。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号