首页> 外文期刊>Systems Engineering >A model-based systems engineering approach to critical infrastructure vulnerability assessment and decision analysis
【24h】

A model-based systems engineering approach to critical infrastructure vulnerability assessment and decision analysis

机译:基于模型的系统工程方法,可实现关键基础设施漏洞评估和决策分析

获取原文
获取原文并翻译 | 示例
           

摘要

Securing critical infrastructure against attack presents significant challenges. As new infrastructure is built and existing infrastructure is maintained, a method to assess the vulnerabilities and support decision makers in determining the best use of security resources is needed. In response to this need, this research develops a methodology for performing vulnerability assessment and decision analysis of critical infrastructure using model-based systems engineering, an approach that has not been applied to this problem. The approach presented allows architects to link regulatory requirements, system architecture, subject matter expert opinion and attack vectors to a Department of Defense Architecture Framework (DoDAF)-based model that allows decision makers to evaluate system vulnerability and determine alternatives to securing their systems based on their budget constraints. The decision analysis is done using an integer linear program that is integrated with DoDAF to provide solutions for how to allocate scarce security resources. Securing an electrical substation is used as an illustrative case study to demonstrate the methodology. The case study shows that the method presented here can be used to answer key questions, for example, what security resources should a decision maker invest in based on their budget constraints? Results show that the modeling and analysis approach provides a means to effectively evaluate the infrastructure vulnerability and presents a set of security alternatives for decision makers to choose from, based on their vulnerabilities and budget profile.
机译:确保攻击的关键基础设施存在重大挑战。随着新的基础架构是构建的,并且维护了现有的基础架构,需要一种评估漏洞和支持决策者在确定最佳安全资源时的方法。为了响应这种需求,本研究开发了一种使用基于模型的系统工程进行关键基础设施的漏洞评估和决策分析的方法,这是一种尚未应用于此问题的方法。该方法允许建筑师将监管要求,系统架构,主题专家意见和攻击向量链接到防御架构框架(Dodaf)的基础模型,允许决策者评估系统漏洞并确定基于保护系统的替代方案他们的预算限制。使用整数线性程序进行决策分析,该程序与Dodaf集成,为如何分配稀缺安全资源提供解决方案。固定电变电站作为说明方法的说明性研究。案例研究表明,这里呈现的方法可用于回答关键问题,例如,决策者基于预算限制的决策者投资哪些安全资源?结果表明,建模和分析方法提供了有效评估基础设施漏洞的方法,并为决策者提供一系列安全替代方案,以根据其漏洞和预算配置文件选择。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号