WP4 – Development of Resilient Systems
Coordinated by
IESE (M01-M36)
Objective
In this WP, tools and methods will be developed for supporting creation of resilient systems w.r.t security attacks and vulnerabilities. The scope is to develop systems that can cope with behavior disturbances caused by malicious attacks, that manifest into a loss of control and can bring a system into hazardous situations. A resilient system shall be able to compensate for interruptions and get back into a safe state in case of emergency situations caused by malicious attacks. In this regard the system shall be able to autonomously and automatically construct awareness of its security in a dynamic environment, to recognize critical situations and to identify the right operational mode for remaining into a secure and trusted operational state.
Concretely, this work package has the following objectives:
- To develop methods and tools that enable runtime evaluation of system operational state in dynamic environments.
- To enhance existing tools that can predict failure propagation caused by malicious attacks and support the transition of an ICT system into a resilient state. Prediction is performed in a simulated environment by counteracting the capabilities of the system under evaluation to detect that it is under evaluation.
- To develop methods that during runtime bring a system into a safe, trusted state, making it resilient to malicious attacks.
Deliverables
- D4.1 Report on Self-checking of vulnerabilities and failures WP4 (7 – RESILTECH) Report Confidential, only for members of the consortium (including the Commission Services) M30
- D4.2 Report on methods and tools for the failure prediction WP4 (2 – Fraunhofer) Report Confidential, only for members of the consortium (including the Commission Services) M24
- D4.3 Report on Method development for resilient systems WP4 (2 – Fraunhofer) Report Confidential, only for members of the consortium (including the Commission Services) M30
Outcomes
Final review Meeting 28 September 2023
DRAFT AGENDA: Thursday 28th September 2023 13.00 – 17.00 CET AGENDA Overview 13:00 - 13:10Project Overview13:10 - 13:25BIECO Tools13:25 - 14:35BIECO Use Cases,including Demos14:35:15:05WP3 & WP4 Presentations15:05 - 15:15BREAK15:15 - 16:15WP5 - WP8...
BIECO Integrated Platform
BIECO Integrated Platform will integrate the tools in a loosely coupled way.
Data Collection Tool
Data Collection Tool (DCT) stores information from relevant vulnerability related datasets, providing a single access point to information required by the vulnerability detection and forecasting tools developed in T3.3, as well as for the failure prediction tools developed in T4.2.
Vulnerability Detection Tool
Vulnerability Detection Tool will detect existing vulnerabilities within the source code which may lead to the successful execution of an attack.
Vulnerability Exploitability Forecasting Tool
Vulnerability Exploitability Forecasting Tool will estimate the probability of a vulnerability to be exploited in the next 3, 6 or 12 months.
Vulnerability Propagation Tool
Vulnerability Propagation Tool will calculate and offer the paths affected by a vulnerability in the source code.