WP6 – Risk Analysis and Mitigation Strategies
Coordinated by
RES (M01-M16)
Objective
This work package researches and develops a methodology for continuous risk assessment process on the ICT supply chain, such that the system is continuously analyzed for potential weaknesses, and corresponding mitigation strategies can be enacted using BIECO solutions.
This WP has the following concrete objectives:
- To identify in an automated fashion main threats, including those that could also derive in a physical hazard in a cyber-physical system.
- To compute the severity of the consequences of threats and hazards.
- To make the link between systems’ internal security causes and their possible safety hazards explicit, e.g. in failure logic models such as Component Fault Trees.
- To define mitigation strategies.
- Out of both design time risk assessment models and mitigation strategies, runtime risk management models shall be synthesized systematically that are suitable to support runtime resilience mechanisms defined in WP4.
- Design and develop security, privacy and accountability measures for all the entities involved in the supply chain.
Envisioned mitigations range from process-based to architecture-based as well as related to the introduction of new patches and error detectors. The WP will ultimately produce a methodology and supporting tools for the systematic and automated i) analysis of risks, and ii) identification of mitigations that shall be equipped in the BIECO framework.
Deliverables
- D6.1 Blockly4SoS model and simulator WP6 (7 – RESILTECH) Report Public M10
- D6.2 Blockly4SoS user guide WP6 (7 – RESILTECH) Report Public M12
- D6.3 Risk Assessment and additional requirements WP6 (10 – 7BULLS) Report Public M24
- D6.4 Mitigations identification and their design WP6 (2 – Fraunhofer) Report Public M16
Outcomes
WP8 monthly meeting
BIECO WP8 monthly meetingThe 9th of November 2021, the monthly meeting for Work Package 8 was held. It was a great meeting, with lots of clarifications, where some low and high-level aspects of the platform were discussed and agreed upon..
On Autonomous Dynamic Software Ecosystems
The Journal paper "On Autonomous Dynamic Software Ecosystems" co-authored together with experts in the field of architecture has been accepted in the journal of IEEE Transactions on Engineering Management. Document type: Article DOI: 10.1109/tem.2021.3116873...
WP6 monthly meeting M15
The 8th November took place the WP6 monthly meeting. In the meeting, 7Bulls updated on their status regarding T6.4, Fraunhofer IESE updated regarding the status of T6.3, IESE provided an allocation for deliverable sections, CNR provided updates regarding their...
ISSRE, within the joint IWSF&SHIFT
The 5th International Workshop on Software Faults& The 3rd Annual International Workshop on Software Hardware Interaction FaultsThe goal of the joint 5th International Workshop on Software Faults (IWSF) and 3rd Annual International Workshop on Software Hardware...
WP7 monthly meeting M14
The 25th October took place the WP7 monthly meeting. We focused on the definition of the different steps needed to evaluate and certificate the security of a system.
Monthly WP3 meeting
BIECO WP3The monthly meeting of Wp3 took place on October 25, where the latest progress as well as the future actions of the WP were updated. The discussions were centered on both T3.3 and T3.4 tasks, which focus on detecting the vulnerabilities in the source code, as...