WP6 – Risk Analysis and Mitigation Strategies
Coordinated by
RES (M01-M16)
Objective
This work package researches and develops a methodology for continuous risk assessment process on the ICT supply chain, such that the system is continuously analyzed for potential weaknesses, and corresponding mitigation strategies can be enacted using BIECO solutions.
This WP has the following concrete objectives:
- To identify in an automated fashion main threats, including those that could also derive in a physical hazard in a cyber-physical system.
- To compute the severity of the consequences of threats and hazards.
- To make the link between systems’ internal security causes and their possible safety hazards explicit, e.g. in failure logic models such as Component Fault Trees.
- To define mitigation strategies.
- Out of both design time risk assessment models and mitigation strategies, runtime risk management models shall be synthesized systematically that are suitable to support runtime resilience mechanisms defined in WP4.
- Design and develop security, privacy and accountability measures for all the entities involved in the supply chain.
Envisioned mitigations range from process-based to architecture-based as well as related to the introduction of new patches and error detectors. The WP will ultimately produce a methodology and supporting tools for the systematic and automated i) analysis of risks, and ii) identification of mitigations that shall be equipped in the BIECO framework.
Deliverables
- D6.1 Blockly4SoS model and simulator WP6 (7 – RESILTECH) Report Public M10
- D6.2 Blockly4SoS user guide WP6 (7 – RESILTECH) Report Public M12
- D6.3 Risk Assessment and additional requirements WP6 (10 – 7BULLS) Report Public M24
- D6.4 Mitigations identification and their design WP6 (2 – Fraunhofer) Report Public M16
Outcomes
WP6 monthly meeting M7
The 1st March took place the WP6 monthly meeting. IESE presented their tool called SafeTbox and they introduced the Conditional Safety Certificates (ConSerts). During this monthly meeting, IESE presented their tool called safeTbox, a tool for modelling and safety...
WP6 monthly meeting M6
The 1st February took place the WP6 monthly meeting. During the meeting it was presented ResilBlockly, the new refactored and extended version of the Blockly4SoS tool. The main focus of this call was on the presentation of Blockly4SoS and on the live demo of the new...
WP6 monthly meeting M5
The 11th January took place the WP6 monthly meeting. Resiltech shared a document with requirements for the extension of Blockly4SoS. It has also been decided that MUD files will be an input of the modelling activities. Resiltech shared a document with requirements for...
WP6 Monthly meeting M4
The 7th December took place the WP6 monthly meeting. The partners discussed about the preliminary results of tasks T6.1 and T6.2. During the meeting, the partners discussed about the preliminary results of tasks T6.1 and T6.2, shared by Resiltech, leader of the two...
Bieco WP5 – Kick Off meeting
On 2th December 2020, we had a remote Kickoff Meeting for WP5 of the European cybersecurity project @bieco_org. It was a great meeting with participants from Portugal, Germany, Italy, Romania, Spain, Austria and Poland. Due to COVID-19 situation, the meeting was held...
Kick-Off meeting of WP4
On 12th of November, we had the internal Kick-Off meeting of WP4, led by Fraunhofer IESE. Within WP4, methods and tools are developed for assuring system resilience based on runtime evaluation of (Software) component behaviours. Specifically, in a runtime...