WP6 – Risk Analysis and Mitigation Strategies

 Coordinated by
RES (M01-M16)

Objective

This work package researches and develops a methodology for continuous risk assessment process on the ICT supply chain, such that the system is continuously analyzed for potential weaknesses, and corresponding mitigation strategies can be enacted using BIECO solutions.

This WP has the following concrete objectives:

  1. To identify in an automated fashion main threats, including those that could also derive in a physical hazard in a cyber-physical system.
  2. To compute the severity of the consequences of threats and hazards.
  3. To make the link between systems’ internal security causes and their possible safety hazards explicit, e.g. in failure logic models such as Component Fault Trees.
  4. To define mitigation strategies.
  5. Out of both design time risk assessment models and mitigation strategies, runtime risk management models shall be synthesized systematically that are suitable to support runtime resilience mechanisms defined in WP4.
  6. Design and develop security, privacy and accountability measures for all the entities involved in the supply chain.

Envisioned mitigations range from process-based to architecture-based as well as related to the introduction of new patches and error detectors. The WP will ultimately produce a methodology and supporting tools for the systematic and automated i) analysis of risks, and ii) identification of mitigations that shall be equipped in the BIECO framework.

Deliverables

Outcomes

Ontology Manager Tool

Ontology Manager is a Framework responsible for managing the Core Ontology used in BIECO, called DAEMON. It aims to support organizing concepts and their relationships related to System of Systems (SoS), Internet of Things (IoT), and System Components management and Monitoring.

Vulnerabilities Forecasting Tool

The Vulnerabilities Forecasting Tool (VFT) provides historical vulnerability data and projections for time intervals of 1, 2, 3, 6, and 12 months for several major software components.

Failure Prediction Tool

The Failure Prediction Tool (FPT) performs failure predictions by monitoring the logs of the applications that make up a system. It has a REST interface through which it receives in real time the log messages from the monitored applications.

safeTbox

The pre-existing tool safeTbox (www.safetbox.de) has been extended to support interoperation with the ResilBlockly tool for combined safety and security analysis.

Conditional Safety Certificates for ICT

Conditional Safety Certificates (ConSerts) have been applied to support resiliency of ICT infrastructures. Support for deployment and execution of ConSerts in ICT infrastructure according to use case needs was provided additionally.

BIECO Project

SUBSCRIBE and become part of the BIECO community!

We don’t spam!

Share This