Journal Article Open Access

An extension of the ADVISE Meta Modeling Framework and its application for an early-stage security analysis of a Public Transport Supervision System

PDF Online

Authors Francesco Mariotti Andrea Bondavalli Paolo Lollini Leonardo Montecchi Simone Nardi
Abstract
Early-stage security analysis can be used for a preliminary assessment of the security level of a system, thus providing useful insights to guide the whole system’s development. In this paper we focus on a specific meta-level modeling framework for security analysis, ADVISE Meta, which allows representing a system using generic built-in blocks and relationships constituting the ontology of the framework, and to automatically derive complex low-level stochastic models representing attack steps and adversaries. In this paper we extend the ADVISE Meta ontology to enlarge the variety of the possible attack paths and adversaries that can be represented in the framework, to model i) attack patterns available in the CAPEC database, a comprehensive dictionary of known patterns of attack, and ii) the adversaries’ profiles defined in the Threat Agent Library (TAL), a reference library which describes the characteristics of threat agents. The paper provides a detailed description of the whole process for extending the ADVISE Meta ontology, and the application of the extended modeling framework for an early-stage security analysis of a public transport supervision system. The framework enables a variety of security-oriented analyses, in particular to assess the probability that a given adversary can successfully reach a specific goal, to analyse the most probable attack path that adversaries can follow to reach a goal, to perform sensitivity analysis at varying of attack patterns and adversaries’ profiles, to compare different architectural solutions, and to identify the system’s components that can be more probably attacked by adversaries.
DOI https://doi.org/10.1007/s40860-023-00209-5
Journal Journal of Reliable Intelligent Environments
Volume 9
Month June
Year 2023
Pages 263-281
Publisher Springer
Citation
Bibtex
@article{2023JRIE,
  author = {Mariotti, Francesco and Bondavalli, Andrea and Lollini, Paolo and Montecchi, Leonardo and Nardi, Simone},
  title = {{An extension of the ADVISE Meta Modeling Framework and its application for an early-stage security analysis of a Public Transport Supervision System}},
  journal = {Journal of Reliable Intelligent Environments},
  publisher = {Springer},
  volume = {9},
  pages = {263-281},
  month = {6},
  year = {2023}
}

Plain Text
F. Mariotti, A. Bondavalli, P. Lollini, L. Montecchi, S. Nardi. An extension of the ADVISE Meta Modeling Framework and its application for an early-stage security analysis of a Public Transport Supervision System. In: Journal of Reliable Intelligent Environments, Vol. 9, pp. 263-281 (June 2023).
 
 

© 2017-2022 Leonardo Montecchi