<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Modelling and Analysing Socio-Technical Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Zaruhi Aslanyan</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Marieta G. Ivanova</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Flemming Nielson</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Christian W. Probst</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>DTU Compute, Technical University of Denmark</institution>
          ,
          <country country="DK">Denmark</country>
        </aff>
      </contrib-group>
      <fpage>121</fpage>
      <lpage>124</lpage>
      <abstract>
        <p>Modern organisations are complex, socio-technical systems consisting of a mixture of physical infrastructure, human actors, policies and processes. An increasing number of attacks on these organisations exploits vulnerabilities on all different levels, for example combining a malware attack with social engineering. Due to this combination of attack steps on technical and social levels, risk assessment in socio-technical systems is complex. Therefore, established risk assessment methods often abstract away the internal structure of an organisation and ignore human factors when modelling and assessing attacks. In our work we model all relevant levels of socio-technical systems, and propose evaluation techniques for analysing the security properties of the model. Our approach simplifies the identification of possible attacks and provides qualified assessment and ranking of attacks based on the expected impact. We demonstrate our approach on a home-payment system. The system is specifically designed to help elderly or disabled people, who may have difficulties leaving their home, to pay for some services, e.g., care-taking or rent. The payment is performed using the remote control of a television box with a contactless payment card (see Figure 1). When a transfer is initiated, a password is needed in order to authenticate the owner of the card.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Model</title>
      <p>
        Our model is based on work by Probst et al. [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and Dimkov et al. [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. To facilitate
formal methods, the model represents the infrastructure of organisations - the
physical as well as the digital world - as nodes in a directed graph. In this directed
graph nodes that are physically or virtually connected are linked by directed
edges. The nodes represent different elements in the modelled organisation such
as locations, assets, and actors. Nodes may belong to different domains. Domains
are used to restrict operations being allowed on the nodes. For example, human
actors are only allowed to move within the nodes from the physical domain. Some
nodes are associated with policies, which are used for regulating the access to
locations and assets, but also for defining actors’ expected behaviour in the
organisation. Policies consist of two parts - required credentials and enabled
actions. The actor needs to fulfill the required credentials in order to be permitted
to perform the enabled actions on the respective node.
      </p>
      <p>The example scenario, also shown in Figure 2, represents an actor Alice,
who receives a care-taking service provided by an actor Charlie. The company
Charlie works for has a policy that forbids the employees to take money from
the customers. The locations modelled in this scenario are Alice’s home, a bank
with an ATM, and a bank computer. Alice’s payment card, the pin it contains,
and the pin Alice knows for her card are modeled as assets. An example for a
node associated with a policy is the bank computer, where the policy requires a
bank account and a matching password.</p>
      <p>
        In order to identify the possible attacks based on the model, our approach
does not analyse only the technical infrastructure but also takes into
consideration the human factor. Social attacks, e.g., social engineering, are an essential
component as attack threats could be easily underseen when only technical
attacks are considered. The human factor modelling in technical systems is also
formally presented using Isabelle theorem prover [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
    </sec>
    <sec id="sec-2">
      <title>Analysis</title>
      <p>
        Our analysis is carried out on attack trees, a suitable tool for presenting
sociotechnical threats and conveying security information to non-experts. Attack
trees, introduced by Schneier [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ], are a widely used graphical tool for
representing attack scenarios. They are used to evaluate the security of complex systems
in a structured, hierarchical way. The root of a tree represents the main goal
of the attacker, while the leaves are the attacker’s basic actions. Internal nodes
illustrate how the basic actions have to be combined in order to achieve the
overall goal. Standard attack trees combine basic actions either conjunctively,
meaning that all actions should be satisfied in order the tree to be satisfied, or
disjunctively, meaning that at least one action should be satisfied in order the
tree to be satisfied.
      </p>
      <p>Attack trees are analysed by assigning values to the basic actions and
propagating them from the leaves to the root of the tree. Most attack tree analyses
consider attack trees with one parameter and optimise one particular aspect of
a scenario, such as likelihood of success or difficulty of a hack, in terms of time
or cost of an attack. Moreover, in most attack tree models with multiple
parameters values are propagating from the leaves to the root based on local decision
strategies, i.e., in each step of the evaluation optimisation is made with respect</p>
      <sec id="sec-2-1">
        <title>Charlie</title>
        <p>card
pin,
96
Alice
pwd,
313
card
pin,
42
pin,
96
owner,
Charlie
pin,
42
owner,
Alice
processes
network
world
actors</p>
      </sec>
      <sec id="sec-2-2">
        <title>Computer C</title>
        <p>C: out(“transfer”, number, pwd, amount)
account C: out(“deposit”, number, amount)
number, pwd,313 cash,
34567 100
WS: out</p>
      </sec>
      <sec id="sec-2-3">
        <title>Bank</title>
        <p>ATM A1
safe card[(pin,X)],(pin,X) : in
cash,
1000</p>
      </sec>
      <sec id="sec-2-4">
        <title>Workstation WS</title>
        <p>harddrive pwd,
313</p>
      </sec>
      <sec id="sec-2-5">
        <title>City</title>
      </sec>
      <sec id="sec-2-6">
        <title>Door</title>
        <p>Alice: out</p>
      </sec>
      <sec id="sec-2-7">
        <title>Home</title>
        <p>trustedby(Alice): move
Pc
Paccount</p>
        <p>Pws
to one parameter. In case of incomparable values, however, this approach may
yield sup-optimal results.</p>
        <p>
          In order to overcome this limitation and evaluate complex attack scenarios,
we present evaluation techniques that consider attack trees where basic actions
are assigned with more than one parameter, such as, likelihood of success and
cost. Our evaluation techniques try to optimise all parameters at once.
However, optimisation of multiple parameters might lead to incomparable values,
e.g., maximising likelihood while minimising cost. Even worse, a best solution
does not always exist. We handle this issue by computing the set of optimal
solutions [
          <xref ref-type="bibr" rid="ref5">5</xref>
          ], defined in terms of Pareto efficiency. A solution is called Pareto
efficient if it is not dominated by any other solution [
          <xref ref-type="bibr" rid="ref6">6</xref>
          ].
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Evaluation</title>
      <p>We illustrate the evaluation techniques on the attack scenario where an attacker
wants to steal money from the card-holder by forcing him/her to pay fake
services. Our evaluation techniques answer the questions, such as “Can an attacker
successfully steal money from the card-holder?” or “What is the maximum
likelihood of success of an attack?”. Moreover, we associate with each basic action a
cost of an attack, and detected the attacks with maximum likelihood and
minimum cost. We compute the set of all Pareto optimal solutions, displayed in
Figure 3, where each point shows a likelihood of success with the corresponding
cost.</p>
      <p>(!!"
'!!"
&amp;!!"
%
$#"%!!"
!
$!!"
#!!"
!"!)!!" !)!'" !)#!" !)#'" !)$!" !)$'" !)%!" !)%'" !)&amp;!"</p>
      <p>&amp;'"()(*+*$,%</p>
      <p>As future work, we plan to introduce countermeasures to the model. Besides
the identification of possible socio-technical threats, we would like to determine
the corresponding defender actions and evaluate attack and defence scenarios.
Acknowledgment: Part of the research leading to these results has received
funding from the European Union Seventh Framework Programme
(FP7/20072013) under grant agreement no. 318003 (TRESPASS). This publication reflects
only the authors’ views and the Union is not liable for any use that may be made
of the information contained herein.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Probst</surname>
            ,
            <given-names>C.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hansen</surname>
            ,
            <given-names>R.R.:</given-names>
          </string-name>
          <article-title>An extensible analysable system model</article-title>
          .
          <source>Information Security Technical Report 13(4) (November</source>
          <year>2008</year>
          )
          <fpage>235</fpage>
          -
          <lpage>246</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Dimkov</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pieters</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hartel</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Portunes: representing attack scenarios spanning through the physical, digital and social domain</article-title>
          .
          <source>In: Proceedings of the 2010 joint conference on Automated reasoning for security protocol analysis and issues in the theory of security</source>
          , Springer (
          <year>2010</year>
          )
          <fpage>112</fpage>
          -
          <lpage>129</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Boender</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ivanova</surname>
            ,
            <given-names>M.G.</given-names>
          </string-name>
          , Kammu¨ller,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Primiero</surname>
          </string-name>
          , G.:
          <article-title>Modeling human behaviour with higher order logic: Insider threats</article-title>
          .
          <source>In: STAST'14</source>
          ,
          <string-name>
            <surname>IEEE</surname>
          </string-name>
          (
          <year>2014</year>
          <article-title>) colocated with CSF'14 in the Vienna Summer of Logic.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Schneier</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Attack Trees: Modeling Security Threats</article-title>
          .
          <source>Dr. Dobb's Journal of Software Tools</source>
          <volume>24</volume>
          (
          <issue>12</issue>
          ) (
          <year>1999</year>
          )
          <fpage>21</fpage>
          -
          <lpage>29</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Aslanyan</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nielson</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>Pareto efficient solutions of attack-defence trees</article-title>
          .
          <source>In: Principles of Security and Trust - 4th International Conference</source>
          , POST. (
          <year>2015</year>
          )
          <fpage>95</fpage>
          -
          <lpage>114</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Legriel</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Guernic</surname>
            ,
            <given-names>C.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Cotton</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maler</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          :
          <article-title>Approximating the pareto front of multi-criteria optimization problems</article-title>
          . In: TACAS. (
          <year>2010</year>
          )
          <fpage>69</fpage>
          -
          <lpage>83</lpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>