<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Resilience Assessment: Accidental and Malicious Threats</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>Mohamed Kaâniche CNRS; LAAS; Université de Toulouse - 7, Avenue du colonel Roche</institution>
          ,
          <addr-line>F-31077 Toulouse</addr-line>
          ,
          <country country="FR">France</country>
          <addr-line>Université de Toulouse; UPS; INSA; INP; LAAS; F-31077 Toulouse</addr-line>
          ,
          <country country="FR">France</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>A large body of research has been dedicated to the analysis, assessment and protection of cyberphysical systems and critical infrastructures against potential threats that might affect the dependability, the security or the resilience of the services delivered to the users. Traditionally, accidental and malicious threats have been taken into account separately. In this talk we will address the challenges raised by the resilience assessment and analysis of such systems considering accidental and malicious threats in an integrated way and we will present some examples of research studies carried out in this context.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        1. SUMMARY
In the past decade, several concerns have been
raised about the vulnerability of critical
infrastructures and cyber-physical systems and
their efficient protection in the presence of
accidental and malicious threats
        <xref ref-type="bibr" rid="ref1 ref5">(Rahman et al.
2009)</xref>
        .
      </p>
      <p>
        Historically, most of the efforts were dedicated to
the protection of critical infrastructures against
accidental faults and natural disasters with a
specific focus on safety. The situation changed
significantly after the September 11, 2001 tragic
events that led to increased international concerns
about the security and robustness of critical
infrastructures in response to evolving malicious
threats
The vulnerability of critical infrastructures has
increased as a result of the wider use of open
networks and information infrastructures, and the
proliferation of vulnerable operating systems and
control devices. Recent events targeting critical
infrastructures show that the threat is real. A widely
reported example is the Stuxnet sophisticated
malware discovered in July 2010 that targeted
specific industrial computer control equipment and
software, used for instance in nuclear power plants
in Iran [
        <xref ref-type="bibr" rid="ref4">(Langner 2011)</xref>
        .
      </p>
      <p>A large body of research has been dedicated to the
analysis, assessment and protection of
cyberphysical systems and critical infrastructures against
potential threats that might affect the dependability,
the security or the resilience of the services
delivered to the users. The resilience term is used
differently, by different communities. It is defined in
(Laprie 2011) as the persistence of service delivery
that can justifiably be trusted, when facing
changes.</p>
      <p>Traditionally, accidental and malicious threats have
been taken into account separately. In this talk we
will address the challenges raised by the resilience
assessment and analysis of such systems
considering accidental and malicious threats in an
integrated way and we will present some examples
of research studies carried out in this context.
In particular this objective has been addressed in
the context of the CRUTIAL project
(http://crutial.rse-web.it/) considering the example
of power grid critical infrastructures and the
associated information infrastructures dedicated to
their management and control.</p>
      <p>CRUTIAL focussed on the failures resulting from
interdependencies between these infrastructures.
The characterization of such failures and the
modelling of their impact on relevant properties of
power systems have been investigated by means
of models at different abstraction levels: i) from a
very abstract view expressing the essence of the
typical phenomena due to the presence of
interdependencies, ii) to an intermediate detail level
representing in a rather abstract way the structure
of the infrastructures, in some scenarios of interest,
iii) to a quite detailed level where the infrastructures
components and their interactions are investigated
at a finer grain, considering elementary events
occurring at the components level and analysing
their impact at the system level.</p>
      <p>
        Accordingly, the proposed resilience assessment
framework
        <xref ref-type="bibr" rid="ref1">(Kaâniche et al. 2009)</xref>
        is based on a
hierarchical modelling approach that
accommodates the composition of different types of
models and formalisms, including generalized
stochastic Petri nets, fault trees, Stochastic Well
formed Nets, and Stochastic Activity Networks.
Additionally, a new formalism called “Dependent
Automata” has been developed to provide a
rigorous definition of interdependencies related
failures. Also, unified models for describing
cascading and escalating failures considering
accidental and malicious threats in an integrated
way have been defined
        <xref ref-type="bibr" rid="ref2">(Laprie et al. 2007)</xref>
        Besides these models, the CRUTIAL project
resilience assessment activities included
architecture validation activities as well as testbed
based experiments to analyse the impact of
different attack scenarios on control applications.
We will outline some of the results obtained in the
context of this project and discuss some open
research problems.
Mohamed Kaâniche has been at LAAS-CNRS,
Toulouse, France, since 1988 where he currently
holds a position of “Directeur de Recherche”,
heading the Dependable Computing and Fault
Tolerance Group. From March 1997 to February
1998, he was a Visiting Research Assistant
Professor at the University of Illinois at
UrbanaChampaign, IL, USA.
      </p>
      <p>His research addresses the dependability and
security assessment of hardware and software fault
tolerant computer systems and critical
infrastructures, using analytical modelling and
experimental measurement techniques.</p>
      <p>He has been involved in several national and
European research projects and acted as a
consultant for companies in France and as an
expert for the European Commission. He has
served on program and organization committees of
international dependability related conferences. He
was Program Chair of PRDC-2004, EDCC-5,
DSNPDS 2010, LADC-2011 and SAFECOMP- 2013. He
is General co-Chair of DSN-2016 that will be held
in Toulouse, France in June 2016.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <surname>Kaâniche</surname>
          </string-name>
          , et al. (
          <year>2009</year>
          )
          <article-title>CRUTIAL Project Deliverable D16 - Final version of the modelling framework</article-title>
          . http://crutial.rseweb.it/Dissemination/DELIVERABLES-OF-THEPROJECT.asp
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Laprie</surname>
          </string-name>
          ,
          <string-name>
            <surname>Jean-Claude</surname>
          </string-name>
          , Kanoun, Karama, Mohamed Kaâniche, (
          <year>2007</year>
          )
          <article-title>Modelling interdependencies between Electricity and Information Infrastructures</article-title>
          .
          <source>The 26th International Conference on Computer Safety</source>
          , Reliability, and
          <string-name>
            <surname>Security</surname>
          </string-name>
          (SAFECOMP-
          <year>2007</year>
          ), Nuremberg, Germany, LNCS 4680, Springer, pp.
          <fpage>54</fpage>
          -
          <lpage>67</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <surname>Laprie</surname>
          </string-name>
          , Jean-Claude “From Dependability to Resilience”,
          <source>IEEE International Conference on Dependable Systems and Networks (DSN2008)</source>
          , Supplemental volume,
          <source>Anchorage</source>
          , Alaska, USA, pp.
          <fpage>G8</fpage>
          -
          <lpage>G9</lpage>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <surname>Langner</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          “
          <source>Stuxnet: Dissecting a Cyberwarfare Weapon,” IEEE Security &amp; Privacy</source>
          , vol.
          <volume>9</volume>
          , no.
          <issue>3</issue>
          ,
          <issue>2011</issue>
          , pp.
          <fpage>49</fpage>
          -
          <lpage>51</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <surname>Rahman</surname>
            ,
            <given-names>H.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Beznosov</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Marti</surname>
            ,
            <given-names>J.R.</given-names>
          </string-name>
          , “
          <article-title>Identification of sources of failures and their propagation in critical infrastructures from 12 years of public failure reports“</article-title>
          ,
          <source>Int. Journal on Critical Infrastructures</source>
          , vol.
          <volume>5</volume>
          , n°
          <issue>3</issue>
          ,
          <fpage>2009</fpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>