<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Towards Security Requirements: Iconicity as a Feature of an Informal Modeling Language</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexandr Vasenev</string-name>
          <email>a.vasenev@utwente.nl</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dan Ionita</string-name>
          <email>d.ionita@utwente.nl</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tommaso Zoppi</string-name>
          <email>tommaso.zoppi@unifi.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrea Ceccarelli</string-name>
          <email>andrea.ceccarelli@unifi.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Roel Wieringa</string-name>
          <email>r.j.wieringa@utwente.nl</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Resilient Computing Lab, University of Florence</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Services, Cybersecurity and Safety Group, University of Twente</institution>
        </aff>
      </contrib-group>
      <abstract>
        <p>Self-adaptive systems need to be designed with respect to threats within their operating conditions. Identifying such threats during the design phase can bene t from the involvement of stakeholders. Using a system model, the stakeholders, who may neither be IT experts nor security experts, can identify threats as a rst step towards formulating security requirements. To support it, the modeling language might possess adequate features to support this task. This paper investigates how iconic signs as a feature of an informal modeling language can contribute to eliciting security requirements by non-experts. Taking urban grid as a case, we relate bene ts and speci cs of using iconic signs to the two modeling challenges: i) reducing the cognitive complexity required to understand and model a system by non-experts, and ii) facilitating the threat identi cation activity using a system model. Outputs of three experiments suggest that iconic signs do assists in addressing the challenges.</p>
      </abstract>
      <kwd-group>
        <kwd>Requirements elicitation and analysis</kwd>
        <kwd>Cyber-physical networks</kwd>
        <kwd>Security requirements</kwd>
        <kwd>Electrical network</kwd>
        <kwd>Smart Grid</kwd>
        <kwd>Experiments</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Modern cyber-physical systems, such as smart grids, should account for the
context in which they operate to ensure the continuous service delivery. In principle,
designing complex systems demands that multiple stakeholders are directly
involved [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. This might include identifying threats to the system as a part of
the security engineering process. On a larger scale, security engineering includes
threat modeling, security requirements, and development of security mechanisms
[
        <xref ref-type="bibr" rid="ref20">20</xref>
        ].
      </p>
      <p>
        Identifying possible misuse cases of a system { as a step toward threat
modeling and then formulating security requirements { leads to earlier focus on
Copyright 2017 for this paper by its authors. Copying permitted for private and
academic purposes.
security. In case of self-adapting systems, a list of identi ed threats can also be
later used to consider later how the system should react to speci c threats. For
instance, adaptation patterns (see, e.g., [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]) can be devised in connection to a
particular threat or a threat group. Constructing a list of threats that a
selfaware system should account for is challenging, especially if stakeholders with
little modeling and security background are involved.
      </p>
      <p>
        This paper follows the paradigm that requirements engineering starts with
problem identi cation and needs input from stakeholders. The involvement of
stakeholders' encourages their creativity and invites them into discussion even
if they lack signi cant technical expertise [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Still, the task of eliciting
requirements from stakeholders can be complicated due to their di erent backgrounds
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        System models can aid in the communication between stakeholders and
system architectures. It can hardly be expected that stakeholders, who are
concerned with proper functioning of complex adaptive systems, possess signi cant
expertise in modeling (e.g., DFD) or using security-related approaches (e.g.,
UMLsec). Importantly, modeling notations "should be palatable to the users"
[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. This challenge is closely related to usability of requirements engineering
(RE) approaches in general. Although this topic didn't receive signi cant
attention yet, RE community is increasingly concerned about making approaches
"usable not only for requirements engineers, but also to stakeholders, with their
diverse backgrounds and needs" [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Thus, it is desirable to study (and provide
empirically-based suggestions) what aspects can impact understanding and e
ectiveness of non-specialists involved in modeling security requirements, including
its threat identi cation as the rst step.
      </p>
      <p>
        Even though a number of researchers concentrated on visual notations (see,
e.g., a seminal work [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] on the topic), several questions on their role in
requirements engineering of complex systems are still open. Speci cally, the question is
still open whether an icon-based representation can indeed assist threat identi
cation by stakeholders and in uence perception of stakeholders about this task.
Moreover, to our best knowledge, little empirical studies are published on this
topic. This paper makes initial steps towards answering this questions. While it
doesn't claim statistically signi cant results, it provides initial support for the
argument that using iconic informal languages can assist in eliciting security
requirements. For this, we draw on advances in conceptual modeling [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], a
well-developed topic in the information systems domain, which often deals with
large-scale systems.
      </p>
      <p>
        We study how iconicity [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] can contribute to modeling and threat identi
cation by non-experts. Iconicity is seen as a relation of resemblance or similarity
between the two main aspects of a sign: its form and its meaning. Herewith, we
consider iconicity to be related to two modeling challenges (MC):
{ MC1. To support the reduction of the cognitive complexity required to
understand and model a system;
{ MC2. To facilitate the threat identi cation activity using a system model.
      </p>
      <p>For the purpose of this research, we take an urban electricity grid as an
example of an adaptive cyber-physical system. The grid model represents city-level
grid components (e.g., a power substation, hospital) and connections between
them. Such a model is similar to a UML deployment diagram, and consists of: i)
nodes as modelling elements that represent the system components and ii) links
among the nodes.</p>
      <p>After reviewing relevant background in the next section, the paper introduces
the methodology used, presents results of three experiments, discusses them, and
concludes with future work.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Background and Motivation</title>
      <p>Often, di erent stakeholders should collaborate to ensure that a system will
deliver desired services. This is particularly relevant for Critical Infrastructures
(CIs). Typically, CIs operate in complex social, economic, and technical
contexts that imply collaborations between a number of stakeholders. The focus of
risk management in CI concerns threats to safety and security. For comparison,
risk management in the insurance, engineering, and nance domains aims at
protecting against nancial losses. All these aspects justify considering an urban
electricity grid, which is a speci c CI, as a particular relevant case for studying
the security requirements elicitation process.</p>
      <p>Being complex systems, urban electricity grids need to re-act to changes in
their environment. In normal operation mode a number of elements are highly
interconnected. At the same time, grid should be ready to adapt to for rapid
changes in real-time. For instance, a part of the grid (including both power and
ICT systems) might be able to became an autonomously operating island (or
a microgrid) to prevent cascading failures. Proper identifying and modeling of
threats is critical to devise adequate security mechanisms.</p>
      <p>
        Numerous grid stakeholders possess speci c (tacit) knowledge relevant to
ensuring proper functioning of the grid. City managers might have signi cant
expertise in daily administrative operations. They might ensure how renewables
are related to renewable energy-related landscape features and to the reduction
of greenhouse gas emission [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. Grid operators are responsible for day-to-day
functioning of the infrastructure and should consider how the interplay between
the urban form and solar energy inputs should be taken into account [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
Specialized agencies might have expertise in contingency planning and risk assessment.
Still, each individual stakeholder might lack an overall picture of city
development strategies, contexts, and speci cs of threat landscape. This calls for the
need for them to work together.
      </p>
      <p>Several solutions exist to assist stakeholders in identifying risks and threats
to the grid, as shown in the next subsection. However, it is unclear how
representations of a modeling language can assist in modeling a system (MC1 ) and
identifying threats to it (MC2 ).
2.1</p>
      <sec id="sec-2-1">
        <title>Risk Assessment Approaches</title>
        <p>
          The need for adequate risk management when considering CI is highlighted
by government agencies [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ]. Speci cally, identifying threats to the grid is an
important step towards supporting de nition of adequate responses [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. This
step should account for the involvement of non-experts.
        </p>
        <p>
          Often, CI-focused risk assessment methodologies are built around three core
tasks that start with threat identi cation: i) identi cation and classi cation of
threats, ii) identi cation of vulnerabilities and iii) evaluation of impact. For
instance, Risk Assessment (RA) for CIs, according to U.S. Department for
Homeland Security, should always start with obtaining a clear and agreed view of the
infrastructure from all public and private partners. This shared view is used
to assess the relevant risks, in terms of threats, vulnerabilities, and impacts[
          <xref ref-type="bibr" rid="ref13">13</xref>
          ].
Thus, supporting solutions to construct system models and identify threats is of
signi cant importance.
        </p>
        <p>
          Several tools were developed to support critical infrastructure analysis.
Primarily, they address the policy maker point of view. An example is the CARVER
tool (Criticality Accessibility Recoverability Vulnerability Espyability
Redundancy) [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]. Similarly, the tool called Critical Infrastructure Modelling
Simulation (CIMS) aims at model-based CI disruption simulation. This provides policy
makers with decision-support when faced with threats and natural disasters [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ].
One more example is a tool [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ] oriented to involve non-technical users.
Altogether, the focus of these tools rely emphasizes the role of involving non-technical
experts to consider threats to the system.
2.2
        </p>
      </sec>
      <sec id="sec-2-2">
        <title>Iconic and Non-Iconic Signs</title>
        <p>It is desirable that (informal) modeling languages can contribute to reducing
the cognitive complexity of a modeling task (MC1 ) and identifying threats to
a system (MC2 ). Together, the two challenges concern investigating utility and
usability of di erent representation of a grid modeling language for the threat
identi cation task.</p>
        <p>
          Cognitive theories support the argument that a less suitable format of the
model representation (the signs used) can hamper understanding of non-experts.
These theories particularity stress the importance of having an intuitive and
understandable representation of concepts. Cognitive t theory, for instance,
suggests that the cognitive load is reduced when a representation matches the
problem [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]. Earlier, it was found that visually recognizable representations
speed up creation and improve understandability of multi-layered models,
especially when domain experts (who are not modelling specialists) are involved
[
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]. Yet, it was not studied whether representation of a modeling language can
contribute to the threat identi cation task. This task is linked to the modeling
exercise, as well concerns security requirements at large.
        </p>
        <p>This paper describes a study on the basic di erentiation between using iconic
and symbolic signs. Iconic signs visually resemble the concepts that they
represent, whereas symbolic signs are arbitrary and the relationship with the concept
they represent is purely conventional. We investigate the e ect of utilizing either
symbolic or iconic signs for the modelling and threat identi cation tasks given
the same list of modelling constructs. Noticeably, we go beyond a simple
consideration that iconic signs are bene cial for understanding concepts, as we study
the role of signs within a modelling language to identify threats to a system.
The experiment design, devised for this paper, accounts for these challenges, as
shown next.
3</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Methodology</title>
      <p>To study how iconicity in uences modeling and threat identi cation, we
designed and conducted three experiments. These experiments are interrelated as
shown in Fig. 1. The combination of three experiments covered di erent
combinations of possible usage of the iconic modeling language. The focus of the
second and the third experiments concerned modeling a system and identifying
threats to a system accordingly. Together, the system of experiments dealt with
both modeling and threat identi cation steps. With respect to evaluation
criteria, we studied perception of users and compared amounts of threats identi ed
by di erent groups.</p>
      <p>The participants were provided with either iconic or textual grid elements
for experiments 1 and 2. Constructed grid models (either iconic or textual ones)
together with a generic threat list formed the input to experiment 3. The
conguration of experiments formed a structure that assessed the utility of iconic
models, in uence of iconicity to model the grid, and its role in identifying threats.
As real experts were unavailable, we used a sample of BSc, MSc and PhD
students. Experiments 1 and 2 were conducted at University of Twente (UT) during
the CuriousU summer school. Later, Experiment 3 took place at University of
Florence (UNIFI). This section describes the set-up in detail.</p>
      <p>The experiments tackled challenges MC1 and MC2 as shown in Table 1.
Also, the table describes sample populations, modeling tartgets, and treatments
of the three experiments.</p>
      <p>The intended target of generalization of the three experiments are city-level
stakeholders with no speci c experience on modeling and threat identi cation.
While students are not representative city planners (and we acknowledge that it
somewhat weakens evaluation e orts), the outcomes of the experiments are
produced by general cognitive mechanisms (such as cognitive t) which are shared
by both groups. Furthermore, both students and city planners are unlikely to
possess knowledge or experience with regard to critical infrastructure modelling
tools or threat identi cation techniques. We did not control for pre-existing
knowledge of the students, but to enhance external validity, participants were
rstly introduced to typical infrastructure components of grids simulating the
basic knowledge that city planners might have.</p>
      <p>Participants, supplied with speci c materials, joined one of the three
experiments. Each experiment consisted of a task performed by two groups. Members
of each group worked collectively on their task. After the completion of task,
the participants lled-out their questionnaires individually. While one can
debate whether the individual questionnaire responses are fully independent, each
task implied the idea of collaborative work. In this connection, we were
interested if a speci c representation (possibly, by supporting interactions) in uenced
perceptions of individuals after they completed a collaborative task.</p>
      <p>Due to self-forming, the group sizes were not equal. Still, the amount of
people in each of the groups (within a single experiment) did not deviate largely
(see Table 1). The di erence can potentially be seen as a threat. However, as
the experiments involved participants of a summer school and visiting students,
they (to our best knowledge) did not have signi cant previous experience of
working with each other. Thus, we did not limit the way how the groups were
formed. While we didn't collect group pro les, participants within each
experiment shared a similar level of education. In each of the three experiments, the
treatments were randomly allocated to the groups involved.</p>
      <p>Experiment 1 focused on whether modeling a grid (MC1 ) and identifying
threats (MC2 ) can be performed within a comparable time interval by using
iconic or symbolic modeling constructs. For this, the groups were tasked to
construct a model how they imagine the campus grid of the UT in 5{10 years.
Potential threats to the validity of this experiment that we could not control are
pre-existing security or safety knowledge and experimenter expectancy (as the
exercise was supervised). However, we attempted to ensure treatment and
measurement validity by running the two sessions in parallel provided each group
with the same tools (MS Visio) and instructions (handouts). Two supervisors
involved in the experiment were allowed only to answer questions strictly related
to the threat lists.</p>
      <p>
        Experiment 2 concerned only with the modeling task and did not cover the
threat identi cation step. It investigated whether iconicity of the modeling
language would in uence modeling changes in the system and understandability
(MC1 ). After performing the task, the participants lled in a questionnaire
formed by 4 questions to document their perception of di culty and success
of the modeling task. Questionnaire design asked for a score from 1 to 5 to each
question following a psychometric semantic di erential scale to reduce
acquiescence bias [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. The questions were as follows:
{ E2Q1. "How would you describe the di culty of the task you just completed?
      </p>
      <p>Rate from 1 (Very easy) to 5 (Very Di cult);
{ E2Q2. "How satis ed are you with the tools provided to complete the task?</p>
      <p>Rate from 1 (Not Satis ed) to 5 (Very Satis ed);
{ E2Q3. "How would you rate the amount of time it took to complete the
task? Rate from 1 (Very little time) to 5 (Too long);
{ E2Q4. "How much do you agree with the nal version of the model? Rate
from 1 (Don't agree) to 5 (Fully agree).</p>
      <p>This second experiment was conducted under stricter conditions: supervisors
were not allowed to assist the modelers. Participants answered printed
questionnaires immediately after the task. However, group dynamics could have
in uenced the measurement validity. For instance, one can assume that some
participants might have reported lower agreement or perceived the task as more
di cult due to intra-group personality or skill mismatches. The experiments did
not investigated either of these aspects. Nevertheless, as the groups were formed
from a pool of participants with similar education experiences, we expect that
in uences of these aspects were limited. Another threat to validity to the second
(as well as to the rst) experiment is that both groups worked in a single,
although very large room. To counter it two supervisors tried to limit cross-group
interaction.</p>
      <p>
        Experiment 3 explicitly dealt with identifying threats to a grid. It
concentrated on how participants relate an iconic or symbolic grid model to a generic
threat list. It was designed to understand how the iconicity feature of a model
in uences the ability of non-experts to perform an e ective { complete, precise,
and accurate { threat identi cation task (MC2 ). After de ning two groups of 3
students at UNIFI, we asked the participants to identify all the possible threat
occurrences of a given modeled scenario considering a reference threat list [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
We supplied all participants with the same scenario, described either in iconic
or symbolic signs. The independent variable (iconicity of constructs), thus, was
thus similar as in Experiment 1 and Experiment 2. See Table 1 for details.
      </p>
      <p>The obtained threat lists were compared with a list provided by an expert
from UNIFI to assess the completeness of students' lists. Also, the participants
lled in the following questionnaire:
{ E3Q1. "How would you describe the di culty of building the list of threats?</p>
      <p>Rate from 1 (Very easy) to 5 (Very Di cult);
{ E3Q2. "Was the graphical/symbolic description enough to complete the
task? Rate from: 1 (Unnecessary) to 5 (Very Useful);
{ E3Q3. "Did you feel that additional software supports were needed? Rate
from: 1 (No) to 5 (Yes, I was lost);
{ E3Q4. "How would you rate the amount of time it took to complete the
task? Rate from: 1 (Very little time) to 5 (Too long);
{ E3Q5. "Do you feel that the list you provided is complete? Rate from 1 (Very
poor list) to 5 (Very complete list).</p>
      <p>Afterwards, we asked the students to anticipate how the threat identi cation
exercise would be if they would have the model described in another way (iconic
for Group 2 and symbolic for Group 1 ). By doing so, we aimed to collect
perceived bene ts of using alternative description of a scenario. The threat identi
cation exercise was not repeated. To di erentiate between the two questionnaires
lled out, the rest of the paper refers to the "perceived bene ts" questionnaire
as Experiment 3b, while the initial survey is referred to as Experiment 3a.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Experiments and Findings</title>
      <p>Input to the rst and the second experiments included lists of i) generic threats to
grid components and ii) either an iconic or a symbolic list of grid components to
build an urban grid. The latter input was organized as a template in a MS Visio
le. In the third experiment, the students were supplied with a list of generic
threats and with either an iconic or symbolic model. The provided model was
similar in complexity to those obtained during the rst two exercises.</p>
      <p>
        Iconic modeling constructs are described in [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] and form pairs (icon-name).
Some icons are included in Fig. 2. In the symbolic template, the modeling
constructs were presented only by their names (e.g., 'power substation', 'wind farm',
and 'hospital'), without icons.
4.1
      </p>
      <sec id="sec-4-1">
        <title>Experiment 1</title>
        <p>
          This experiment aimed to consider the utility of the provided language to model
the grid and identify threats to it. The main task was to create grid models
(see, e.g., Fig. 2). Also, we asked participants to identify threats relevant to
particular steps of the grid development (using a generic list of possible threats,
as described in [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ]) and relate evolution to threat sources (in terms of their
capability, intent, and targeting characteristics. This secondary task investigated
whether participants can meaningfully relate the grid structure they constructed
with the idea of threat modeling. By doing so, we intended to position the task of
threat identi cation in the context of security engineering. Altogether, we aimed
at investigating whether constructing a grid model and identifying threats to it
can be feasible for both iconic and symbolic groups.
        </p>
        <p>Main Findings. An interesting nding of this experiment was that the
iconic group decided to proceed with modeling the grid in MS Visio directly,
while another group started to draft their plans on a whiteboard and paper
sheets. We did not anticipate that groups would utilize alternative media when
confronted with non-iconic notations. An explanation could be that in this case a
lack of iconicity eliminated perceived bene ts of using a software-modelling tool,
while the exibility a orded by free-hand drawing led to the use of whiteboard.
This potentially points out that the notation of a modelling language can directly
impact the modelling process. Both groups were capable to construct grid models
and identify a comparable number of relevant threats, despite their previous lack
of experience with this task. It suggests that the both representations, as well
as the language, can be used for relating components to threat sources.
4.2</p>
      </sec>
      <sec id="sec-4-2">
        <title>Experiment 2</title>
        <p>This experiment concentrated on obtaining initial quantitative data whether
modeling using software tools with iconic signs is perceived by non-experts as
more understandable compared to modeling with non-iconic signs. Similar to
Experiment 1, two groups of ten students each were asked to construct models
of a smart future university campus. Afterwards, we collected four questionnaires
from the group that used iconic signs (Group 1 ) and seven questionnaires from
the other group (Group 2 ).</p>
        <p>Main Findings. Table 2 describes the collected data. The members of Group
2 found the task more di cult (by 64%) and were less satis ed with the tool to
model the infrastructure (24%). The E2Q1 answers from the two groups di er
signi cantly and their con dence intervals do not overlap. It highlights di culties
that the students from Group 2 encountered during modeling the future grid.
The replies to E2Q3 and E2Q4 are less illustrative: while being comparable, they
deviate largely.</p>
        <p>The outcome of this experiment suggests that software-based modelling with
iconic signs is perceived as less di cult than when using symbolic signs.
4.3</p>
      </sec>
      <sec id="sec-4-3">
        <title>Experiment 3</title>
        <p>
          The last experiment focused on investigating how an iconic/non-iconic model
in uences the outcomes of the threat identi cation task. Two groups each of 3
students participated in the experiment: Group 1 worked with an iconic
description of the grid of the scienti c complex of UNIFI, while Group 2 worked with
a non-iconic (symbolic) version. Provided with a list of generic threats (a subset
of threats 7, 10, 17, 18, 19, 21, 24, 29, 31, 37 of the threat list in Appendix B
of [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ]), all students built a threat list to the system model. In Table 4 'A' and
'B' letters in the questions distinguish between questionnaires for Experiment 3a
and 3b.
        </p>
        <p>Main Findings. Table 3 shows that the amount of valid identi ed threats
is signi cantly higher for participants who were supplied with the iconic model.
Group 1 members identi ed 17, 10, and 19 threats. Members from Group 2
identi ed 8, 8, and 9 valid threats.</p>
        <p>The expert evaluated most of the threats identi ed by the students as being
valid. Some threats, e.g., "conduct physical attacks on organizational facilities",
were commonly identi ed. Some others threats were identi ed less often ((for
instance, only two out of six students identi ed "conduct attacks using
unauthorised ports, protocols and services"). An explanation can be that some threats
are di cult to understand (and identify), because they require speci c technical
knowledge.</p>
        <p>The Iconic group reported less di culty (E3AQ1) and more satisfaction of
the results (E3AQ5). Also, they were indicated (E3AQ3) that additional software
support is needed less, if compared to the symbolic group. Interestingly, the
participants didn't anticipate that employing another representation format can
result in a more complete list of threats. E3AQ5 and E3BQ5 answers of Group
1 both score 3.0. More speci cally, there is only a relatively small increase (0.3)
in the di erence between E3BQ5 and E3AQ5 for Group 2.</p>
        <p>In summary, all subjects in possession of the iconic model constructed more
complete lists of plausible threats compared to their counterparts. It suggests
that the threat identi cation task can bene t from employing an iconic model
of a system.
5</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Discussion</title>
      <p>5.1</p>
      <sec id="sec-5-1">
        <title>Modeling Challenges</title>
      </sec>
      <sec id="sec-5-2">
        <title>MC1: Reduction of cognitive complexity. While Experiment 1 showed that</title>
        <p>both notations can be potentially used to identify threats to a system, E2Q1 from
Experiment 2 and to a smaller extent E2Q3 showed that the perceived di culty
of the modeling task slightly decrease when iconic signs are used. Notably, the
Iconic group was less satis ed with the tools provided (E2Q2). Nevertheless,
based on the outcome of the experiments we can argue that the use of iconic
signs instead of symbolic ones lowered the cognitive complexity of the task.</p>
      </sec>
      <sec id="sec-5-3">
        <title>MC2: Facilitating threat identi cation. In general, non-expert users can</title>
        <p>identify threats to a system regardless of the model's representation (Experiment
1 ). However, if supplied with a readily made iconic models | in contrast to a
symbolic one { they performed better (Experiment 3 ) and considered that such
the iconic description was completely enough to perform the task.
5.2</p>
      </sec>
      <sec id="sec-5-4">
        <title>Practical Implications</title>
        <p>
          As noted in [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ], enumerating threats helps system architects to develop
realistic and meaningful security requirements. Thus, this paper contributes to the
process of working on security requirements at large.
        </p>
        <p>Speci cally, this research provides initial empirical support for claims
related to devising and employing means for eliciting security requirements. Our
ndings hint at high-level suggestions how to approach eliciting security
requirements from stakeholders who are less experienced in modeling. In particular: i)
using icons for modeling compared to pure text representation of modeling
constructs facilitates comprehension of non-experts; ii) iconic models can assist in
identifying potential threats by non-experts. We envision that an informal iconic
model of a system, such as the one shown in Fig. 2, can facilitate collaboration
between stakeholders.
5.3</p>
      </sec>
      <sec id="sec-5-5">
        <title>Limitations</title>
        <p>
          Notes on experiments. Some aspects related to the con guration of
experiments should be noted. First, it can be possible that outcomes of the
experiments were obtained by pure chance. However, it is the consistency of outcomes
of several experiments that points out that using icon-based informal
modeling language can be useful to identify threats to a complex system. Second,
the experiments were conducted with a low number of participants.
Nevertheless, the con guration of experiments was not intended to make statistic-based
claims. The potential for generalizations is related to ideas within cognitive
theories. More experiments with larger amounts of groups will clearly be bene cial.
Third, the experiments were focused on assets-threats connections. We did not
account for compliance obligations, raw requirements, security requirements, as
well as security measures at large. All these aspects (see, e.g., [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ] for a structure
of interrelations) are important for security requirements engineering.
Investigating the e ect of iconicity in connection to other security requirement engineering
processes might be a direction for future research. Fourth, the impact of iconicity
may be di erent if the users only identify threats or model and identify threats as
two consequent steps. This aspect, as well as the question how qualitative results
can be related to quantitative ones in case of threat identi cation, deserves
further studies. Firth, we didn't aim to cover speci c expertise of stakeholders. Still,
we can expect that stakeholders involved in modeling could have participated
in a BSc, MSc, or PhD program. While stakeholders' educational background
may be di erent from the students, critical thinking, analytic, and other skills
obtained through their education might be similar. Finally, it is possible that
real-world applications might require several modeling sessions, where users over
time will become more familiar with construct and their representations. Still, if
iterations are rare, stakeholders might need to (re-)familiarize themselves with
those elements, similarly to the rst time exercise. The outcomes of this research
can still be useful in such cases.
        </p>
        <p>Model Quality. In this study the semantics (i.e., correctness and
completeness) of the models was not investigated in detail. Also, although an RA expert
examined the threats identi ed by students within Experiment 3, we cannot
make any claims with regard to the e ects of iconicity on the absolute quality
of the results. Besides, the "quality" of the identi ed threats was not part of the
evaluation. It is the next steps of the security development process that should
account for such a merit. Besides, we did not study how iconicity can explicate
tacit knowledge (as experts are needed for this task) and creativity (students
were provided with a list of possible threats). Still, we can anticipate that iconic
models, due the reduction of cognitive load, can also contribute to these aspects.</p>
        <p>
          Adherence to syntax. We observed that groups with symbolic signs started
to freely draw schemes on the whiteboard, thereby reducing possibilities to
enforce syntax of the modelling language. In connection to the cognitive t theory
[
          <xref ref-type="bibr" rid="ref18">18</xref>
          ], we can explain that another way used to represent information suited the
task (and the audiences) better. However, bene ts and limitations of using a
speci c media were not investigated. Possibly, dual encoding (illustrating the
text corresponding to the components next to their graphical representation)
can support e ciently employing di erent media for modeling.
        </p>
        <p>
          Choice of signs. Symbolic signs were kept as simple as possible, by using
only boxes, arrows and colors. However, the complexity and suitability of iconic
signs were not evaluated. It is possible that these icons can be simpli ed, employ
more discriminable symbols, and possess more semantic transparency. Also, this
research didn't concern the modeling constructs themselves, as well as portability
of the modeling approach to a large-scale scenario. Huge CPS with lots of detail
might call for nding a particular level of abstraction. We acknowledge that the
set-up of this research accounts for only a fragment of the real world's complexity.
It does not investigate how having a very large number of iconic representations
can negatively impact human comprehension because of, for instance, similarity
across potentially similar elements. We can expect that in such cases modeling
languages might bene t from grouping elements. Also, di erent notations aspects
[
          <xref ref-type="bibr" rid="ref6">6</xref>
          ] can be applied. This question, next to how the cost of icon design can in uence
modeling process, was not considered in this paper.
6
        </p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>Conclusions and Future Work</title>
      <p>Eliciting security requirements, as a collaborative process that starts with
identifying threats (in other words, misuse cases), should account for inputs from
diverse stakeholders. In this paper, we empirically investigated iconicity | a
feature of an informal modeling language. We concentrated on identifying threats
to an urban grid as a case of cyber-physical system.</p>
      <p>Our ndings indicate that individuals with little modelling experience do
bene t from employing an iconic representations of an informal language.
Participants of three experiments perceived iconic models as easier to construct and
more understandable. Moreover, participants equipped with the iconic model
were capable to point out more threats relevant to the system.</p>
      <p>From a requirements standpoint, the ndings suggest that iconic
representations of informal modeling languages constructs can bene t the threat
identi cation task. This task is an important step of security requirements. Those
concerned with developing and employing languages and tools for security
requirements can consider employing such notations. Ultimately, the ndings can
also assist specialists involved in communicating risk assessment and risk
management processes to stakeholders. Future work should attempt to replicate the
experiments at a large scale, ideally with practitioners.</p>
      <p>Acknowledgments This work has been partially supported by the Joint
Program Initiative (JPI) Urban Europe via the IRENE project and has received
funding from the European Union Seventh Framework Programme
(FP7/20072013) under grant agreement no 318003 (TREsPASS). We thank the students
who participated in the experiments. This publication re ects only the author's
views and the Union is not liable for any use that may be made of the information
contained herein.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Murer</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bonati</surname>
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Managed evolution: a strategy for very large information systems</article-title>
          . Springer Science &amp; Business
          <string-name>
            <surname>Media</surname>
          </string-name>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Sindre</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Opdahl</surname>
            ,
            <given-names>A. L.</given-names>
          </string-name>
          :
          <article-title>Eliciting security requirements with misuse cases</article-title>
          .
          <source>J. Requirements Engineering</source>
          ,
          <volume>10</volume>
          (
          <issue>1</issue>
          ),
          <volume>34</volume>
          {
          <fpage>44</fpage>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Houmb</surname>
            ,
            <given-names>S. H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Islam</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Knauss</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jrjens</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schneider</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec</article-title>
          .
          <source>J. Requirements Engineering</source>
          ,
          <volume>15</volume>
          (
          <issue>1</issue>
          ),
          <volume>63</volume>
          {
          <fpage>93</fpage>
          (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Hickey</surname>
            ,
            <given-names>A.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Davis</surname>
            ,
            <given-names>A.M..:</given-names>
          </string-name>
          <article-title>Elicitation technique selection: how do experts do it</article-title>
          ? In: 11th IEEE International Requirements Engineering conference (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Bombonatti</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gralha</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Moreira</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Araujo</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goulao</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Usability of requirements techniques: a systematic literature review</article-title>
          .
          <source>In: 31st Annual ACM Symposium on Applied Computing</source>
          , Pisa, Italy (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6. Moody, D.:
          <article-title>The "Physics" of Notations: Toward a Scienti c Basis for Constructing Visual Notations in Software Engineering</article-title>
          .
          <source>J. IEEE Trans. Softw. Eng</source>
          .
          <volume>35</volume>
          ,
          <issue>6</issue>
          , 756{
          <fpage>779</fpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Aissen</surname>
          </string-name>
          , J.:
          <article-title>Di erential object marking: Iconicity vs</article-title>
          .
          <source>economy. J. Natural Language &amp; Linguistic Theory 21.3</source>
          <volume>435</volume>
          {
          <issue>483</issue>
          (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Barjis</surname>
          </string-name>
          , J.:
          <article-title>Collaborative, participative and interactive enterprise modeling</article-title>
          .
          <source>In: Enterprise information systems</source>
          . Springer Berlin Heidelberg,
          <volume>651</volume>
          {
          <fpage>662</fpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Hernantes</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , et al.:
          <article-title>Collaborative modeling of awareness in Critical Infrastructure Protection</article-title>
          .
          <source>In: 44th IEEE Hawaii International Conference on System Sciences (HICSS)</source>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Ionita</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wieringa</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bullee</surname>
            ,
            <given-names>J.-W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vasenev</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Tangible modeling to elicit domain knowledge: an experiment and focus group</article-title>
          .
          <source>In: Conceptual Modeling</source>
          . Springer International Publishing,
          <volume>558</volume>
          {
          <fpage>565</fpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Zubelzu</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          , lvarez, R.,
          <string-name>
            <surname>Hernndez</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Methodology to calculate the carbon footprint of household land use in the urban planning stage</article-title>
          .
          <source>J. Land Use Policy</source>
          <volume>48</volume>
          ,
          <issue>223</issue>
          {
          <fpage>235</fpage>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Amado</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Poggi</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>Solar Urban Planning: a parametric approach</article-title>
          .
          <source>J. Energy Procedia</source>
          <volume>48</volume>
          ,
          <issue>1539</issue>
          {
          <fpage>1548</fpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13. U.S. Department of Homeland Security.: NIPP Supplemental Tool:
          <article-title>Executing a Critical Infrastructure Risk Management Approach (</article-title>
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14. Federal Emergency Management Agency.
          <article-title>: A Whole Community Approach to Emergency Management: Principles, Themes, and Pathways for Action (</article-title>
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Bennett</surname>
            ,
            <given-names>B.T.</given-names>
          </string-name>
          :
          <article-title>Understanding, assessing, and responding to terrorism: Protecting critical infrastructure and personnel</article-title>
          . John Wiley &amp; Sons (
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Pederson</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          , Dudenhoe er, D.,
          <string-name>
            <surname>Hartley</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Permann</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <string-name>
            <given-names>Critical</given-names>
            <surname>Infrastructure</surname>
          </string-name>
          . Idaho National Laboratory (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Giannopoulos</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Filippini</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schimmer</surname>
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Risk assessment methodologies for critical infrastructure protection, part I: A state of the art</article-title>
          .
          <source>In: JRC Technical Notes</source>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Vessey</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Galletta</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Cognitive t: an empirical study of information acquisition</article-title>
          .
          <source>J. Inf. Syst. Res</source>
          .
          <volume>2</volume>
          (
          <issue>1</issue>
          )
          <fpage>63</fpage>
          -
          <lpage>84</lpage>
          (
          <year>1991</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          19.
          <string-name>
            <surname>Oddgeir</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Martinussen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rosenvinge</surname>
            ,
            <given-names>J.H.</given-names>
          </string-name>
          :
          <article-title>Likert-based vs. semantic differential-based scorings of positive psychological constructs: A psychometric comparison of two versions of a scale measuring resilience</article-title>
          .
          <source>J. Personality and Individual Di erences 40.5</source>
          <volume>873</volume>
          {
          <issue>884</issue>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          20.
          <string-name>
            <surname>Myagmar</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Adam</surname>
            <given-names>J.L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>William</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Threat Modeling as a Basis for Security Requirements</article-title>
          .
          <source>In: Symposium on Requirements Engineering for Information Security (SREIS)</source>
          (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          21.
          <article-title>Improving the robustness of urban electricity networks (IRENE) project: Deliverable D2.1 Threats identi cation and ranking</article-title>
          , http://ireneproject.eu/ wp-content/uploads/2016/01/IRENE-D2.
          <article-title>1</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          22.
          <string-name>
            <surname>Schmitt</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Liggesmeyer</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>A Model for Structuring and Reusing Security Requirements Sources and Security Requirements</article-title>
          . In: REFSQ Workshops (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          23.
          <string-name>
            <surname>Menasce</surname>
            ,
            <given-names>D.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gomaa</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Malek</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sousa</surname>
            ,
            <given-names>J.P:</given-names>
          </string-name>
          <article-title>SASSY: A framework for selfarchitecting service-oriented systems</article-title>
          ,
          <source>IEEE Software</source>
          ,
          <volume>28</volume>
          (
          <issue>6</issue>
          )
          <fpage>78</fpage>
          {
          <fpage>85</fpage>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>