<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Systemic Risk analysis through SE methods and techniques</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Andrea Tundis</string-name>
          <email>tundis@tk.tu-darmstadt.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Max Mühlhäuser</string-name>
          <email>max@tk.tu-darmstadt.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Simona Citrigno</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sabrina Graziano</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Centro di Competenza ICT-SUD Piazza Vermicelli</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Rende</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Italy</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>simona.citrigno</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>sabrina.graziano}@cc-ict-sud.it</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Informatics</institution>
          ,
          <addr-line>Modeling, Electronics and Systems Engineering (DIMES)</addr-line>
          ,
          <institution>University of Calabria Via Ponte P.</institution>
          <addr-line>Bucci 41C, Rende (CS), 87036</addr-line>
          <country country="IT">Italy</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Telecooperation Lab, Department of Computer Science Technische Universität Darmstadt Darmstadt</institution>
          ,
          <country country="DE">Germany</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Teresa Gallo</institution>
          ,
          <addr-line>Alfredo Garro, Domenica Saccá</addr-line>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2017</year>
      </pub-date>
      <abstract>
        <p>-The Systemic Risk is the risk that derives from the interdependence of the system under consideration, object of the analysis, and the services provided by other systems and, in general, by the interactions among them. The combination of the GOReM methodology and the RAMSoS method is proposed for Systemic Risk Assessment so as to provide the following benefits: (i) Effective modeling of SoSs structure and behavior; (ii) Explicit representation of dysfunctional behavior; (iii) Evaluation of different risk scenarios through agent-based simulation; (iv) Quantitative and qualitative risk assessment also in combination with classical analysis techniques (such as Bayesian Networks).</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Copyright © held by the author</p>
      <p>Keywords—Cybersecurity, Modeling and
Requirement Engineering, Systemic Risk Analysis
Simulation,
I.</p>
      <p>IDEA AND PROPOSAL
 Identify the main phases of the Systemic Risk (SR)</p>
      <p>Proposed a Modelling and Simulation based approach
Defined a step by step methodology (not a software
tool)
Performing Static and Dynamic Systemic Risk Analysis
II.</p>
    </sec>
    <sec id="sec-2">
      <title>SYSTEMIC RISK ANALISYS PHASES The proposed process to support the analysis of the systemic risk can be organized in three macro-phases (see</title>
      <p>Figure 1): System Analysis, System Design and Simulation
Modeling and Results Assessment.</p>
      <p>System requirements and other aspects of interest are
identified and described. The involved entities (such as
stakeholders, services providers and so on) are identified along
with their roles and related objectives. Goals to be achieved
and their dependencies are highlighted. The rules and
regulations that govern the context under analysis are
identified.</p>
      <p>Fig. 1. Systemic Risk Analysis Phases</p>
      <sec id="sec-2-1">
        <title>B. System Design</title>
        <p>The target of the analysis as well as boundaries of the
design, i.e. what needs to be represented and what can or
should be neglected/omitted, are defined. Specific use cases are
redefined in terms of scenarios of interest. Application
scenarios are introduced to specify the functionalities that
should be provided in each business scenario description of the
system is delivered by providing from different points of view
such as for structural, functional, and so on.</p>
        <p>C. Simulation Modeling &amp; Results Evaluation</p>
        <p>At this point, a subset of the models generated in the
System Design macro-phase is selected and processed.
According to the simulation-platform different
Model-toModel transformation rules are defined. Great attention is
placed on the indices / objectives identified during the System
Analysis. From these indices and the objectives to be pursued,
the simulation platform, which is able to support the desired
analysis, is selected. Based on the objectives to be verified, it is
possible to choose the simulation environment that better fits
the type of analysis to be carried out.</p>
        <p>DERIVING BAYESIAN NETWORKS MODELS FOR</p>
        <p>SUPPORTING SYSTEMIC RISK ANALYSIS
A. A combined approach for modeling and assessing the
Systemic Risk</p>
        <p>How and which entities of the overall system influence the
operation of the entire system and the evaluation of the
Systemic Risk.</p>
        <p>Modeling and evaluating Systemic Risk by exploiting
(agent-based) simulation + Bayesian Network
B. RAMSoS and GOReM: Enabling Factors



</p>
        <p>Common modeling notation: SysML/UML.</p>
        <p>Both RAMSoS and GOReM are defined in terms of
phases and work-products
GOReM is defined as a method to support the analysis
of system requirements with particular emphasis on
their elicitation and tracking; while RAMSoS is meant
to be used mostly for supporting the validation and
verification phases. Together they cover the entire
Systemic Risk Analysis Phases</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Reuse of models. Figure 2 shows the integration approach based on WorkProducts</title>
      <p>RISK ANALYSIS APPLIED TO A SERVICE OF ELECTRONIC</p>
      <p>ONLINE PAYMENT OF POSTE ITALIANE</p>
      <p>The risk of success or failure of the PEO service relies on
two complementary services:
 SMS Notifications service (Mobile Service Provider)
 Payments and Transactions service (Web Service</p>
      <p>Provider, Energy Provider, IT infrastructure)
1. A statistics based approach using a tool for a static analysis
is applied: GeNIe (Graphical Network Interface) a
development environment for the creation of decision
models based on Bayesian Network (BN)
2. An agent-based approach using a dynamic tool is adopted:
ReActor an object oriented framework based on
discreteevents simulation</p>
      <p>For each actor the following risk ranges (or QoS) have been
identified:
 SMS Notification: Good, Low;
 Payments and Transactions: LowRisk, HighRisk;
 IT Internal Infrastructure: Good, Standard, Poor;


</p>
      <p>WebServiceProvider: High, Medium, Low;</p>
    </sec>
    <sec id="sec-4">
      <title>Energy Provider: High, Standard;</title>
      <p>MobileServiceProvider: HighLevelOfService,</p>
      <p>StandardLevelOfService;</p>
      <p>Once the model and relationships among actors and their
goals are well described and defined, it is possible to use
simulation to provide an assessment about what can happen
into an application scenario according to specific inputs to the
system. Figure 3 shows Architectural Modeling for risk
analysis applied to a service of Electronic Online Payment of
Poste Italiane.</p>
      <sec id="sec-4-1">
        <title>PEO Service Result Analysis</title>
        <p>Considering a combination of services based on high level
quality percentage, the probability of PEO success is 99%,
which means a LowRisk.</p>
        <p>(i) the availability (working) or unavailability (not working)
of a service</p>
        <p>(ii) the time when the failure of a service happened
(timestamps)</p>
        <p>(iii) the cause of the failure, if it is due to internal or
external factors.</p>
        <p>This allows to assess the main system (PEO Service) and its
interdependencies with the involved services, by considering
events of faults and failures and their propagation in the
network, from a dynamic point of view by including temporal
constrains.</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>A.</given-names>
            <surname>Tundis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Garro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Gallo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Saccá</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Citrigno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Graziano</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Mühlhäuser</surname>
          </string-name>
          .
          <year>2017</year>
          .
          <article-title>Systemic Risk Modeling and Evaluation through</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>