<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>International Workshop on Petri Nets and Software
Engineering, June</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Adaptative Systems Based on Continuous Observation of Petri Net Product Lines</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Elena Gómez-Martínez</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>José Ignacio Requeno</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Universidad Autónoma de Madrid, C/Francisco Tomás y Valiente</institution>
          ,
          <addr-line>11, Madrid, 28049</addr-line>
          ,
          <country country="ES">Spain</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Universidad Complutense de Madrid, C/Prof. José García Santesmases</institution>
          ,
          <addr-line>9, Madrid, 28040</addr-line>
          ,
          <country country="ES">Spain</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2022</year>
      </pub-date>
      <volume>21</volume>
      <issue>2022</issue>
      <fpage>0000</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>Traditionally, critical systems have been deployed in isolation, that is, in closed environments where the access control was easily managed. However, the increasing complexity and connectivity of these systems make them vulnerable to cyberattacks, malfunctioning or any kind of uncontrolled events. In this work, we propose a framework that is capable of automatically adapt its configuration for addressing the challenges of an environmental change. To this end, we model the critical system as a Petri net which is enriched with product lines that implement actions for diferent scenarios. The execution traces are then continuously monitored and provide information to the control logic responsible for achieving the critical system goals by means of the product lines.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Petri net</kwd>
        <kwd>Product line</kwd>
        <kwd>Runtime verification</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Traditionally, critical systems have been deployed in
isolation, that is, in closed environments where the access
control was easily managed. Recently reports indicate
that these systems are vulnerable to cyberattacks as well
[1]. Security flaws may directly impact safety in critical
systems. Current approaches and tools concerning
security do not ensure their adequacy to industrial standards
for safety level.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Background</title>
      <p>We combine the following concepts for our approach: 1)
Petri nets as formal model, 2) Product Lines for designing,
and 3) Runtime verification for system monitoring.</p>
      <p>A Petri net will model the critical system, where each
product line implements a specific configuration.
Depending on the Key Performance Indicators (KPI) defined
by the customer and the measurements the monitor
extracts by simulation of the formal model, our new
framework checks if the critical system will manage to achieve
the user requirements by switching on/of the product
lines on runtime.</p>
      <p>We are basing our approach on the following previous
works:
• A framework for modelling product lines with
Petri nets, using an eclipse plug-in, called Titan
[2].
• A framework for abstracting data and datatypes
as colours and hierarchies in Coloured Petri Nets
[3, 4].
• A transformation of product Lines with Petri nets
into Coloured Petri Nets [5].
• A language for the specification and runtime
verification of systems [6].
safety and security requirements and system
characteristics in a single picture.
• automatically adapt the system configuration
based on the simulation reports.</p>
    </sec>
    <sec id="sec-3">
      <title>Acknowledgments</title>
      <p>This work was supported by the Spanish Ministry of
Science and Innovation under projects FAME
(RTI2018093608-B-C31), MASSIVE (RTI2018-095255-B-I00) and
the Comunidad de Madrid under project FORTE-CM
(S2018/TCS-4314) co-funded by EIE Funds of the
European Union.
[1] T. Telford, Cyber attacks on rail network, Computing</p>
      <p>Security .
3. Approach [2] E. Gómez-Martínez, J. de Lara, E. Guerra, Extensible
Structural Analysis of Petri Net Product Lines, Trans.</p>
      <p>In contrast to [2], our new approach includes a Trans- Petri Nets Other Model. Concurr. 15 (2021) 27–49.
formation phase, which maps product lines to colours in [3] M. Westergaard, L. M. Kristensen, The Access/CPN
Coloured Petri Nets [3]. Framework: A Tool for Interacting with the CPN</p>
      <p>Then, the Simulation phase runs the model, which now Tools Simulator, in: G. Franceschinis, K. Wolf (Eds.),
supports all the features that the Access/CPN engine Applications and Theory of Petri Nets, 30th
Internaprovides such as timed information. tional Conference, PETRI NETS 2009, Paris, France,</p>
      <p>The Monitoring phase, aimed at detecting concurrence June 22-26, 2009. Proceedings, vol. 5606 of Lecture
and performance issues, analyses the simulation traces Notes in Computer Science, Springer, 313–322, 2009.
via TeSSLa [6] in order to report performance and con- [4] K. Jensen, L. M. Kristensen, L. Wells, Coloured Petri
currence reports. Nets and CPN Tools for modelling and validation</p>
      <p>During the Assessment phase, the framework will au- of concurrent systems, Int. J. Softw. Tools Technol.
tomatically turn on/of specific product lines in order to Transf. 9 (3-4) (2007) 213–254.
achieve the target KPI. [5] E. Gómez-Martínez, J. de Lara, E. Guerra, Analysing
Product Lines of Concurrent Systems with Coloured
Petri Nets, in: Accepted in the 34th International</p>
    </sec>
    <sec id="sec-4">
      <title>4. Ongoing work</title>
      <p>Conference on Software Engineering and Knowledge
Engineering, 2022.
[6] M. Leucker, C. Sánchez, T. Schefel, M. Schmitz,
A. Schramm, TeSSLa: runtime verification of
nonsynchronized real-time streams, in: H. M. Haddad,
R. L. Wainwright, R. Chbeir (Eds.), Proceedings of
the 33rd Annual ACM Symposium on Applied
Computing, SAC 2018, Pau, France, April 09-13, 2018,
ACM, 1925–1933, 2018.</p>
      <p>We are currently working on two directions. Firstly, we
are extending the PNPL modelling framework capabilities
to support additional features such as timed information.
Secondly, we explore how to automatically (de)activate
product lines based on the monitoring of Key
Performance Indicators (KPI). In particular, we are connecting
Titan with 1) AccessCPN, the kernel of CPNTools, for
simulation purposes; and 2) TeSSLa, a runtime
monitoring engine, for providing information to the control logic
responsible for managing the product lines.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <p>In this work in process, our aim is to:
• augment our framework for enabling software
engineers to express and monitor performance,</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>