Developing Dependability Requirements Engineering for Secure and Safe Information Systems with Knowledge Acquisition for Automated Specification — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
Developing Dependability Requirements Engineering for Secure and Safe Information Systems with Knowledge Acquisition for Automated Specification
Software Engineering Department, University of Palestine, Gaza, Palestine
1 Software Engineering Department, University of Palestine, Gaza, Palestine
Our dependability on software in every aspect of our lives has exceeded the level that was expected in the past. We have now reached a point where we are currently stuck with technology, and it made life much easier than before. The rapid increase of technology adoption in the different aspects of life has made technology affordable and has led to an even stronger adoption in the society. As technology advances, almost every kind of technology is now connected to the network like infrastructure, automobiles, airplanes, chemical factories, power stations, and many other systems that are business and mission critical. Because of our high dependency on technology in most, if not all, aspects of life, a system failure is considered to be very critical and might result in harming the surrounding environment or put human life at risk. We apply our conceptual framework to integration between security and safety by creating a S a S (Safety and Security) domain model. Furthermore, it demonstrates that it is possible to use goal-oriented KAOS (Knowledge Acquisition in automated Specification) language in threat and hazard analysis to cover both safety and security domains making their outputs, or artifacts, well-structured and comprehensive, which results in dependability due to the comprehensiveness of the analysis. The conceptual framework can thereby act as an interface for active interactions in risk and hazard management in terms of universal coverage, finding solutions for differences and contradictions which can be overcome by integrating the safety and security domains and using a unified system analysis technique (KAOS) that will result in analysis centrality. For validation we chose the Systems-Theoretic Accident Model and Processes (STAMP) approach and its modelling language, namely System-Theoretic Process Analysis for safety (STPA), on the safety side and System-Theoretic Process Analysis for Security (STPA-sec) on the security side in order to be the base of the experiment in comparison to what was done in S a S. The concepts of S a S domain model were applied on STAMP approach using the same example @ RemoteSurgery .
KeywordsSafety Information ModelSecurity Information ModelDependability RequirementsGoal ModelingKAOSObstacles Base
Committee on National Security Systems (CNSS). National Information Assurance (IA) Glossary (CNSS Instruction No.4009). Committee on National Security Systems (CNSS), National Security Agency (NSA), Fort Meade, May 2003.
Piètre-Cambacédès, L. and Chaudet, C. (2010) The SEMA Referential Framework: Avoiding Ambiguities in the Terms “Security” and “Safety”. International Journal of Critical Infrastructure Protection, 3, 55-66. https://doi.org/10.1016/j.ijcip.2010.06.003
Benjamin, F., Seda, G., Maritta, H., Thomas, S. and Holger, S. (2010) A Comparison of Security Requirements Engineering Methods. Requirements Engineering, 15, 7-40.
Avizienis, A., Laprie, J.-C., Randell, B. and Landwehr, C. (2004) Basic Concepts and Taxonomy of Dependable and Secure Computing. IEEE Transactions on Dependable and Secure Computing, 1, 11-33. https://doi.org/10.1109/TDSC.2004.2
Firesmith, D.G. (2003) Common Concepts Underlying Safety Security and Survivability Engineering. (No. CMU/SEI-2003-TN-033) Software Engineering Institute, Carnegie Mellon University.
Firesmith, D.G. (2004) A Taxonomy of Safety-Related Requirements. Position Paper at the Requirements for High Assurance Systems (RHAS) Workshop at the 12th IEEE International Conference on Requirements Engineering (RE'2004) in Kyoto, Japan on 6 September 2004, 11 p.
Firesmith, D.G. (2012) Engineering Safety- and Security-Related Requirements for Software-Intensive Systems. The 11th IASTED International Conference on Software Engineering (SE 2012) in Crete, Greece on 18 June 2012.
Mayer, N., Rifaut, A. and Dubois, E. (2005) Towards a Risk-Based Security Requirements Engineering Framework. Proceedings of the 11th International Workshop on Requirements Engineering: Foundation for Software Quality (REFSQ'05), in Conjunction with the 17th Conference on Advanced Information Systems Engineering (CAiSE'05).
Yu, E.S.K. (1997) Towards Modeling and Reasoning Support for Early-Phase Requirements Engineering. RE '97: Proceedings of the 3rd IEEE International Symposium on Requirements Engineering. IEEE Computer Society, Washington DC, 226.
Yu, E.S.K. and Liu, L. (2001) Modelling Trust for System Design Using the i * Strategic Actors Framework. Proceedings of the Workshop on Deception, fraud, and Trust in Agent Societies Held during the Autonomous Agents Conference, Springer, London, 175-194.
Liu, L., Yu, E. and Mylopoulos, J. (2003) Security and Privacy Requirements Analysis within a Social Setting. Proceedings of 11th IEEE Requirements Engineering Conference. IEEE Press, 151-161. https://doi.org/10.1109/icre.2003.1232746
Risk Management
Piètre-Cambacédès, L. and Bouissou, M. (2010) Modeling Safety and Security Interdependencies with BDMP (Boolean logic Driven Markov Processes). 2010 IEEE International Conference on Systems Man and Cybernetics (SMC), 10-13 October 2010, 2852, 2861.
Kriaa, S., Bouissou, M. and Piètre-Cambacédès, L. (2012) Modeling the Stuxnet Attack with BDMP: Towards More Formal Risk Assessments. 2012 7th International Conference on Risk and Security of Internet and Systems (CRiSIS), 10-12 October 2012, 1-8.
Firesmith, D. (2010) Engineering Safety- and Security-Related Requirements for Soft-Ware-Intensive Systems: Tutorial Summary. Proceedings of the 32nd ACM/ IEEE International Conference on Software Engineering, Volume 2 (ICSE '10), Vol. 2. ACM, New York, 489-490.
Mayer, N. (2009) Model-Based Management of Information System Security Risk. Doctoral Dissertation, University of Namur, Namur.
C. Warren, A. (2012) Engineering Safe and Secure Software Systems. 1st Edition, Artech House, Boston.
Redmill, F. and Consultancy, R. (1999) An Introduction to the Safety Standard IEC 61508. Hazard Prevention, 35, 20-25.
Brazendale, J. (1995) IEC 1508: Functional Safety: Safety-Related Systems. In Software Engineering Standards Symposium, August 1995. (ISESS'95)'Experience and Practice', Proceedings, Second IEEE International, IEEE, 8-17.
Van Lamsweerde, A. and Letier, E. (2000) Handling Obstacles in Goal-Oriented Requirements Engineering. IEEE Transactions on Software Engineering, 26, 978-1005. https://doi.org/10.1109/32.879820
Firesmith, D.G. (2007) Engineering Safety and Security Related Requirements for Soft-Ware Intensive Systems. 29th International Conference on Software Engineering-Companion, 2007. ICSE 2007 Companion, 169-169.
Van Lamsweerde, A. (2009) Requirements Engineering: From System Goals to UML Models to Software Specifications.
Matulevičius, R. and Heymans, P. (2007) Comparing goal Modelling Languages: An Experiment. In: Sawyer, P., Paech, B. andHeymans, P., Eds., Proceedings of the 13th International Working Conference on Requirements Engineering: Foundation for Software Quality (REFSQ'07), Springer-Verlag, Berlin, Heidelberg, 18-32.
Sadvandi, S., Chapon N. and Pietre-Cambacedes, L. (2011) Towards a System Engineering Approach to Master Safety and Security Interdependencies. Proceedings of the 23rd International Conference on Software & Systems Engineering and Their Application (ICSSEA), Paris.
Romani, M.A.S., Lahoz, C.H.N. and Yano, E.T. (2009) Dependability Attributes for Space Computer Systems. Proceedings of 3rd CTA-DLR’Brazilian Symposium on Aerospace Engineering and Applications/Workshop on Data Analysis and Flight Control.
Hollnagel, E., Woods, D.D. and Leveson, N., Eds. (2007) Resilience Engineering: Concepts and Precepts. Ashgate Publishing, Ltd., Ashgate.
Basili, V., Caldiera, G. and Rombach, H.D. (1994) The Goal Question Metric Approach. John Wiley & Sons, Inc.
Matulevičius, R. and Heymans, P. (2007) Comparing Goal Modelling Languages: An Experiment. Requirements Engineering: Foundation for Software Quality Lecture Notes in Computer Science, 4542, 18-32.
Young, W. and Leveson, N.G. (2013) Systems Thinking for Safety and Security. ACSAC.
Young, W. and Leveson, N.G. (2014) An Integrated Approach to Safety and Security Based on Systems Theory. Communications of the ACM, 57, 31-35.
Matulevičius, R., Heymans, P. and Sindre, G. (2006) Comparing Goal-Modelling Tools with the RE-Tool Evaluation Approach. Information Technology and Control, 35A, 276-284.
Jackson, D., Thomas, M. and Millett, L.I., Eds., Committee on Certifiably Dependable Software Systems, National Research Council (2007) Software for Dependable Systems: Sufficient Evidence? National Academy of Sciences, Washington DC.
Fei, B.w., Ng, W.S., Chauhan, S. and Kwoh, C.K. (2001) The Safety Issues of Medical Robotics. Reliability Engineering & System Safety, 73, 183-192.
Marescaux, J., Lero, J., Rubino, F., Vix, M., Simone, M. and Mutter, D. (2002) Transcontinental Robot Assisted Remote Telesurgery: Feasibility and Potential Applications. Annals of Surgery, 235, 487-492. https://doi.org/10.1097/00000658-200204000-00005
Anvari, M., McKinley, C. and Stein, H. (2005) Establishment of the World’s First Telerobotic Remote Surgical Service: For Provision of Advanced Laparoscopic Surgery in a Rural Community. Annals of Surgery, 241, 460-464.
Anvari, M. (2007) Remote Telepresence Surgery: The Canadian Experience. Surgical Endoscopy, 21, 537-541.
Arata, J., et al. (2006) A Remote Surgery Experiment between Japan-Korea Using the Minimally Invasive Surgical System. Proceedings 2006 IEEE International Conference on Robotics and Automation, ICRA 2006, IEEE, 2006.
Hollnagel, E., Woods, D.D. and Leveson, N. (2006) Resilience Engineering Concepts and Precepts. Chapter 8: Engineering Resilience into Safety-Critical Systems. CRC Press. US, NW.
Leveson, N.G. (2012) Engineering a Safer World: Systems Thinking Applied to Safety. The MIT Press, Cambridge, MA.
Leveson, N.G. (2013) An STPA Primer Version 1. August 2013.
ISO, E. (2009) 14971: 2009. Medical Devices-Application of Risk Management to Medical Devices (ISO 14971: 2007, Corrected version 2007-10-01). CEN/CENELEC, Brussels, Belgium.
Council Directive 93/42/EEC of 14 June 1993 concerning medical devices, Official Journal L 169, 12/07/1993 P. 0001-0043.