Cybersecurity Vulnerability Identification in System-of-Systems using Model-based Testing

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 64
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorThwe, May Myatko
dc.contributor.authorBelay, Zelalem Mihretko
dc.contributor.authorJee, Eunkyoungko
dc.contributor.authorBae, Doo-Hwanko
dc.date.accessioned2022-11-09T10:00:41Z-
dc.date.available2022-11-09T10:00:41Z-
dc.date.created2022-09-27-
dc.date.created2022-09-27-
dc.date.issued2022-06-09-
dc.identifier.citation2022 17th Annual System of Systems Engineering Conference (SOSE), pp.317 - 322-
dc.identifier.urihttp://hdl.handle.net/10203/299410-
dc.description.abstractWhen operationally and managerially independent constituent systems are integrated to form a System of Systems (SoS), cybersecurity vulnerabilities can be exploited by cyber threats that can break the security requirements of SoS due to its collaborative nature. Using model-based testing to generate test cases automatically can potentially aid in discovering vulnerabilities. However, security test case generation is time-consuming, error-prone, and labor-intensive; therefore, it is desirable to fully or partially automate security testing processes. This paper proposes the automatic test data generation using formal models presented as communicating sequential processes. We use the model-checking technique that generates counterexamples when the specified security properties are violated. Our approach then converted those counterexamples into executable test data by applying the conversion rule and defined mapping algorithm. We demonstrate our approach with an experiment using an operation of an air traffic control (ATC) system, a representative of SoS. We developed an agent simulation program to test the operation of the ATC by using the generated test data and evaluating it in terms of vulnerability identification. We incorporated four attack types, and our experimental results show that the security tests generated from the models can identify the known vulnerabilities in the ATC system.-
dc.languageEnglish-
dc.publisherInstitute of Electrical and Electronics Engineers Inc.-
dc.titleCybersecurity Vulnerability Identification in System-of-Systems using Model-based Testing-
dc.typeConference-
dc.identifier.scopusid2-s2.0-85135133824-
dc.type.rimsCONF-
dc.citation.beginningpage317-
dc.citation.endingpage322-
dc.citation.publicationname2022 17th Annual System of Systems Engineering Conference (SOSE)-
dc.identifier.conferencecountryUS-
dc.identifier.conferencelocationRochester-
dc.identifier.doi10.1109/SOSE55472.2022.9812676-
dc.contributor.localauthorBae, Doo-Hwan-
dc.contributor.nonIdAuthorThwe, May Myat-
dc.contributor.nonIdAuthorBelay, Zelalem Mihret-
dc.contributor.nonIdAuthorJee, Eunkyoung-
Appears in Collection
CS-Conference Papers(학술회의논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0