This paper presents a generic component for Analytic Hierarchy Process (AHP)-based decision support in risk management. The component was originally dedicated to railway transportation issues; however, its generality enabled it to extend its functionality for other domains too. To show the generality of the module and possibility of its application in other domains, an environmental case was run. Its goal was to select methods for planning the post-mining heap revitalization process, especially decision-making focusing on the selection of the most advantageous revitalization option on the basis of the Analytic Hierarchy Process and different, non-financial factors, e.g., social, environmental, technological, political, etc. Taking into account expert responses, the suggested solution was related to energy production.
This paper concerns the revitalization of post-mining heaps using a developed software tool. Revitalizing degraded areas is crucial for sustainable development because heaps pose numerous hazards to people and the environment, and there are significant numbers of waste heaps across Europe. The applied approach enables us to consider essential factors when deciding on the heap revitalization strategy. This includes heap properties, assumed land use, and various risks to people and environment, financial, and intangible factors. The methodology addresses various revitalization aims, ranging from heap liquidation to different forms of nature restoration and industrial or energy applications. A computer-aided tool was developed based on this approach, allowing the specification of the revitalized heap and proposed revitalization alternatives. It assesses risk reduction, costs/benefits, and non-financial factors such as social, environmental, technological, and political aspects for each alternative. This provides decision-makers with input to manually select the target alternative for implementation. The revitalization planning process is supported comprehensively, and there are additional cost-, quality-, and time-related advantages due to computer aid. The authors suggest future tool enhancements, especially to extend the range of applications and better formalize the decision process.
The Industry 4.0 idea inspires the development of different specialized IT components used to build automation and control systems, like PLD (Programmable Logic Device), SCADA (Supervisory Control and Data Acquisition), HMI (Human Machine Interface), RTU (Remote terminal unit), as well as intelligent sensors, instruments and autonomous devices connected through the internet to industrial applications embraced by the term IloT (Industrial Internet of Things). Such components require security assurance so that they should not be the weakest links of complex industry systems. One of the ways to obtain security assurance is the third party security evaluation and certification. Existing security evaluation schemes and their methodologies are not ready to evaluate numerous components emerging in this domain. For several years new approaches to solve this problem have been developed. Some of them already work, while the most comprehensive ones are under development. The paper includes a review of the main directions of these works. It presents the significance of the EU Cybersecurity Act (CSA) and the initiatives it implied. Existing standards are very important, especially Common Criteria and IEC 62443. They are adapted to new challenges. Equally important are works focused on the preparation of international lightweight certification schemes allowing to get a security certificate in a restricted time horizon.
It seems to be a truism to say that we should pay more and more attention to network traffic safety. Such a goal may be achieved with many different approaches. In this paper, we put our attention on the increase in network traffic safety based on the continuous monitoring of network traffic statistics and detecting possible anomalies in the network traffic description. The developed solution, called the anomaly detection module, is mostly dedicated to public institutions as the additional component of the network security services. Despite the use of well-known anomaly detection methods, the novelty of the module is based on providing an exhaustive strategy of selecting the best combination of models as well as tuning the models in a much faster offline mode. It is worth emphasizing that combined models were able to achieve 100% balanced accuracy level of specific attack detection.
This paper presents an advanced risk management methodology which supports the planning of the revitalization process of post-mining heaps. More specifically, it supports decision-makers in the selection of the most advantageous revitalization actions with respect to the defined criteria embracing risk and cost–benefit parameters as well as different qualitative factors. This methodology was elaborated with a view to software implementation and is a good example of ICT adoption in emerging domains of application. The question is how to organize the revitalization decision process and support it with a software tool. The methodology and tool are based on three pillars: risk, cost–benefit, and qualitative criteria assessments of the considered revitalization actions in order to select the target for the implementation of the given heap. This paper presents the methodology implemented in the software as well as its validation on an extensive example. The steps described in the example allow the decision-maker to identify a target revitalization alternative. The conclusions focus on the solution’s feasibility and the software implementation and extensions.
Assuring the network traffic safety is a very important issue in a variety of today’s industries. Therefore, the development of anomalies and attacks detection methods has been the goal of analyses. In the paper the binary classification-based approach to network traffic safety monitoring is presented. The well known methods were applied to artificially modified network traffic data and their detection capabilities were tested. More detailed interpretation of the nature of detected anomalies is carried out with the help of the XAI approach. For the purpose of experiments a new benchmark network traffic data set was prepared, which is now commonly available.
The paper concerns the EU RFCS SUMAD (Sustainable Use of Mining Waste Dump) project. It presents the concept of an extension of the risk management tool which can be applied to plan the revitalization process of post-mining areas, such as waste dumps. The tool will support decision makers in the revitalization planning phase by the selection of the most advantageous revitalization activities for the considered waste dump and the assumed land use. The proposed tool is based on three pillars: Risk Reduction Assessment (RRA), Cost-Benefits Analysis (CBA) and Qualitative Criteria Analysis (QCA), used to work out aggregated information for a decision maker. The extension of this tool, discussed in the paper, embraces a new functionality called the performance evaluation subsystem. It allows to monitor the revitalized object after the implementation of the revitalization plan. Three categories of performance indicators are designed: environmental, financial and social, and four types of the indicators with respect to the monitored values. Different modes of indicators feeding are discussed. The presented model was validated on some diversified examples of indicators.
The paper presents an open–source–based environment for network traffic anomaly detection. The system complements the well known network security platforms as it tries to detect unexplained descriptions of the traffic. For this purpose several anomaly detection algorithms were applied. To assure better system performance, the moving history approach is also applied.
Network traffic monitoring becomes, year by year, an increasingly more important branch of network infrastructure maintenance. There exist many dedicated tools for on-line network traffic monitoring that can defend the typical (and known) types of attacks by blocking some parts of the traffic immediately. However, there may occur some yet unknown risks in network traffic whose statistical description should be reflected as slow-intime changing characteristics. Such non-rapidly changing variable values probably should not be detectable by on–line tools. Still, it is possible to detect these changes with the data mining method. In the paper the popular anomaly detection methods with the application of the moving window procedure are presented as one of the approaches for anomaly (outlier) detection in network traffic monitoring. The paper presents results obtained on the real outer traffic data, collected in the Institute.
The paper concerns the Common Criteria Evaluation Methodology (CEM) and is focused on the knowledge engineering application for vulnerability assessment. To enable automation of this complex process, better structurization of evaluation activities and data is required. The main finding of the paper is the development of ontology-based data models to be applied in the knowledgebase of a tool supporting the Common Criteria Vulnerability Assessment. The ontology use is exemplified on the vulnerability analysis of a simple firewall. The readers should have basic knowledge about Common Criteria and the ontology development.
The paper concerns the EU RFCS SUMAD (Sustainable Use of Mining Waste Dump) project. It presents the concept of a risk management tool which can be applied to plan the revitalization process of post-mining areas, such as waste dumps. The tool will support decision makers in the selection of the most advantageous revitalization activities for the considered waste dump and the assumed land use. The proposed tool is based on three pillars: Risk Reduction Assessment (RRA), Cost-Benefits Analysis (CBA) and Qualitative Criteria Analysis (QCA) used to work out aggregated information for a decision maker. The RRA user, based on the current risk related to the waste dump, proposes several alternatives of revitalization activities properly reducing this risk. Next, economic parameters of alternatives are analyzed with the use of CBA. Finally, non-financial parameters like: societal, ethical, political, technological, environmental parameters, etc. are considered with the support of QCA. The decision maker gets aggregated information to select the right activities for implementation. The proposed tool concept will be used to orientate the tool design and implementation and to search the project domain for data needed for the tool development.
There are more and more applications of sensors in today's world. Moreover, sensor systems are getting more complex and they are used for many high-risk security-critical purposes. Security assurance is a key issue for sensors and for other information technology (IT) products. Still, sensor security facilities and methodologies are relatively poor compared to other IT products. That is why a methodical approach to the sensor IT security is needed, i.e., risk management, implementation of countermeasures, vulnerability removal, and security evaluation and certification. The author proposes to apply the main security assurance methodology specified in ISO/IEC 15408 Common Criteria to solve specific security problems of sensors. A new Common Criteria compliant method is developed which specifies the vulnerability assessment process and related data in a structured way. The input/output data of the introduced elementary evaluation processes are modeled as ontology classes to work out knowledge bases. The validation shows that sensor-specific knowledge can be acquired during the vulnerability assessment process and then placed in knowledge bases and used. The method can be applied in different IT products, especially those with few certifications, such as sensors. The presented methodology will be implemented in a software tool in the future.
The paper deals with the Common Criteria Evaluation Methodology (CEM), especially with its part related to the vulnerability assessment. The aim of the paper is better structurization of the vulnerability assessment process, allowing its future automatization. The ontological approach will be applied to develop the models of processes and data. The elementary evaluation processes are defined on the basis of the analysis of the CEM vulnerability assessment. The process activities, input and output information, are identified and specified in a pseudocode. The process verification against CEM is performed. The conclusions summarize the verification and propose future works to build the ontology, knowledge base and the vulnerability assessment tool.
The paper focuses on a selected element of network security assurance, which is anomaly detection in network traffic monitoring. The anomaly detection component is developed as part of Regional Security Operation Center (developed in the RegSOC project) – a local instance of the Security Operational Center (SOC) – to detect incidents or their symptoms in terms of outlier observations in data. The objective of the research is to assess and select for implementation methods and tools satisfying the requirements of the performed RegSOC project. The paper discusses the role and placement of such tools in the general SOC architecture and requirements to be satisfied by these tools in a view of the specific RegSOC project needs. Next, a review of available methods and tools is performed to select the most useful ones. Using the selected tool, a general concept of security analysis component is presented and assessed against the project requirements.
The paper deals with the Common Criteria assurance methodology, particularly with the IT security evaluation process specified by the Common Criteria Evaluation Methodology (CEM). To better organize this very complex evaluation process the ontological approach is proposed. The previously developed ontology focused on the IT product development according to Common Criteria is extended by evaluation issues. Ontology classes, properties and individuals are elaborated to express the IT security evaluation according to CEM. The ontology use is exemplified on the vulnerability analysis of a simple firewall. The paper points out the need to extend this ontology to the full vulnerability analysis of different IT products and assurance levels. The readers should have basic knowledge about Common Criteria and the ontology development.
The paper concerns the risk management issue. Different approaches static and real-time (dynamic) are reviewed, as well as their advantages and gaps. A broadly used static risk assessment/management (SRA/M) process is comprehensive, complex, invoked periodically, but it omits fluctuating risk factors and has limited ability to adapt itself to the changing risk picture. The paper proposes a mixed-mode approach. The SRA/M process is transformed towards the adaptive risk management (ARM) process. This adaptation is based on real-time risk management (RTRM) results gathered during a period between static risk assessments. All risk management processes are expressed in a pseudo-code. The method is exemplified by a simple but representative case study.
The paper deals with the Common Criteria assurance methodology, particularly vulnerability assessment which is the key activity of the IT security evaluation process. Vulnerability assessment is specified by the Common Criteria Evaluation Methodology (CEM). The paper is focused on software support for vulnerability assessment. As the implementation platform, a ready-made risk management software developed by the author's organization is applied. The paper includes introduction to the vulnerability assessment, review of the existing methods and tools, specification of the CEM-based method to be implemented in the software, implementation and short exemplification. The conclusions summarize the validation and propose future works to extend and improve the tool.
The paper concerns a risk assessment and management methodology in critical infrastructures. The aim of the paper is to present researches on risk management within the experimentation tool based on the OSCAD software. The researches are focused on interdependent infrastructures where the specific phenomena, like escalating and cascading effects, may occur. The objective of the researches is to acquire knowledge about risk issues within interdependent infrastructures, to assess the usefulness of the OSCAD-based risk manager in this application domain, and to identify directions for further R&D works. The paper contains a short introduction to risk management in critical infrastructures, presents the state of the art, and the context, plan and scenarios of the performed validation experiments. Next, step by step, the validation is performed. It encompasses two collaborating infrastructure (railway, energy). It is shown how a hazardous event impacts the given infrastructure (primary and secondary effects) and the neighbouring infrastructure. In the conclusions the experiments are summarized, the OSCAD software assessed and directions of the future works identified.
The paper concerns research related to the European project CIRAS and presents a validation experiment with the use of a risk management tool adapted for critical infrastructures. The project context and state of the art are discussed. The adaptation of the risk management tool is performed according to previously elaborated requirements which consider interdependencies, cause-consequences analysis, risk measures and risk register implementation. A novel structured risk management method was proposed how to deal with internal and external impacts of a hazardous event which occurred in the given CI. The method is embedded into the critical infrastructure resilience process. These requirements can be implemented on the ready-to-use software platform for further experiments. The experimentation results are used as the input for CIRAS. The discussed tool can be applied as the risk reduction component in the CIRAS Tool, and the validation process presented here is the basis to elaborate two project use cases.
The paper deals with a methodology for the assessment and management of risk in critical infrastructures. A ready-made risk manager, which supports information security- and business continuity management systems, was adapted to a new application domain-critical infrastructure protection and was used in the EU Ciras project as one of its three basic pillars. First, the author reviewed security issues in critical infrastructures, with special focus on risk management. On this basis the assumptions were discussed how to adapt the ready-made risk manager for this domain. The experimentation tool was configured, including risk measures and system dictionaries. The operations of the tool were illustrated by examples from a case study performed in a previous work. The case study dealt with the collaborating railway- and energy critical infrastructures. The aim of this research is to assess the usefulness of such approach and to acquire knowledge for future project works.