Advanced Air Mobility (AAM) and Urban Air Mobility (UAM) are emerging concepts that capitalize on urban airspace for commercial transportation of passengers and cargo as well as augment surface transportation infrastructure. A major part of the solution towards achieving the UAM/AAM vision will be assured and trusted autonomy that enable human operators and passengers to interact with autonomous systems that transport humans and cargo with high assurance of safety, security and reliability. Given the complex interactions among the autonomy algorithms, human, environment and UAM control, there is a need for vehicle-level monitoring that detects emerging hazard scenarios. The data gathered from UAM systems that would help detect emerging hazards will be diverse: from highly-regular information (onboard flight controls) to irregular streaming information (weather, real time population dynamics). This paper presents a systematic approach for developing model- and data-driven hazard monitoring framework which we call pervasive monitoring. The aim of pervasive monitoring is to “comprehensively" observe a Cyber Physical System (CPS) at different architectural levels to ensure its safety and security with respect to its intended operation. Since there is no single monitor type that solves complex in-time hazard detection problems for UAM, we assert that several classes of monitors are needed to address this challenge. In this paper, we present a methodology based on STPA that partitions the UAM hazard monitoring challenge into two problems: a context monitoring problem and vehicle monitoring problem. We present preliminary results on deriving monitors from STPA, and realization of the monitors using the NASA Runtime Verification language Co-pilot.
While design assurance and testing methods for safety-critical systems have been widely researched and studied for years across a number of industry domains, there are few efforts reported in the literature on the actual application of software testing methods to nuclear power digital I&C systems or devices. We see this as a gap in the knowledge basis. The motivation for this research was to investigate the efficacy and challenges that arise when planning, automating and conducting systematic software testing on actual real-time embedded digital devices. In this paper, we present results on the application of a systematic testing methodology called Pseudo-Exhaustive testing. The systematic testing methods were applied at the unit and module integration levels of the software. The findings suggest that Pseudo Exhaustive testing supported by automated testing technology is an effective approach to testing real-time embedded digital devices in critical nuclear applications.
Applying security as a lifecycle practice is becoming increasingly important to combat targeted attacks in safety-critical systems. Among others, there are two significant challenges in this area: the need for models that can characterize a realistic system in the absence of an implementation and an automated way to associate attack vector information, that is, historical data, to such system models. We propose the cybersecurity body of knowledge (CYBOK), which takes in sufficiently characteristic models of systems and acts as a search engine for potential attack vectors. CYBOK is fundamentally an algorithmic approach to vulnerability exploration, which is a significant extension to the body of knowledge it builds upon. By using CYBOK, security analysts and system designers can work together to assess the overall security posture of systems early in their lifecycle, during major design decisions and before final product designs, consequently, assisting in applying security earlier and throughout the systems lifecycle.
Today, there is a plethora of software security tools employing visualizations that enable the creation of useful and effective interactive security analyst dashboards. Such dashboards can assist the analyst to understand the data at hand and, consequently, to conceive more targeted preemption and mitigation security strategies. Despite the recent advances, model-based security analysis is lacking tools that employ effective dashboards-to manage potential attack vectors, system components, and requirements. This problem is further exacerbated because model-based security analysis produces significantly larger result spaces than security analysis applied to realized systems-where platform specific information, software versions, and system element dependencies are known. Therefore, there is a need to manage the analysis complexity in model-based security through better visualization techniques. Towards that goal, we propose an interactive security analysis dashboard that provides different views largely centered around the system, its requirements, and its associated attack vector space. This tool makes it possible to start analysis earlier in the system lifecycle. We apply this tool in a significant area of engineering design-the design of cyber-physical systems-where security violations can lead to safety hazards.
Robert H. Klenke合作论文数Virginia Commonwealth University1