To cope with unforeseen attacks to software systems in critical application domains, redundancy-based ITSs schemes are among popular countermeasures to deploy. Designing the adequate ITS for the stated security requirements calls for stochastic analysis supports, able to assess the impact of variety of attack patterns on different ITS configurations. As contribution to this purpose, a stochastic model for ITS is proposed, whose novel aspects are the ability to account for both camouflaging components and for correlation aspects between the security failures affecting the diverse implementations of the software cyber protections adopted in the ITS. Extensive analyses are conducted to show the applicability of the model; the obtained results allow to understand the limits and strengths of selected ITS configurations when subject to attacks occurring in unfavorable conditions for the defender.
With focus on open-ended architectural adaptation, where individual components represent alternatives that can be added and removed dynamically at runtime, a new metric is proposed to provide insights on the effectiveness of architectural changes, such as the addition or removal of components. Specifically, the new metric allows to assess how much the system actually adapts to variations of the environment by properly applying a system reconfiguration. The approach is based on a statistical analysis of the system, which exploits the Bell inequality, conveniently adapted from the Quantum Mechanic theory. The formal definition of the new adaptability metric is presented, as well as an example of application in a simple case study.
A new methodology for effective definition and efficient evaluation of dependability-related properties is proposed. The analysis targets the systems composed of a large number of components, each one modeled implicitly through high-level formalisms, such as stochastic Petri nets. Since the component models are implicit, the reward structure that characterizes the dependability properties has to be implicit as well. Therefore, we present a new formalism to specify those reward structures. The focus here is on component models that can be mapped to stochastic automata with one or several absorbing states so that the system model can be mapped to a stochastic automata network with one or several absorbing states. Correspondingly, the new reward structure defined on each component's model is mapped to a reward vector so that the dependability-related properties of the system are expressed through a newly introduced measure defined starting from those reward vectors. A simple, yet representative, case study is adopted to show the feasibility of the method.
Continuous power supply in railway systems is vital to guarantee dependable accomplishment of energy-supported critical operations. With reference to the Italian railway infrastructure, this paper focuses on the railroad signaling system, used to control the movement of railway traffic, where Uninterruptable Power Supply systems (UPS) for Safety and Signalling are employed. Fault tolerant UPS architectures are adopted to cope with unpredictable fault events occurring at UPS level, potentially resulting in safety/availability violations. This paper proposes a stochastic model-based analysis to support the comparison between different UPS redundant architectures in terms of dependability attributes, primarily reliability and availability indicators. The analysis results can be fruitfully exploited by a designer to set up the most effective UPS configuration, able to satisfy dependability requirements, while also accounting for possible saving in energy consumption.
TAPAS is a new tool for efficient evaluation of dependability and performability attributes of systems composed of many interconnected components. The tool solves homogeneous continuous time Markov chains described by stochastic automata network models structured in submodels with absorbing states. The measures of interest are defined by a reward structure based on submodels composed through transition-based synchronization. The tool has been conceived in a modular and flexible fashion, to easily accommodate new features. Currently, it implements an array of state-based solvers that addresses the state explosion problem through powerful mathematical techniques, including Kronecker algebra, Tensor Trains and Exponential Sums. A simple, yet representative, case study is adopted, to present the tool and to show the feasibility of the supported methods, in particular frommemory consumption point of view.
Borrowing from well known fault tolerant approaches based on redundancy to mask the effect of faults, redundancy-based intrusion tolerance schemes are proposed in this paper, where redundancy of ICT components is exploited as a first defense line against a subset of compromised components within the redundant set, due to cyberattacks. Features to enhance defense and tolerance capabilities are first discussed, covering diversity-based redundancy, confusion techniques, protection mechanisms, locality policies and rejuvenation phases. Then, a set of intrusion tolerance variations of classical fault tolerant schemes (including N Version Programming and Recovery Block, as well as a few hybrid approaches) is proposed, by enriching each original scheme with one or more of the previously introduced defense mechanisms. As a practical support to the system designer in making an appropriate choice among the available solutions, for each developed scheme a schematic summary is provided, in terms of resources and defense facilities needed to tolerate f value failures and k omission failures, as well as observations regarding time requirements. To provide an example of more detailed analysis, useful to set up an appropriate intrusion tolerance configuration, a trade-off study between cost and additional redundancy employed for confusion purposes is also carried out.
Given their crucial role for a society and economy, an essential component of critical infrastructures is the Bad State Estimator (BSE), responsible for detecting malfunctions affecting elements of the physical infrastructure. In the past, the BSE has been conceived to mainly cope with accidental faults, under assumptions characterizing their occurrence. However, evolution of the addressed systems category consisting in pervasiveness of ICT-based control towards increasing smartness, paired with the openness of the operational environment, contributed to expose critical infrastructures to intentional attacks, e.g. exploited through False Data Injection (FDI). In the flow of studies focusing on enhancements of the traditional BSE to account for FDI attacks, this paper proposes a new solution that introduces randomness elements in the diagnosis process, to improve detection abilities and mitigate potentially catastrophic common-mode errors. Differently from existing alternatives, the strength of this new technique is that it does not require any additional components or alternative source of information with respect to the classic BSE. Numerical experiments conducted on two IEEE transmission grid tests, taken as representative use cases, show the applicability and benefits of the new solution.
A technique to approximate solution bundles, i.e., solutions of a parametric model where parameters are treated as independent variables instead of constants, is presented for Markov models. Analyses based on an approximated solution bundle are more efficient than those that solve the model for all combinations of parameters’ values separately. In this paper the idea is to properly adapt low rank tensor approximation techniques, and in particular Adaptive Cross Approximation, to the evaluation of performability attributes. Application on exemplary case studies confirms the advantages of the new solution technique with respect to solving the model for all time and parameters’ combinations.
This paper focuses on the generation of stochastic models for dependability and performability analysis, through mechanisms for the automatic replication of template models when identity of replicas cannot be anonymous. The major objective of this work is to support the modeler in selecting the most appropriate replication mechanism, given the characteristics of the system under analysis. To this purpose, three most used solutions to identity-aware replication are considered and a formal framework to allow representing them in a consistent way is first defined. Then, a comparison of their behavior is extensively carried out, with focus on efficiency, both from a theoretical perspective and from a quantitative viewpoint. For the latter, a specific implementation of the considered replication mechanisms in the Möbius modeling environment and a case study representative of realistic interconnected infrastructures are developed.
Mobius is well known as a modeling and evaluation environment for performance and dependability indicators. It has been conceived in a modular and flexible fashion, to be easily expanded to incorporate new features, formalisms and tools. The need of modeling systems characterized by a large population of heterogeneous interacting components, which are nowadays more and more common in a variety of application contexts, provided the opportunity to focus on a new operator to efficiently manage non-anonymous replication, as requested for these systems. This tool paper presents the implementation of a new replication operator, called Advanced Rep, in Mobius. Efficiency of Advanced Rep is evaluated against a recently developed alternative solution.
Railway is currently envisioned as the most promising transportation system for both people and freight to reduce atmospheric emission and combat climate change. In this context, ensuring the energy efficiency of the railway systems is paramount in order to sustain their future expandability with minimum carbon footprint. Recent advancements in computing and communication technologies are expected to play a significant role to enable novel integrated control and management strategies in which heterogeneous data is exploited to noticeably increase energy efficiency. In this paper we focus on exploiting the convergence of heterogeneous information to improve energy efficiency of railway systems, in particular on the heating system for the railroad switches, one of the major energy intensive components. To this aim, we define new policies to efficiently manage the heating of these switches exploiting also external information such as weather and forecast data. In order to assess the performance of each strategy, a stochastic model representing the structure and operation of the railroad switch heating system and environmental conditions (both weather profiles and specific failure events) has been developed and exercised in a variety of representative scenarios. The obtained results allow to understand both strengths and limitations of each energy management policy, and serves as a useful support to make the choice of the best technique to employ to save on energy consumption, given the system conditions at hand.
Traditionally, critical infrastructures demand for high dependability, being the services they provide essential to human beings and the society at large. However, more recent attention to cautious usage of energy resources is changing this vision and calls for solutions accounting for appropriate multi-requirements combinations when developing a critical infrastructure. In such a context, analysis supports able to assist the designer in envisioning a satisfactory trade-off among the multi-requirements for the system at hand are highly helpful. In this paper, the focus is on the railway sector and the contribution is a stochastic model-based analysis framework to quantitatively assess trade-offs between dependability indicators and electrical energy consumption incurred by the rail switch heating system.Moving from a preliminary study that concentrated on energy consumption only, the analysis framework has been extended to become a solid support to devise appropriate tuning of the heating policy that guarantees satisfactory trade-offs between dependability and energy consumption. An evaluation campaign in a variety of climate scenarios demonstrates the feasibility and utility of the developed framework.
The KAES methodology for efficient evaluation of dependability-related properties is proposed. KAES targets systems representable by Stochastic Petri Nets-based models, composed by a large number of submodels where interconnections are managed through synchronization at action level. The core of KAES is a new numerical solution of the underlying CTMC process, based on powerful mathematical techniques, including Kronecker algebra, Tensor Trains and Exponential Sums. Specifically, advancing on existing literature, KAES addresses efficient evaluation of the Mean-Time-To-Absorption in CTMC with absorbing states, exploiting the basic idea to further pursue the symbolic representation of the elements involved in the evaluation process, so to better cope with the problem of state explosion. As a result, computation efficiency is improved, especially when the submodels are loosely interconnected and have small number of states. An instrumental case study is adopted, to show the feasibility of KAES, in particular from memory consumption point of view.
Awareness and efforts to moderate energy consumption, desirable from both economical and environmental perspectives, are nowadays increasingly pursued. However, when critical sectors are addressed, energy saving should be cautiously tackled, so to not impair stringent dependability properties such contexts typically require. This is the case of the railway transportation system, which is the critical infrastructure this paper focuses on. For this system category, the attitude has been typically to neglect efficient usage of energy sources, motivated by avoiding to put dependability in danger. The new directives, both at national and international level, are going to change this way of thinking. Our study intends to be a useful support to careful energy consumption. In particular, a refined stochastic modeling framework is offered, tailored to the railroad switch heating system, through which analyses can be performed to understand the sophisticated dynamics between the system (both the cyber and physical components) and the surrounding weather conditions.
Modeling cyber-physical systems (CPSs) for assessment or design support purposes is a complex activity. Capturing all relevant physical, structural or behavioral aspects of the system at hand is a crucial task, which often implies representation of peculiar features/constraints through non-linear equations. Values that fulfill the constraints, described with a domain specific language, are obtained solving the equations through a properly developed solution tool. Only for a limited set of CPSs it is possible to find a straightforward strategy to design the software that solves the constraints equations. In the general case, instead, the modeler has to develop an ad-hoc artifact for each different system. This is the case of non-holomorphic but real analytic complex equations, adopted to represent system components with wave behaviors. In this paper, we present a new approach to develop a software for solving such complex equations following a generative programming strategy, based on Wirtinger derivatives within the Newton-Raphson method.
This paper addresses the generation of stochastic models for dependability and performability analysis of complex systems, through automatic replication of template models inside the Möbius modeling framework. The proposed solution is tailored to systems composed by large populations of similar non-anonymous components, loosely interconnected with each other (as typically encountered in the electrical or transportation sectors). The approach is based on models that define channels shared among replicas, used to exchange the values of each state variable of a replica with the other replicas that need to use them. The goal is to improve the performance of simulation based solvers with respect to the existing state-sharing approach, when employed in the modeling of the addressed class of systems. Simulation results for the time overheads induced by both channel-sharing and state-sharing approaches for different system scenarios are presented and discussed. They confirm the expected gain in efficiency of the proposed channel-sharing approach in the addressed system context.
Smart grids provide services at the basis of a number of application sectors, several of which are critical from the perspective of human life, environment or financials. It is therefore paramount to be assisted by technologies able to analyze the smart grid behavior in critical scenarios, e.g. where cyber malfunctions or grid disruptions occur. In this paper, we present a stochastic modelling framework to quantitatively assess representative indicators of the resilience and quality of service of the distribution grid, in presence of accidental faults and malicious attacks. The results from the performed analysis can be exploited to understand the dynamics of failures and to identify potential system vulnerabilities, against which appropriate countermeasures should be developed. The features of the proposed analysis framework are discussed, pointing out the strong non-linearity of the involved physics, the developed solutions to deal with control actions and the definition of indicators under analysis. A case study based on a real-world network is also presented.
Jacobian-free Newton-Raphson methods are general purpose iterative non-linear system solvers. The need to solve non-linear systems is ubiquitous throughout computational physics [1] and Jacobian-free Newton-Raphson methods can offer scalability, super-linear convergence and applicability. In fact, applications span from discretized PDEs [2] to power-flow problems [3]. The focus of this article is on Inexact-Newton-Krylov [2] and Quasi-Inverse-Newton [4] methods. For both of them, we prove analytically that the initial ordering of the equations can have a great impact on the numerical solution, as well as on the number of iterations to reach the solution. We also present numerical results obtained from a simple but representative case study, to quantify the impact of initial equations ordering on a concrete scenario.
Rail road switch heaters are used to avoid the formation of snow and ice on top of rail road switches during the cold season, in order to guarantee their correct functioning. Effective management of the energy consumption of these devices is important to reduce the costs and minimise the environmental impact. While doing so, it is critical to guarantee the reliability of the system.In this work we analyse reliability and energy consumption indicators for a system of (remotely controlled) rail road switch heaters by developing and solving a stochastic model-based approach based on the Stochastic Activity Networks (SAN) formalism. An on-off policy is considered for heating the switches, with parametric thresholds of activation/deactivation of the heaters and considering different classes of priority.A case study has been developed inspired by a real rail road station, to practically demonstrate the application of the proposed approach to understand the impact of different thresholds and priorities on the indicators under analysis (probability of failure and energy consumption). (C) 2016 Published by Elsevier Ltd.
In Computer Science, an emulator is hardware or software or both that duplicates (or emulates) the functions of one computer system (the guest) in another computer system (the host), different from the first one, so that the emulated behavior closely resembles the behavior of the real system (the guest). The computer systems are an affected by software and hardware fault, solved in numerous mechanisms to handle. Fault injection is the method of testing such mechanisms, by providing artificial faults and errors (intending to mimic real faults and errors as closely as possible) in order to activate fault handling components. An emulator is object oriented software systems are used for fault emulation. In this paper first, the software components or classes are identified for fault injection by using the calculation is cohesion metrics. If the class is highly cohesive then that software component or class is used for fault emulation. In existing approaches cohesion measured from only structural information. Disadvantage is lack of high cohesion and lacking of measurement in cohesion. Here we propose unstructured information for cohesion measurement so achieving high cohesion and using this, accurate fault prediction can be performed.
Domenico Cotroneo合作论文数University of Napoli Federico II;Computer Engineering ;Dipartimento di Informatica e Sistemistica4
Gabriele Costa合作论文数IIT-CNR3
Andy D Pimentel合作论文数Computer Systems Architecture group;University of Amsterdam;Informatics Institute2