This paper describes a simulation-based approach for automated risk assessment of complex cyber-physical systems to support implementers of ISO 27005. The approach is based on systematic cause-and-effect modelling of threats, their causes and effects, and the ways in which the effects of one threat can lead to other threats. In this way, the approach deals with inter-dependencies within the target system, automatically finding attack paths and secondary effect cascades, which generally are very complex and the source of many challenges when implementing ISO 27005. The approach uses a knowledgebase describing classes of system assets and their possible relationships, along with the associated threats, causes and effects in a generic context. A target system can then be modelled in terms of related assets, describing the intended system structure and purpose (in the absence of any deviations). The knowledgebase is then used to identify which threats are relevant and create a cause-and-effect simulation of those threats. This allows threat likelihoods and risk levels to be found based on input concerning trust assumptions and the presence of controls in the system. The approach has been implemented by the open source Spyderisk project and validated by modelling a published case study of an attack on a steel mill. Given reasonable assumptions about security controls in place, the shortest, highest likelihood attack path found coincides with the published analysis. The case study demonstrates the strengths of the approach: transparency, reproducibility, and performance.
This paper describes next generation modeling tools to solve a basic problem of concept analysis, which is the lack of component models that realistically estimate the performance of technology that has yet to be fully reduced to specific products. Three important classes of electric power components essential to future Army vehicles are addressed: integrated electric machines, battery energy storage, and traction motor drives. Behavior models are delivered in a common software simulation “wrapper” with a limited number of user settings that allow the ratings of the component to be scaled to the performance required by the vehicle concept represented in a larger simulation. This approach captures expert knowledge about components so the systems engineer managing the concept analysis can create reliable simulations quickly.
Abstract Background Prehospital stroke trials will inevitably recruit patients with non-stroke conditions, so called stroke mimics. We undertook a pre-specified analysis to determine outcomes in patients with mimics in the second Rapid Intervention with Glyceryl trinitrate in Hypertensive stroke Trial (RIGHT-2). Methods RIGHT-2 was a prospective, multicentre, paramedic-delivered, ambulance-based, sham-controlled, participant-and outcome-blinded, randomised-controlled trial of transdermal glyceryl trinitrate (GTN) in adults with ultra-acute presumed stroke in the UK. Final diagnosis (intracerebral haemorrhage, ischaemic stroke, transient ischaemic attack, mimic) was determined by the hospital investigator. This pre-specified subgroup analysis assessed the safety and efficacy of transdermal GTN (5 mg daily for 4 days) versus sham patch among stroke mimic patients. The primary outcome was the 7-level modified Rankin Scale (mRS) at 90 days. Results Among 1149 participants in RIGHT-2, 297 (26%) had a final diagnosis of mimic (GTN 134, sham 163). The mimic group were younger, mean age 67 (SD: 18) vs 75 (SD: 13) years, had a longer interval from symptom onset to randomisation, median 75 [95% CI: 47,126] vs 70 [95% CI:45,108] minutes, less atrial fibrillation and a lower systolic blood pressure and Face-Arm-Speech-Time tool score than the stroke group. The three most common mimic diagnoses were seizure (17%), migraine or primary headache disorder (17%) and functional disorders (14%). At 90 days, the GTN group had a better mRS score as compared to the sham group (adjusted common odds ratio 0.54; 95% confidence intervals 0.34, 0.85; p = 0.008), a difference that persisted at 365 days. There was no difference in the proportion of patients who died in hospital, were discharged to a residential care facility, or suffered a serious adverse event. Conclusions One-quarter of patients suspected by paramedics to have an ultra-acute stroke were subsequently diagnosed with a non-stroke condition. GTN was associated with unexplained improved functional outcome observed at 90 days and one year, a finding that may represent an undetected baseline imbalance, chance, or real efficacy. GTN was not associated with harm. Trial registration This trial is registered with International Standard Randomised Controlled Trials Number ISRCTN 26986053 .
Frank c. LamBert President Georgia Tech-NEETRAC, USA JeSSica J. Bian President-Elect Grid-X Partners, USA SaiFur rahman Immediate Past President Virginia Tech, USA BaBak enayati VP Education National Grid, USA Wayne a. BiShoP Jr. VP Meetings OMICRON, USA mazana armStrong VP Chapters Powertech Labs, Canada JuLio romero aguero VP Membership & Image Quanta Technology, USA viJay vittaL VP Technical Activities Arizona State University, USA BikaSh PaL VP Publications Imperial College London, UK Shay Bahramirad VP New Initiatives/Outreach ComEd, USA nouredine hadJSaid Treasurer Grenoble Institute of Technology, France Jonathan SykeS Secretary Schweitzer Engineering Laboratories, New Mexico cLaudio canizareS Division VII Director-Elect University of Waterloo, ECE, Canada OFFICERS AND VICE PRESIDENTS OF CO-SPONSORING SOCIETIES
applied to control, treatment, and measurement of industrial processes.
As digital information has come to underpin the majority of modern systems in almost all domains (e.g. business, finance, government, education, health, third sector), increasingly sophisticated cybersecurity attacks have become an unavoidable reality of modern life. In the face of this, regulation and best practice are increasing moving from simplistic security control tick-lists towards risk management frameworks (such as recommended in the EU's GDPR and NIS directive and described in standards such as ISO 27005). Consequently, it is highly relevant for students, practitioners, and researchers alike to understand risk management, systems modelling, attack paths, and human interactions and risks in order to understand the central value and importance of cybersecurity risk management in supporting trustworthiness in information systems. As part of the H2020 CyberKit4SME project, this interactive, hands-on tutorial will explore state-of-the-art approaches to trustworthy cybersecurity risk management that is able to effectively and sufficiently account for the risks that humans introduce into any information system [1]. After establishing the basic concepts around cybersecurity, trustworthiness, system modelling, risk management and socio-technical theory, an exploration of the importance and role of visualised attack paths in providing easily understood risks, thereby ensuring intelligent risk management tools do not become `black boxes' to their users, will be undertaken. Alongside this, how attack paths help support human decision-making by pinpointing the most effective risk mitigation strategies will be investigated. In addition, the tutorial will explore human interaction flows and how they can combine with attack paths to empower comprehensive cybersecurity risk assessments and help guide holistic mitigations. In the final part of the tutorial, there will be an opportunity to get practical experience of modelling an information system and identifying and mitigating the cybersecurity risks to it using two tools: the System Security Modeller [2, 3] (University of Southampton) and the Human and Organisational Risk Modelling framework (SINTEF) which is derived from the Customer Journey Modelling Language [4, 5] (CJML).
development, design, manufacture, and application of electrical systems, apparatus, devices, and controls to the processes and equipment of industry and commerce; the promotion of safe, reliable, and economic installations; industry leadership in energy conservation and environmental, health, and safety issues; the creation of voluntary engineering standards and recommended practices; and the professional development of its membership.