skip to main content
10.1145/1413140.1413180acmotherconferencesArticle/Chapter ViewAbstractPublication PagescsiirwConference Proceedingsconference-collections
research-article

A multi-layered security architecture for modelling complex systems

Published:12 May 2008Publication History

ABSTRACT

Existing practical architectural models have been proposed with a hierarchy of layers such as Neumann's 8-layered security model. These models cannot reason about complex systems convincingly, so we need new models for systematic and faithful analysis. We have simplified Neumann's model to create a three-layer security model that can be used for understanding and reasoning about the security of complex systems and formalised to automate analysis. The three layers are the semantic (involving people and organisations), logical (computers and networks) and physical layers including the relationships and interactions between them. Our model can be used to analyse systems more systematically and holistically including human and physical factors, rather than as technical systems alone. The model is applied to examine the security of the electricity grid, which is very difficult to analyse because of its complexity. It can also model other aspects of critical infrastructure and other complex systems such as financial networks.

Skip Supplemental Material Section

Supplemental Material

References

  1. Neumann PG, "Practical Architectures for Survivable Systems and Networks", SRI International (2000), online at www.csl.sri.com/neumann/survivability.pdf.Google ScholarGoogle Scholar
  2. Howard JD and Longstaff TA, "A Common Language for Computer Security Incidents", Sandia Report SAND98--8667 (1998), online at www.cert.org/research/taxonomy_988667.pdf.Google ScholarGoogle ScholarCross RefCross Ref
  3. Day JD and Zimmermann H, "The OSI Reference Model", Proceedings of the IEEE, vol 71 (1983), pp 1334--1340.Google ScholarGoogle ScholarCross RefCross Ref
  4. Howard JD, "An Analysis of Security Incidents on the Internet", 1989--1995, PhD thesis, Carnegie-Mellon University (1997), online at www.cert.org/research/JHThesis. Google ScholarGoogle ScholarDigital LibraryDigital Library
  5. Amin M, "Balancing Market Priorities with Security Issues", IEEE Power and Energy vol 2 no 4 (2004), pp30--38.Google ScholarGoogle ScholarCross RefCross Ref
  6. Milner, R, "Pure Bigraphs: a Tutorial (Draft 7)" (2007), online at www.cl.cam.ac.uk/~rm135Google ScholarGoogle Scholar

Index Terms

  1. A multi-layered security architecture for modelling complex systems

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Other conferences
      CSIIRW '08: Proceedings of the 4th annual workshop on Cyber security and information intelligence research: developing strategies to meet the cyber security and information intelligence challenges ahead
      May 2008
      470 pages
      ISBN:9781605580982
      DOI:10.1145/1413140

      Copyright © 2008 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 12 May 2008

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • research-article

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader