Authors:
Tithnara Nicolas Sun
1
;
Bastien Drouot
1
;
Fahad R. Golra
1
;
Joël Champeau
1
;
Sylvain Guerin
1
;
Luka Le Roux
1
;
Raúl Mazo
2
;
1
;
Ciprian Teodorov
1
;
Lionel Van Aertryck
3
and
Bernard L’Hostis
3
Affiliations:
1
Lab STICC UMR6285, ENSTA Bretagne, Brest, France
;
2
GIDITIC, Universidad EAFIT, Medellin, Colombia
;
3
DGA-MI, Bruz, France
Keyword(s):
Attack Surface Modeling, Model Federation, DSL, Modeling, Cyber Security.
Abstract:
Cybersecurity is becoming vital as industries are gradually moving from automating physical processes to a higher level automation using cyber physical systems (CPS) and internet of things (IoT). In this context, security is becoming a continuous process that runs in parallel to other processes during the complete life cycle of a system. Traditional threat analysis methods use design models alongside threat models as an input for security analysis, hence missing the life-cycle-based dynamicity required by the security concern. In this paper, we argue for an attacker-aware systems modeling language that exposes the systems attack surfaces. For this purpose, we have designed Pimca, a domain specific modeling language geared towards capturing the attacker point of view of the system. This study introduces the formalism along with the Pimca workbench, a framework designed to ease the development and manipulation of the Pimca models. Finally, we present two relevant use cases, serving as
a preliminary validation of our approach.
(More)