Title :
A Systems Dynamics View of Security Assurance Issues: "The Curse of Complexity and Avoiding Chaos"
Abstract :
ISA 99 defines security assurance as the target level of security that corresponds to the effectiveness of countermeasures to thwart cyber attacks against industrial automation systems. ISA intends to provide a scale of target levels of security which asset owners can then use to establish a minimum set of operational requirements. Each set is designed to protect selected zones or conduits against access to and use of devices, systems and data. Sounds good, but the complexities of this approach are exposed when the mathematics of the proposed model are well understood. In this paper a notional time/event model is used to describe the temporal characteristics of security assurance and the need to account for time dynamics and event dynamics. Because of the complexities, the common approach is to implement defense-in-depth mechanisms. Using a systems dynamics model, this paper shows why such mechanisms may make matters worse by significantly degrading the security assurance level.
Keywords :
Unified Modeling Language; chaos; formal specification; object-oriented methods; security of data; chaos; countermeasure; defense-in-depth mechanism; event dynamics; formal specification; industrial automation system; object-oriented modeling; security assurance level; target level; thwart cyber attack; time dynamics; unified modeling language; Chaos; Communication system security; Computer security; Data security; Degradation; Instruction sets; Mathematics; NIST; Power system security; Uncertainty;
Conference_Titel :
System Sciences, 2009. HICSS '09. 42nd Hawaii International Conference on
Conference_Location :
Big Island, HI
Print_ISBN :
978-0-7695-3450-3
DOI :
10.1109/HICSS.2009.41