• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Monitoring security compliance of critical processes
 
  • Details
  • Full
Options
2014
Conference Paper
Title

Monitoring security compliance of critical processes

Abstract
Enforcing security in process-aware information systems at runtime requires the monitoring of systems' operation using process information. Analysis of this information with respect to security and compliance aspects is growing in complexity with the increase in functionality, connectivity, and dynamics of process evolution. To tackle this complexity, the application of models is becoming standard practice. Considering today's frequent changes to processes, model-based support for security and compliance analysis is not only needed in pre-operational phases but also at runtime. This paper presents an approach to support evaluation of the security status of processes at runtime. The approach is based on operational formal models derived from process specifications and security policies comprising technical, organizational, regulatory and cross-layer aspects. A process behavior model is synchronized by events from the running process and utilizes prediction of expected cl ose-future states to find possible security violations and allow early decisions on countermeasures. The applicability of the approach is exemplified by a misuse case scenario from a hydroelectric power plant.
Author(s)
Rieke, R.
Repp, J.
Zhdanova, M.
Eichler, J.
Mainwork
22nd Euromicro International Conference on Parallel, Distributed, and Network-Based Processing, PDP 2014. Proceedings  
Conference
International Conference on Parallel, Distributed and Network-Based Processing (PDP) 2014  
DOI
10.1109/PDP.2014.106
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024