In the rapidly evolving landscape of software engineering, the demand for robust and secure systems has become increasingly critical. This is especially true for self-adaptive systems due to their complexity and the dynamic environments in which they operate. To address this issue, we designed and developed the SAFT-GT toolchain that tackles the multifaceted challenges associated with ensuring both safety and security. This paper provides a comprehensive description of the toolchain's architecture and functionalities, including the Attack-Fault Trees generation and model combination approaches. We emphasize the toolchain's ability to integrate seamlessly with existing systems, allowing for enhanced safety and security analyses without requiring extensive modifications and domain knowledge. Our proposed approach can address evolving security threats, including both known vulnerabilities and emerging attack vectors that could compromise the system. As a use case for the toolchain, we integrate it into the feedback loop of self-adaptive systems. Finally, to validate the practical applicability of the toolchain, we conducted an extensive user study involving domain experts, whose insights and feedback underscore the toolchain's relevance and usability in real-world scenarios. Our findings demonstrate the toolchain's effectiveness in real-world applications while highlighting areas for future improvements. The toolchain and associated resources are available in an open-source repository to promote reproducibility and encourage further research in this field.


翻译:在软件工程快速发展的背景下,对稳健且安全系统的需求日益突显。对于自适应系统而言,由于其复杂性和动态运行环境,这一问题尤为关键。为此,我们设计并开发了SAFT-GT工具链,以应对确保安全性与安保性所面临的多重挑战。本文全面阐述了该工具链的架构与功能,包括攻击-故障树生成及模型组合方法。我们重点强调了工具链与现有系统无缝集成的能力,能够在无需大规模修改和专业知识的前提下,增强安全性与安保性分析。所提出的方法可应对不断演化的安全威胁,包括已知漏洞及可能危及系统的新型攻击向量。作为工具链的应用案例,我们将其集成至自适应系统的反馈回路中。最后,为验证工具链的实际适用性,我们开展了涵盖领域专家的广泛用户研究,其见解与反馈证实了工具链在真实场景中的相关性与可用性。研究结果展示了工具链在实际应用中的有效性,同时指出未来改进方向。该工具链及相关资源已开源,以促进成果复现并推动该领域进一步研究。

0
下载
关闭预览

相关内容

《提升生成模型的安全性与保障》博士论文
专知会员服务
12+阅读 · 4月20日
《用于建模系统攻击路径的强化学习环境》
专知会员服务
23+阅读 · 3月5日
探索大型语言模型在网络安全中的作用:一项系统综述
专知会员服务
22+阅读 · 2025年4月27日
大型语言模型网络安全综述
专知会员服务
68+阅读 · 2024年5月12日
基于模型系统的系统设计
科技导报
10+阅读 · 2019年4月25日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
20+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
VIP会员
相关主题
最新内容
乌克兰纵深打击如何重塑俄罗斯的战略选择
专知会员服务
1+阅读 · 今天12:25
俄乌战争中关于中程打击无人机部署的经验启示
专知会员服务
0+阅读 · 今天12:08
《基于强化学习的自动化红队测试》
专知会员服务
4+阅读 · 7月23日
伊朗不对称防空战略的演进
专知会员服务
4+阅读 · 7月23日
对抗环境下超视距目标打击的情报支援
专知会员服务
10+阅读 · 7月22日
相关VIP内容
《提升生成模型的安全性与保障》博士论文
专知会员服务
12+阅读 · 4月20日
《用于建模系统攻击路径的强化学习环境》
专知会员服务
23+阅读 · 3月5日
探索大型语言模型在网络安全中的作用:一项系统综述
专知会员服务
22+阅读 · 2025年4月27日
大型语言模型网络安全综述
专知会员服务
68+阅读 · 2024年5月12日
相关资讯
基于模型系统的系统设计
科技导报
10+阅读 · 2019年4月25日
相关基金
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
4+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
20+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
Top
微信扫码咨询专知VIP会员