© 2017-2026 Leonardo Montecchi
Conference Paper Open Access To Appear
| Authors | |
|---|---|
| Abstract | Cyber-physical systems in critical domains such as self-driven cars and unmanned aerial vehicles, involve complex interactions between safety and security concerns. Failures in CPSs such as self-driven cars are caused either by hardware/software component faults, or attacks. The identification of hazards, their risks, and root causes are addressed by Safety Engineering, e.g., using Fault Tree Analysis. On the other hand, Security Engineering addresses the identification of asset vulnerabilities, their associated external threats, risks, and causes, using Attack Tree Analysis. Although both disciplines use separate terminology, processes, and tools, they rely on a common system architecture and in the use models such as Component Fault Trees and Attack Trees to support their analyses. In the automotive domain, such analyses should be performed in alignment with guidance defined in assurance standards, e.g., ISO 26262 for funcional safety, and ISO 21434 for cybersecurity. However, existing techniques that integrate safety and security models are not fully aligned with the ISO 21434. In this paper, we introduce a novel Component Fault Attack Trees (CFAT) modeling language and visual notation, built upon Component Fault Trees and ISO 21434 concepts, for integrating safety and security analysis models. Since CFAT was built in alignment with traditional safety and security analysis formalisms and standards, it has the potential to guide engineers in the development of multi-concern analysis model-driven engineering tools. We illustrate the use of our CFAT language and visual notation to support safety and security co-analysis of an automotive system. |
| Event | XXVI Brazilian Symposium on Cybersecurity (SBSeg 2026) |
| Venue | Armação dos Búzios, RJ, Brazil |
| Date | September 1-4, 2026 (To appear) |
| Citation |
Bibtex
@inproceedings{2026SBSEG,
author = {Grechi, Victor Luiz and de Oliveira, André Luiz and Gallina, Barbara and Montecchi, Leonardo and Vaccare Braga, Rosana Teresinha},
title = {{Model-based Safety and Security Co-Analysis using Component Attack Fault Trees}},
booktitle = {XXVI Brazilian Symposium on Cybersecurity (SBSeg 2026)},
address = {Armação dos Búzios, RJ, Brazil},
date = {2026-09-01/2026-09-04},
note = {\emph{To appear}},
year = {2026}
}
Plain TextV. Grechi, A. de Oliveira, B. Gallina, L. Montecchi, R. Braga.
Model-based Safety and Security Co-Analysis using Component Attack Fault Trees.
In: XXVI Brazilian Symposium on Cybersecurity (SBSeg 2026).
Armação dos Búzios, RJ, Brazil, September 1-4, 2026.
|
© 2017-2026 Leonardo Montecchi