Modelling and Analysing Socio-Technical Systems
نویسندگان
چکیده
Modern organisations are complex, socio-technical systems consisting of a mixture of physical infrastructure, human actors, policies and processes. An increasing number of attacks on these organisations exploits vulnerabilities on all different levels, for example combining a malware attack with social engineering. Due to this combination of attack steps on technical and social levels, risk assessment in socio-technical systems is complex. Therefore, established risk assessment methods often abstract away the internal structure of an organisation and ignore human factors when modelling and assessing attacks. In our work we model all relevant levels of socio-technical systems, and propose evaluation techniques for analysing the security properties of the model. Our approach simplifies the identification of possible attacks and provides qualified assessment and ranking of attacks based on the expected impact. We demonstrate our approach on a home-payment system. The system is specifically designed to help elderly or disabled people, who may have difficulties leaving their home, to pay for some services, e.g., care-taking or rent. The payment is performed using the remote control of a television box with a contactless payment card (see Figure 1). When a transfer is initiated, a password is needed in order to authenticate the owner of the card.
منابع مشابه
An Integrated Model of Responsibility for the Analysis of the Dependability of Socio-Technical Systems
The notion of responsibility modelling has been proposed as a useful construct for analysing the dependability of socio-technical systems. In this paper, a semantics for the modelling of responsibility are introduced together with a notation to support the construction of responsibility models, both for planning, and for observation activities such as ethnographic studies.
متن کاملDavid Greenwood PhD thesis
.................................................................................................................iv Contents...................................................................................................................v 1. Thesis Overview..................................................................................................1 1.1 Introduction.....................
متن کاملAgent-Based Modelling of Socio-Technical Systems (Agent-Based Social Systems) by Koen H. van Dam, Igor Nikolic and Zofia Lukszo (eds.)
agent based modelling of socio technical systems agent agent-based modeling and analysis of socio-technical systems capturing socio-technical systems with agent-based human behaviour modelling in complex sociotechnical agent-based social systems springer agent based modeling of large-scale socio-technical metal substantiating agent-based quality goals for understanding chapter 9 next steps in m...
متن کاملLinking Business Modelling to Socio- Technical System Design Linking Business Modelling to Socio-technical System Design
Few methods address analysis of socio-technical system requirements. This paper describes a method for analysing dependencies between computer systems and users/stakeholders in the operational environment. Domain scenarios describing the system and its context are used to create an environment model based on the i* notation. A method is proposed to define business organisational relationships, ...
متن کاملSecurity Requirements Engineering with STS-Tool
In this chapter, we present STS-Tool, the modelling and analysis support tool for STS-ml, an actorand goal-oriented security requirements modelling language for socio-technical systems. STS-Tool is a standalone application written in Java and based on the Eclipse RCP Framework. It supports modelling a socio-technical system in terms of high-level primitives such as actor, goal delegation, and d...
متن کامل