Methods and Tools for Railway Safety, Reliability and Security. edited by Francesco Flammini



Similar documents
Francesco Manni, Alessio Faccia Introduction to accounting. The Double Entry Bookkeeping System & a case study

How To Contact Cognome Nome

How To Write A Train Control System

Efficient Verification for Avionic Product Development

A FRAMEWORK FOR THREAT RECOGNITION IN PHYSICAL SECURITY INFORMATION MANAGEMENT

Cisco Advanced Services for Network Security

Industrial Control Systems Security Guide

Proceedings of the International Conference on Sustainable Cultural Heritage Management

Stefano Marrone assistant professor in Computer Engineering

IT Service Management Practitioner: Plan & Improve (based on ITIL ) (IPPI.EN)

Building Secure Cloud Applications. On the Microsoft Windows Azure platform

8/27/2015. Brad Schuette IT Manager City of Punta Gorda (941) Don t Wait Another Day

Implementing Large-Scale Autonomic Server Monitoring Using Process Query Systems. Christopher Roblee Vincent Berk George Cybenko

Improving SCADA Control Systems Security with Software Vulnerability Analysis

An Automated Development Process for Interlocking Software that. Cuts Costs and Provides Improved Methods for Checking Quality.

The Banks and the Italian Economy

PASTA Abstract. Process for Attack S imulation & Threat Assessment Abstract. VerSprite, LLC Copyright 2013

Design of Flexible Production Systems

A Practical Approach to Threat Modeling

SOFTWARE-IMPLEMENTED SAFETY LOGIC Angela E. Summers, Ph.D., P.E., President, SIS-TECH Solutions, LP

Safety controls, alarms, and interlocks as IPLs

Viewpoint on ISA TR Simplified Methods and Fault Tree Analysis Angela E. Summers, Ph.D., P.E., President

The Bayesian Network Methodology for Industrial Control System with Digital Technology

Cyber Security nei prodotti di automazione

Alessia Garofalo. Critical Infrastructure Protection Cyber Security for Wireless Sensor Networks. Fai della Paganella, 10-12/02/2014

Security Issues with Integrated Smart Buildings

Huawei One Net Campus Network Solution

Model-based Testing of Automotive Systems

Cisco IPS 4200 Series Sensors

Update On Smart Grid Cyber Security

Human Rights in European Criminal Law

Cyber Security R&D (NE-1) and (NEET-4)

Metrics that Matter Security Risk Analytics

MEN'S FASHION UK Items are ranked in order of popularity.

Nine partners from Italy, France, Switzerland, Norway, Israel, Sweden, Romany, with the coordination of TERN Consortium (Italy)

WORKDAY CONCEPT: EMPLOYEE SELF SERVICE

Announcement of a new IAEA Co-ordinated Research Programme (CRP)

Smart grid security analysis

Presented by Evan Sylvester, CISSP

Storage Cloud Infrastructures

Cloud security architecture

Copyright 2013 wolfssl Inc. All rights reserved. 2

Network Security A Decision and Game-Theoretic Approach

Novell. ZENworks Patch Management Design, Deployment and Best Practices. Allen McCurdy Sr. Technical Specialist

managment and mantainance of Civil Infrastructures

CONTROL LEVEL NETWORK RESILIENCY USING RING TOPOLOGIES. Joseph C. Lee, Product Manager Jessica Forguites, Product Specialist

Towards Visualising Security with Arguments

Artificial Intelligence and Politecnico di Milano. Presented by Matteo Matteucci

An approach to Web Application Penetration Testing. By: Whiskah

Statistics for Innovation

CYBER SECURITY: SYSTEM SERVICES FOR THE SAFEGUARD OF DIGITAL SUBSTATION AUTOMATION SYSTEMS. Massimo Petrini (*), Emiliano Casale TERNA S.p.A.

La Gestione delle Infrastrutture Critiche. Prof. Roberto Setola Unità di Ricerca di AUTOMATICA Facoltà Dipartimentale di Ingegneria

Technical Support. Technical Support. Customer Manual v1.1

WHITE PAPER ON SECURITY TESTING IN TELECOM NETWORK

Automated Firewall Analytics

Biometrics and Cyber Security

Information Technology

CLAC 2008 THE PERFECT CAREER Drive Change in a Changing World 6 7 June 2008 Milan REPORT

ESKISP Manage security testing

Veritas Cluster Server by Symantec

IT ASSET MANAGEMENT Securing Assets for the Financial Services Sector

Industrial Application of MultiPARTES

Magna Græcia AORtic Interventional Project (MAORI) 3rd SYMPOSIUM COMPLEX DISEASES OF THORACIC AND THORACO-ABDOMINAL AORTA.

Maintaining PCI-DSS compliance. Daniele Bertolotti Antonio Ricci

WHAT IS BUSINESS INTELLIGENCE

IBX Business Network Platform Information Security Controls Document Classification [Public]

eguide: Designing a Continuous Response Architecture 5 Steps For Windows Server 2003 End of Life Success

Quality Management. Objectives. Topics covered. Process and product quality Quality assurance and standards Quality planning Quality control

Cloud Database Storage Model by Using Key-as-a-Service (KaaS)

Testing for the Unexpected: An Automated Method of Injecting Faults for Engine Management Development

Chap 1. Software Quality Management

NIST Cybersecurity Framework Manufacturing Implementation

Eudemon1000E Series Firewall HUAWEI TECHNOLOGIES CO., LTD.

SUMMER SCHOOL. 5-9 July Professional. Learning. in a friendly. atmosphere. Con il Patrocinio del Centro Studio Malattie Vascolari

Leveraging innovative security solutions for government. Helping to protect government IT infrastructure, meet compliance demands and reduce costs

Agile and Secure: OWASP AppSec Seattle Oct The OWASP Foundation

Data Security Concerns for the Electric Grid

ParkingManagementSystems. Videobased Parking Management System INDOOR and OUTDOOR Description

Sensitivity Analysis of Safety Measures for Railway Tunnel Fire Accident

Use service virtualization to remove testing bottlenecks

Transcription:

A09 155

Methods and Tools for Railway Safety, Reliability and Security edited by Francesco Flammini

Copyright MMXII ARACNE editrice S.r.l. www.aracneeditrice.it info@aracneeditrice.it via Raffaele Garofalo, 133/A B 00173 Roma (06) 93781065 ISBN 978-88-548-4848-1 No part of this book may be reproduced by print, photoprint, microfilm, microfiche, or any other means, without publisher s authorization. I edition: June 2012

Contents 7 Preface Part I Software verification techniques 11 A Grey Box Approach to the Functional Testing of Complex Automatic Train Protection Systems Giuseppe De Nicola, Pasquale di Tommaso, Rosaria Esposito, Francesco Flammini, Pietro Marmo, Antonio Orazzo 29 The Simulation of Anomalies in the Functional Testing of the ERTMS/ETCS Trackside System Pasquale di Tommaso, Francesco Flammini, Armando Lazzaro, Raffaele Pellecchia, Angela Sanseviero 49 Modelling of Railway Logics for Reverse Engineering, Verification and Refactoring Francesco Flammini, Armando Lazzaro, Nicola Mazzocca 77 Automatic instantiation of abstract tests on specific configurations for large critical control systems Francesco Flammini, Nicola Mazzocca, Antonio Orazzo Part II Model based dependability evaluation 109 Using Repairable Fault Trees for the evaluation of design choices for critical repairable systems Francesco Flammini, Nicola Mazzocca, Mauro Iacono, Stefano Marrone 133 Modeling system reliability aspects of ERTMS/ETCS by Fault Trees and Bayesian Networks Francesco Flammini, Stefano Marrone, Nicola Mazzocca, Valeria Vittorini 5

6 Contents 155 A new modeling approach to the safety evaluation of N modular redundant computer systems in presence of imperfect maintenance Francesco Flammini, Stefano Marrone, Nicola Mazzocca, Valeria Vittorini 181 Multiformalism techniques for critical infrastructure modeling Francesco Flammini, Nicola Mazzocca, Francesco Moscato, Alfio Pappalardo, Concetta Pragliola, Valeria Vittorini Part III Security risk assessment and mitigation 207 Security Risk Management of Railway Transportation Systems Francesco Flammini, Nicola Mazzocca 225 Dependable integrated surveillance systems for the physical security of metro railways Giovanni Bocchetti, Francesco Flammini, Concetta Pragliola, Alfio Pappalardo 243 On line integration and reasoning of multi sensor data to enhance infrastructure surveillance Francesco Flammini, Andrea Gaglione, Nicola Mazzocca, Vincenzo Moscato, Concetta Pragliola 267 Formal evaluation of a majority voting concept to improve the dependability of multiple technology sensors Francesco Flammini

Methods and Tools for Railway Safety, Reliability and Security ISBN 978-88-548-4848-1 DOI 10.4399/97888548484811 pag. 7 8 (june 2012) Preface Modern rail transport systems feature an increasing level of complexity. One of the main reasons for this growth is the trend to automate delicate control and supervisory functions through heterogeneous distributed computer systems. This book aims at presenting a set of novel and advanced techniques used in real world industrial applications to improve the dependability of rail based transportation systems. The analyses address both natural/random and intentional/malicious threats (ranging from human errors, e.g. coding or maintenance mistakes, to terrorist attacks), which can compromise system integrity both at the hardware (control devices, infrastructures) and software (logic code, data network) levels. To date, most existing books only address general safety critical real time systems engineering; only a few exist covering all the subjects related to railway safety, reliability and security in a holistic and systemic fashion. On this regard, this book can be a useful reference for experts, consultants and railway system engineers who need to perform risk or dependability analyses for development or certification purposes. It also provides a collection of techniques and case studies for students of university courses about security and dependability of critical systems and infrastructures. The book is structured as a collection of self contained chapters which are (revised and extended) reprint versions of papers which I have co authored and have been recently published in proceedings of international conferences, contributed books or research journals. All the chapters refer to railway dependability either as the main application scenario or for the example case studies. More in detail, the book is organized as follows. It is divided into three main parts, each one containing 4 chapters. The first part covers verification techniques for railway control software, focusing on 7

8 Methods and Tools for Railway Safety, Reliability and Security testing approaches which can improve both the effectiveness and efficiency of the safety assessment processes. The second part surveys model based approaches to formally evaluate quantitative dependability attributes (like safety and reliability), mostly at the hardware abstraction level. Finally, part three addresses railway infrastructure security issues from the risk management perspective, including vulnerability assessment and design of protection mechanisms. Francesco Flammini