The “Mission Aware” Concept for Design of Cyber-Resilience
Abstract
This chapter introduces the Mission Aware framework, which is a proactive, model-based, and strategic approach to cybersecurity. Mission Aware is an outcome of work in the SERC's Trusted Systems research area with the aim of creating tools and methods to support engineering and testing of cyber-resilient cyber-physical systems. Mission Aware aims to provide a framework for designing systems that are resilient against cyberattacks. The framework focuses on the use of engineered mechanisms for detecting and responding to potential cyberattacks. During the early conceptual and requirements phases, patterns for these engineered mechanisms can be specified using model-based systems engineering (MBSE) techniques and used as a basis for requirements, architecting, design, and provisioning for verification and validation activities. This approach is primarily applied in cyber-physical systems, such as vehicles and weapons systems, rather than pure cyber and networking systems. Mission Aware is meant to be used in concert with the System Theoretic Processes Assessment (STPA) and variants from the safety community, as well as the Cyber Security Requirements Methodology (CSRM) and Framework for Operational Resilience in Engineering and System Test (FOREST) developed by SERC. Each of these companion methodologies are covered by a chapter in this cluster.
Leads
Peter A. Beling
Virginia Polytechnic Institute and State University
Megan M. Clifford
Stevens Institute of Technology
Tim Sherburne
Stevens Institute of Technology
Tom A. McDermott
Stevens Institute of Technology
Barry M. Horowitz
University of Virginia
Publications
Beling , P. , Horowitz , B. , Fleming , C. , et al. ( 2019 ). Model-Based Engineering for Functional Risk Assessment and Design of Cyber Resilient Systems . University of Virginia Charlottesville United States, Technical Report .
Beling , P. , McDermott , T. , Sherburne , T. , et al. ( 2021 ). Developmental Test and Evaluation and Cyberattack Resilient Systems . Systems Engineering Research Center, Technical Report .
Beling , P. , Sherburne , T. , and Horowitz , B. ( 2023 ). Sentinels for cyber resilience, in autonomous intelligent agents for cyber defense . Springer 87 : 425 – 444 . [forthcoming].
Biesecker , C . ( 2017 ). Boeing 757 testing shows airplanes vulnerable to hacking, DHS says .
Horowitz , B. , Beling , P. , Skadron , K. , et al. ( 2014 ). Security Engineering Project-System Aware Cyber Security for an Autonomous Surveillance System on Board an Unmanned Aerial Vehicle . Systems Engineering Research Center, Hoboken, NJ, Technical Report .
Horowitz , B. , Beling , P. , Humphrey , M. , and Gay , C. ( 2015a ). System Aware Cybersecurity: A Multi-Sentinel Scheme to Protect a Weapons Research Lab . Stevens Institute of Technology, Hoboken, NJ, Technical Report .
Horowitz , B. , Beling , P. , Skadron , K. , et al. ( 2015b ). Security Engineering Project . Systems Engineering Research Center, Hoboken, NJ , Technical Report .
Horowitz , B. , Beling , P. , Fleming , C. , et al. ( 2017 ). Security Engineering FY17 Systems Aware Cybersecurity . Stevens Institute of Technology, Hoboken, United States, Technical Report .
Horowitz , B. , Beling , P. , Fleming , C. , et al. ( 2018 ). Cyber Security Requirements Methodology . Stevens Institute of Technology, Hoboken, United States, Technical Report .
Horowitz , B. , Beling , P. , Clifford , M. , and Sherburne , T. ( 2021 ). Developmental Test and Evaluation (DTE&A) and Cyber Attack Resilient Systems - Measures and Metrics Source Tables . Systems Engineering Research Center, Technical Report .
McDermott , T. , Fleming , C. , Clifford , M.M. et al. ( 2020 ). Methods to Evaluate Cost/Technical Risk and Opportunity Decisions for Security Assurance in Design . Stevens Institute of Technology, Systems Engineering Research Center Hoboken United States .
Young , W. and Porada , R. ( 2017 ). System-theoretic process analysis for security (STPA-Sec): cyber security and STPA . In 2017 STAMP Conference (27–30 March 2017). MIT Press .