Write a Blog >>
ESEC/FSE 2021
Thu 19 - Sat 28 August 2021 Clowdr Platform
Thu 26 Aug 2021 09:20 - 09:30 - Dependability—Cyber-Physical Systems 1 Chair(s): Ritu Kapur
Thu 26 Aug 2021 21:20 - 21:30 - Dependability—Cyber-Physical Systems 1 Chair(s): Joanne M. Atlee

Cyber-physical systems (CPSs) are part of many critical infrastructures such as industrial automation and transportation systems. Thus, security incidents targeting CPSs can have disruptive consequences to assets and people. As incidents tend to re-occur, sharing knowledge about these incidents can help organizations be more prepared to prevent, mitigate or investigate future incidents. This paper proposes a novel approach to enable representation and sharing of knowledge about CPS incidents across different organizations. To support sharing, we represent incident knowledge (\emph{incident patterns}) capturing incident characteristics that can manifest again, such as incident activities or vulnerabilities exploited by offenders. Incident patterns are a more abstract representation of specific incident instances and, thus, are general enough to be applicable to various systems - different than the one in which the incident occurred. They can also avoid disclosing potentially sensitive information about an organization’s assets and resources. We provide an automated technique to \emph{extract} an incident pattern from a specific incident instance. To understand how an incident pattern can manifest again in other cyber-physical systems, we also provide an automated technique to \emph{instantiate} incident patterns to specific systems. We demonstrate the feasibility of our approach in the application domain of smart buildings. We evaluate correctness, scalability, and performance using two substantive scenarios inspired by real-world systems and incidents.

Thu 26 Aug

Displayed time zone: Athens change

09:00 - 10:00
Dependability—Cyber-Physical Systems 1Journal First / Research Papers +12h
Chair(s): Ritu Kapur University of Sannio
09:00
10m
Paper
Hazard Analysis for Human-on-the-Loop Interactions in sUAS SystemsArtifacts Available
Research Papers
Michael Vierhauser JKU Linz, Md Nafee Al Islam University of Notre Dame, Ankit Agrawal University of Notre Dame, Jane Cleland-Huang University of Notre Dame, James Mason Northrop Grumman
DOI Media Attached
09:10
10m
Paper
An Exploratory Study of Autopilot Software Bugs in Unmanned Aerial VehiclesArtifacts Available
Research Papers
Dinghua Wang University of Technology Sydney, Shuqing Li Southern University of Science and Technology, Guanping Xiao Nanjing University of Aeronautics and Astronautics, Yepang Liu Southern University of Science and Technology, Yulei Sui University of Technology Sydney
DOI
09:20
10m
Paper
Incidents Are Meant for Learning, Not Repeating: Sharing Knowledge About Security Incidents in Cyber-Physical Systems
Journal First
Faeq Alrimawi Lero - the Science Foundation Ireland Research Centre for Software, Liliana Pasquale University College Dublin & Lero, Deepak Mehta Apple, Nobukazu Yoshioka Waseda University, Bashar Nuseibeh The Open University (UK) & Lero (Ireland)
09:30
30m
Live Q&A
Q&A (Dependability—Cyber-Physical Systems 1)
Research Papers

21:00 - 22:00
Dependability—Cyber-Physical Systems 1Research Papers / Journal First
Chair(s): Joanne M. Atlee University of Waterloo
21:00
10m
Paper
Hazard Analysis for Human-on-the-Loop Interactions in sUAS SystemsArtifacts Available
Research Papers
Michael Vierhauser JKU Linz, Md Nafee Al Islam University of Notre Dame, Ankit Agrawal University of Notre Dame, Jane Cleland-Huang University of Notre Dame, James Mason Northrop Grumman
DOI Media Attached
21:10
10m
Paper
An Exploratory Study of Autopilot Software Bugs in Unmanned Aerial VehiclesArtifacts Available
Research Papers
Dinghua Wang University of Technology Sydney, Shuqing Li Southern University of Science and Technology, Guanping Xiao Nanjing University of Aeronautics and Astronautics, Yepang Liu Southern University of Science and Technology, Yulei Sui University of Technology Sydney
DOI
21:20
10m
Paper
Incidents Are Meant for Learning, Not Repeating: Sharing Knowledge About Security Incidents in Cyber-Physical Systems
Journal First
Faeq Alrimawi Lero - the Science Foundation Ireland Research Centre for Software, Liliana Pasquale University College Dublin & Lero, Deepak Mehta Apple, Nobukazu Yoshioka Waseda University, Bashar Nuseibeh The Open University (UK) & Lero (Ireland)
21:30
30m
Live Q&A
Q&A (Dependability—Cyber-Physical Systems 1)
Research Papers