Analysing the Efficacy of Security Policies in Cyber-Physical Socio-Technical Systems
English
Lenzini, Gabriele[University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Mauw, Sjouke[University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) >]
Ouchani, Samir[University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
2016
Security and Trust Management - STM 2016
Barthe, Gilles
Markatos, Evangelos
Springer-Verlag
Yes
No
International
12th International Workshop on Security and Trust Management
from 26-09-2016 to 27-09-2016
Heraklion
Greece
[en] Socio-Technical Physical Systems ; Modelling Security and Policies
[en] A crucial question for an ICT organization wishing to improve its security is whether a security policy together with physical access controls protects from socio-technical threats.
We study this question formally. We model the information flow defined by what the organization's employees do (copy, move, and destroy information) and propose an algorithm that enforces a policy on the model, before checking against an adversary if a security requirement holds.