Visible to the public Modelling User Availability in Workflow Resiliency AnalysisConflict Detection Enabled

TitleModelling User Availability in Workflow Resiliency Analysis
Publication TypeConference Paper
Year of Publication2015
AuthorsJohn C. Mace, Newcastle University, Charles Morisset, Newcastle University, Aad Van Moorsel, Newcastle University
Conference NameSymposium and Bootcamp on the Science of Security (HotSoS)
PublisherACM
Conference LocationUrbana, IL
KeywordsData-Driven Model-Based Decision-Making, Markov Decision Process, NSA SoS Lablets Materials, Probabilistic Model Checker, science of security, simulation, UIUC, Workflow Satisfiability Problem
Abstract

Workflows capture complex operational processes and include security constraints limiting which users can perform which tasks. An improper security policy may prevent cer- tain tasks being assigned and may force a policy violation. Deciding whether a valid user-task assignment exists for a given policy is known to be extremely complex, especially when considering user unavailability (known as the resiliency problem). Therefore tools are required that allow automatic evaluation of workflow resiliency. Modelling well defined workflows is fairly straightforward, however user availabil- ity can be modelled in multiple ways for the same workflow. Correct choice of model is a complex yet necessary concern as it has a major impact on the calculated resiliency. We de- scribe a number of user availability models and their encod- ing in the model checker PRISM, used to evaluate resiliency. We also show how model choice can affect resiliency computation in terms of its value, memory and CPU time.

URLhttp://publish.illinois.edu/science-of-security-lablet/files/2014/05/Modelling-User-Availablity-in-W...
Citation Keynode-23237

Other available formats:

Modelling User Availablity in Workflow Resiliency Analysis
AttachmentSize
bytes