Show simple item record

dc.contributor.authorJahan, Sharmin
dc.date.accessioned2023-10-12T14:56:51Z
dc.date.available2023-10-12T14:56:51Z
dc.date.issued2020-04-06
dc.identifieroksd_jahan_mape-k_mape-sac_2020
dc.identifier.citationJahan, S. (2020). MAPE-K/MAPE-SAC: An interaction framework for adaptive systems with security assurance cases. Future Generation Computer Systems, 109(0167-739X), 197-209. https://doi.org/10.1016/j.future.2020.03.031
dc.identifier.issn0167-739X
dc.identifier.urihttps://hdl.handle.net/11244/339844
dc.description.abstractSecurity certification establishes that a given system satisfies properties and constraints as specified in the system security profile. Mechanisms and techniques have been developed to assess if and how well the system complies with the properties, thereby providing a degree of confidence in the security certification. Generally, certification of security controls defined by NIST SP800-53 is performed at design time to provide confidence in a system’s trustworthiness to achieve the organization’s mission and business requirements. Assuring confidence in a self-adaptive system’s security profile is challenging when both functional and security conditions may change at run time. Static security solutions are insufficient, given that dynamic application of defense mechanisms often needs to dynamically adapt security functionality at run time as part of self-protection. This security adaptation may hinder maintaining functional constraints or vice versa. In addition, adaptation capabilities may give rise to the need for dynamic certification, which can be a difficult procedure given the complexity of the security dependencies. Confidence in an information system’s compliance with security constraints can be expressed using security assurance cases (SACs). NIST security controls are defined with a hierarchical structure that makes them amenable to being specified in terms of SACs. A collection of SACs for related security controls form a network that can be used to measure the confidence of security compliance through certification-based evidence. Once the system is deployed, environmental and functional uncertainties may require the coordination of functional and security adaptations. This paper introduces the MAPE-SAC, a security-focused feedback control loop, and its interaction with a MAPE-K, function and performance-focused control loop, to dynamically manage run-time adaptations in response to changes in functional and security conditions. We illustrate the use of both control loops and their interaction with an example of two independent systems that need to cooperate to facilitate autonomous search and rescue in the aftermath of a natural disaster.
dc.formatapplication/pdf
dc.languageen_US
dc.publisherElsevier
dc.relation.ispartofFuture Generation Computer Systems, 109 (0167-739X)
dc.rightsThis material has been previously published. In the Oklahoma State University Library's institutional repository this version is made available through the open access principles and the terms of agreement/consent between the author(s) and the publisher. The permission policy on the use, reproduction or distribution of the material falls under fair use for educational, scholarship, and research purposes. Contact Digital Resources and Discovery Services at lib-dls@okstate.edu or 405-744-9161 for further information.
dc.titleMAPE-K/MAPE-SAC: An interaction framework for adaptive systems with security assurance cases
dc.date.updated2023-10-11T14:49:56Z
dc.noteopen access status: Hybrid OA
osu.filenameoksd_jahan_mape-k_mape-sac_2020.pdf
dc.identifier.doi10.1016/j.future.2020.03.031
dc.description.departmentComputer Science
dc.type.genreArticle
dc.type.materialText
dc.subject.keywordsinformation and computing sciences
dc.subject.keywordscybersecurity and privacy
dc.subject.keywordscomputer software
dc.subject.keywordsdistributed computing
dc.subject.keywordsinformation systems
dc.subject.keywordsdata management and data science
dc.subject.keywordsdistributed computing and systems software
dc.identifier.authorORCID: 0000-0003-1306-4591 (Jahan, Sharmin)
dc.identifier.authorScopusID: 1941703 (Jahan, Sharmin)


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record