ORCID

Shiu-Kai Chin 0009-0007-5318-923X

Document Type

Report

Date

2018

Keywords

Systems Security Engineering (SSE), STORM (System-Theoretic and Technical Operational Risk Management), STPA-Sec (System-Theoretic Process Analysis for Security), Certified Security by Design (CSBD), Concept of Operation (CONOPS), Secure state machines, Complete mediation, Access-control logic, Higher-Order Logic (HOL) / formal verification, Mission assurance

Language

English

Funder(s)

Air Force Research Laboratory

Funding ID

FA8750-16-C-0308

Acknowledgements

This work was partially supported by the Air Force Research Laboratory contract 

FA8750-16-C-0308

Disciplines

Systems Engineering

Description/Abstract

STORM (System-Theoretic and Technical Operational Risk Management) is a systems security engineering (SSE) methodology for assuring missions and managing risk. Fully consistent with the System Security Engineering principles and objectives as described in NIST SP 800-160, STORM addresses the shortcomings of compliance-centric approaches by providing rigorous, behavior-focused tools applicable at both leadership and technical levels.

STORM integrates two principal components: STPA-Sec (System-Theoretic Process Analysis for Security) and CSBD (Certified Security by Design). STPA-Sec is used to derive and validate a mission Concept of Operation (CONOPS) by enumerating unacceptable losses, identifying hazards and unsafe control actions, and identifying security constraints. CSBD takes a mission-validated CONOPS, formally defines security constraints as security policies in an access-control logic, and formally verifies defines secure behavior in the form of a secure state machine (SSM). The access-control logic is a propositional modal logic with Kripke semantics. All SSM actions are completely mediated — all actions are executed if and only if they are authenticated and authorized. Formal proofs are machine-checked and are conservative extensions to the HOL-4 theorem prover.

STORM is implementation-agnostic, parametric, higher-order, tailorable, and scalable. Its application is demonstrated through a UAV Payload Controller for an air interdiction mission, proceeding from mission statement through formally verified secure state machine. STORM has been successfully applied to additional cases including a secure memory loader for F-16 aircraft and a networked thermostat, and has been taught to DoD personnel and university students at both undergraduate and graduate levels.

Creative Commons License

Creative Commons Attribution 4.0 International License
This work is licensed under a Creative Commons Attribution 4.0 International License.

Share

COinS