The relationships between safety and security
Description
Safety and security have long been considered as independent issues, and dealt with by separated communities. In fact, they share substantial commonalities that have already supported several reciprocal inspirations on methodological, technological or architectural aspects. Nevertheless, the exchanges between the associated communities are still very limited and the potential for cross-fertilization is still significant. Moreover, the convergence of safety and security requirements and measures on the same systems is a recent phenomenon with consequences which are still to be mastered. This thesis deals with the relationships between safety and security covering both the cross-fertilization on a methodological point of view and the consequences of their convergence. It has led to three main contributions: - The SEMA referential framework, which helps to make the latent differences underlying the use of the terms 'security' and 'safety' explicit by a simple graphical notation; - The adaptation of the BDMP formalism from the safety area to security, providing an attractive trade-off between readability and modeling power in attack modeling; - A new approach, based on BDMP, enabling graphical representation, qualitative and quantitative analysis of situations combining safety and security risks. For each contribution, several possible enhancements and alternatives have been identified, which will make sense as the safety and the security communities strengthen their links. Beyond the contributions, this Ph.D. thesis aims at being both a manifestation and an invitation for such a rapprochement. (author)
Abstract (French)
Historiquement separees, surete et securite sont pourtant deux problematiques intimement liees. Si les trop rares initiatives de decloisonnement, adaptant notamment des outils d'un domaine a l'autre, ont abouti a des resultats convaincants, ce decloisonnement reste encore timide et son potentiel considerable. De plus, la recente convergence de risques de securite et de surete implique des interactions inedites entre exigences et mesures auparavant distinctes, dont la caracterisation necessite une perspective globale. Dans ces conditions, ces travaux de these ont d'abord vise a mieux cerner les notions de surete et de securite. Ils ont conduit a un cadre referentiel denomme SEMA (Systeme-Environnement Malveillant-Accidentel) permettant de positionner ces concepts l'un par rapport a l'autre selon les contextes. La complementarite des outils de chaque discipline a ensuite ete exploree. Cette demarche s'est concretisee par l'adaptation des BDMP (Boolean logic Driven Markov Processes), issus de la surete, au domaine de la modelisation graphique d'attaques. Ils permettent de depasser bien des limites des techniques classiquement employees. Enfin, l'extension des BDMP a ete mise a profit pour fournir un formalisme integratif, permettant de capturer graphiquement et de caracteriser des situations ou risques surete et securite s'exercent conjointement. Pour chacune de ces trois contributions, limites, ameliorations et voies alternatives ont ete identifiees. Elles n'auront sens que si les communautes de la surete et de la securite accentuent leur rapprochement, dont cette these se veut a la fois une manifestation et une invitation. (auteur)Files
54049232.pdf
Files
(8.1 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:f252d4384eabdadbb84b0ec285eece98
|
8.1 MB | Preview Download |
Additional details
Additional titles
- Original title (French)
- Des relations entre surete et securite
Publishing Information
- Imprint Pagination
- 190 p.
- Report number
- FRNC-TH--14275
INIS
- Country of Publication
- France
- Country of Input or Organization
- France
- INIS RN
- 54049232
- Subject category
- S22: GENERAL STUDIES OF NUCLEAR REACTORS;
- Resource subtype / Literary indicator
- Thesis
- Descriptors DEI
- ALGORITHMS; CYBER ATTACKS; FAILURE MODE ANALYSIS; FAULT TREE ANALYSIS; KNOWLEDGE BASE; MARKOV PROCESS; PROBABILISTIC ESTIMATION; RELIABILITY; RISK ASSESSMENT; SAFETY; SECURITY; SENSITIVITY ANALYSIS; VULNERABILITY
- Descriptors DEC
- CALCULATION METHODS; CRIME; MATHEMATICAL LOGIC; SABOTAGE; STOCHASTIC PROCESSES; SYSTEM FAILURE ANALYSIS; SYSTEMS ANALYSIS
Optional Information
- Notes
- 556 refs.; Available from the INIS Liaison Officer for France, see the INIS website for current contact and E-mail addresses