About

Log in?

DTU users get better search results including licensed content and discounts on order fees.

Anyone can log in and get personalized features such as favorites, tags and feeds.

Log in as DTU user Log in as non-DTU user No thanks

DTU Findit

Conference paper

Modelling and Analysing Socio-Technical Systems

In Ceur Workshop Proceedings 2015, pp. 121-124
From

Department of Applied Mathematics and Computer Science, Technical University of Denmark1

Language-Based Technology, Department of Applied Mathematics and Computer Science, Technical University of Denmark2

Modern organisations are complex, socio-technical systems consisting of a mixture of physical infrastructure, human actors, policies and processes. An in-creasing number of attacks on these organisations exploits vulnerabilities on all different levels, for example combining a malware attack with social engineering.

Due to this combination of attack steps on technical and social levels, risk assessment in socio-technical systems is complex. Therefore, established risk assessment methods often abstract away the internal structure of an organisation and ignore human factors when modelling and assessing attacks. In our work we model all relevant levels of socio-technical systems, and propose evaluation techniques for analysing the security properties of the model.

Our approach simplifies the identification of possible attacks and provides qualified assessment and ranking of attacks based on the expected impact. We demonstrate our approach on a home-payment system. The system is specifically designed to help elderly or disabled people, who may have difficulties leaving their home, to pay for some services, e.g., care-taking or rent.

The payment is performed using the remote control of a television box with a con-tactless payment card (see Figure 1). When a transfer is initiated, a password is needed in order to authenticate the owner of the card.

Language: English
Year: 2015
Pages: 121-124
Proceedings: 1st International Workshop on Socio-Technical Perspective in IS Development (STPIS'15)
Series: Ceur Workshop Proceedings
ISSN: 16130073
Types: Conference paper
ORCIDs: Nielson, Flemming and Probst, Christian W.

DTU users get better search results including licensed content and discounts on order fees.

Log in as DTU user

Access

Analysis