Realizing the benefits of safety-security co-analysis through effective tool support
RUBICON aims to develop a proof-of-concept software tool for integrated safety-security risk analysis in technology, enhancing decision-making through advanced algorithms and multi-objective optimization.
Projectdetails
Introduction
Effective tool support for the joint analysis of safety and security risks is long overdue.
Importance of Risk Management
Risk management is an important activity to ensure the reliable functioning of technology, such as power plants and self-driving cars. Risks include both safety (accidental failures) and security aspects (malicious attacks). Historically, safety and security risks have been analyzed in isolation, despite often conflicting with each other.
Effective decision-making requires considering safety and security risks in combination, as measures that increase safety may decrease security and vice versa.
CAESAR Framework
My Consolidator Grant CAESAR has laid out the groundwork for a safety-security co-analysis framework:
- A graphical risk model, mapping how vulnerabilities and failures propagate and cause system-level disruptions.
- Efficient algorithms to compute risk metrics, indicating how well a system performs in terms of safety-security.
- Algorithms that quantify the uncertainty of the analysis algorithms.
RUBICON Project Goals
In RUBICON, I will develop a proof-of-concept (PoC) software tool that supports methods from CAESAR, advancing from TRL1 to TRL3. Key challenges to be tackled include:
- Scaling up analysis methods to handle industry-size problems by tailoring algorithms to work with specific subclasses that appear in practice.
- Improving the interpretability of calculated outcomes. We will develop diagnostic feedback methods based on counterexample analysis and importance factors.
- Multi-objective optimization techniques. When dealing with multiple, interdependent parameters, conflicting requirements often arise due to resource constraints and varying priorities. RUBICON will develop optimal strategies to effectively balance such conflicts, exploiting and advancing Pareto-analysis.
Testing and Commercialization
The proof-of-concept tool will be tested and validated via lab and pilot studies across different industrial domains. A serious market analysis will lay out an actionable strategy to commercialize the PoC tool post-project.
Financiële details & Tijdlijn
Financiële details
Subsidiebedrag | € 150.000 |
Totale projectbegroting | € 150.000 |
Tijdlijn
Startdatum | 1-12-2024 |
Einddatum | 31-5-2026 |
Subsidiejaar | 2024 |
Partners & Locaties
Projectpartners
- UNIVERSITEIT TWENTEpenvoerder
Land(en)
Vergelijkbare projecten binnen European Research Council
Project | Regeling | Bedrag | Jaar | Actie |
---|---|---|---|---|
Resilient and Sustainable Software SecurityThe RS³ project aims to enhance software security by developing resilient and sustainable countermeasures through innovative testing, secure compilers, attack mitigation, and hardware improvements. | ERC Consolid... | € 1.998.851 | 2023 | Details |
Breaching the boundaries of safety and intelligence in autonomous systems with risk-based rationalityThis project aims to develop a comprehensive risk-based autonomy framework for autonomous systems, enhancing safety and decision-making in marine environments through advanced modeling and human supervision. | ERC Advanced... | € 2.499.773 | 2025 | Details |
Systematic and computer-aided performance certification for numerical optimizationThe project aims to enhance theoretical foundations of numerical optimization to bridge the gap between theory and practice, developing robust algorithms and certification tools for complex applications. | ERC Starting... | € 1.497.650 | 2024 | Details |
CertiFOX: Certified First-Order Model ExpansionThis project aims to develop methodologies for ensuring 100% correctness in combinatorial optimization solutions by providing end-to-end proof logging from user specifications to solver outputs. | ERC Consolid... | € 1.999.928 | 2024 | Details |
SUrrogate measures for SAFE autonomous and connected mobilitySUperSAFE aims to develop a proactive safety evaluation method for the interaction between conventional and connected automated vehicles to enhance traffic safety and support European zero-fatality goals. | ERC Starting... | € 1.500.000 | 2023 | Details |
Resilient and Sustainable Software Security
The RS³ project aims to enhance software security by developing resilient and sustainable countermeasures through innovative testing, secure compilers, attack mitigation, and hardware improvements.
Breaching the boundaries of safety and intelligence in autonomous systems with risk-based rationality
This project aims to develop a comprehensive risk-based autonomy framework for autonomous systems, enhancing safety and decision-making in marine environments through advanced modeling and human supervision.
Systematic and computer-aided performance certification for numerical optimization
The project aims to enhance theoretical foundations of numerical optimization to bridge the gap between theory and practice, developing robust algorithms and certification tools for complex applications.
CertiFOX: Certified First-Order Model Expansion
This project aims to develop methodologies for ensuring 100% correctness in combinatorial optimization solutions by providing end-to-end proof logging from user specifications to solver outputs.
SUrrogate measures for SAFE autonomous and connected mobility
SUperSAFE aims to develop a proactive safety evaluation method for the interaction between conventional and connected automated vehicles to enhance traffic safety and support European zero-fatality goals.
Vergelijkbare projecten uit andere regelingen
Project | Regeling | Bedrag | Jaar | Actie |
---|---|---|---|---|
Integrated Safety for Deeply Embedded Systems Software (ISAFE)Het ISAFE-project ontwikkelt een geïntegreerde aanpak voor de kwalificatie van softwaretools in veiligheid kritische systemen, gericht op het voldoen aan veiligheidsstandaarden en het verbeteren van softwareontwikkeling. | Mkb-innovati... | € 160.200 | 2016 | Details |
SCCOTS: Standard Cboost Components of the ShelfCboost onderzoekt de haalbaarheid van 'plug-and-play' AI-modules om digitalisering voor MKB toegankelijker te maken. | Mkb-innovati... | € 20.000 | 2022 | Details |
Risk SignalHet project onderzoekt de haalbaarheid van een machine learning-applicatie voor het signaleren van gevaarlijke situaties in bedrijfsomgevingen om incidenten te voorkomen. | Mkb-innovati... | € 20.000 | 2021 | Details |
Risicomanager in bedrijfOntwikkeling van een innovatief risicomanagementplatform dat klanten helpt bij het begrijpen en managen van financiële en niet-financiële risico's voor betere bedrijfscontinuïteit. | Mkb-innovati... | € 169.692 | 2015 | Details |
REVOLUTIONISING INDUSTRIAL ROBOTICS WITH THE NEXT GENERATION ROBOT-SPECIFIC AI-POWERED SECURITY PLATFORMRIS is an innovative AI-based Endpoint Protection Platform designed to secure industrial robots by detecting vulnerabilities and protecting against known and unknown threats. | EIC Accelerator | € 2.499.875 | 2024 | Details |
Integrated Safety for Deeply Embedded Systems Software (ISAFE)
Het ISAFE-project ontwikkelt een geïntegreerde aanpak voor de kwalificatie van softwaretools in veiligheid kritische systemen, gericht op het voldoen aan veiligheidsstandaarden en het verbeteren van softwareontwikkeling.
SCCOTS: Standard Cboost Components of the Shelf
Cboost onderzoekt de haalbaarheid van 'plug-and-play' AI-modules om digitalisering voor MKB toegankelijker te maken.
Risk Signal
Het project onderzoekt de haalbaarheid van een machine learning-applicatie voor het signaleren van gevaarlijke situaties in bedrijfsomgevingen om incidenten te voorkomen.
Risicomanager in bedrijf
Ontwikkeling van een innovatief risicomanagementplatform dat klanten helpt bij het begrijpen en managen van financiële en niet-financiële risico's voor betere bedrijfscontinuïteit.
REVOLUTIONISING INDUSTRIAL ROBOTICS WITH THE NEXT GENERATION ROBOT-SPECIFIC AI-POWERED SECURITY PLATFORM
RIS is an innovative AI-based Endpoint Protection Platform designed to secure industrial robots by detecting vulnerabilities and protecting against known and unknown threats.