论文标题
使用Bowties进行相互依存的安全安全评估
Towards Interdependent Safety Security Assessments using Bowties
论文作者
论文摘要
我们提出了一种使用Bowtie图组合安全和安全评估的方法。 Bowties模型都导致了中央故障事件的原因和由该事件产生的后果,以及障碍物的障碍。 Bowties先前已被分别用于安全和安全评估,但我们建议单个模型中的统一处理可以优雅地捕获几种类型的安全性相互依存关系。我们以2021年10月的Facebook DNS关闭为例展示了我们的方法,研究了事件的链条以及导致停电的安全障碍与安全障碍之间的相互作用。
We present a way to combine security and safety assessments using Bowtie Diagrams. Bowties model both the causes leading up to a central failure event and consequences which arise from that event, as well as barriers which impede events. Bowties have previously been used separately for security and safety assessments, but we suggest that a unified treatment in a single model can elegantly capture safety-security interdependencies of several kinds. We showcase our approach with the example of the October 2021 Facebook DNS shutdown, examining the chains of events and the interplay between the security and safety barriers which caused the outage.