Rule‐based Verification of System Security using Feature‐Based Product Line Engineering
James K. Teaff · Insight · 2020
ABSTRACT Systems security engineering is a discipline to engineer a system of interest ensuring system functionality under disruptive conditions associated with misuse and malicious behavior. Today's cyber‐physical systems must survive in a constantly changing threat environment. Cybersecurity controls and cyber resiliency capabilities require continuous delivery to meet this challenge. This article describes creating and using a rule base as an integral part of a systems and software product line engineering (PLE) factory enabling continuous resilient and secure cyber‐physical systems delivery ensuring the system can function under disruptive conditions. A hypothetical intelligence gathering network comprising unmanned vehicles, a ground control segment, and an intelligence analytics segment is the system of interest. Systems engineering activities include continuously analyzing the cyber‐attack surface for each system variant in the product portfolio; creating or amending cyber resiliency capabilities and cybersecurity controls for each system variant addressing each attack vector; and a living rule base maintained within a PLE factory ensuring each system variant automatically generated by the factory contains the requisite system capabilities. Applying this approach results in rule‐based verification of continuously delivered cyber resiliency capabilities and cybersecurity controls for each fielded system variant. Moving at the speed of mission need is essential, and automated rule‐based verification of system deliveries meets that need.