• No se han encontrado resultados

System-of-Systems (SoS) are a class of system whose interacting parts comprise systems, that are owned and managed by independent parties, and whose parts evolve over time (Maier, 1998). Typical examples are integrated supply chain management systems, integrated healthcare networks, and cyber-physical systems such as integrated embedded systems within ships, land vehicles, aircraft, or industrial plants. Coalitions-of-systems (CoS) are a sub-class of SoS that have the additional property that their subsystems interact to further overlapping self- interests rather than achieving an overarching mission/goal as in the case of

required as organisations are driven by profit and the rewards/risks will be distributed between partners so understanding these interests become important to understanding its ongoing operation.

The dependability of a system, in this context, is definable as the property of a system where “reliance can justifiably be placed on the services it delivers” (Sommerville, Dewsbury, Clarke, & Rouncefield, 2006). We define threats to dependability as events or conditions that affect a systems availability, reliability, safety, integrity, confidentiality, and maintainability (Avizienis, Laprie, Randell, & Landwehr, 2004; Sommerville et al., 2006).

Socio-technical threats are an important factor when analysing the dependability of a CoS. This is because coalition partners overlapping self-interests may be fragile and subject to change. For example, a change in a cloud provider’s interests may result in the withdrawal of certain services, or changes to their behavioural properties, thus resulting in threats to the availability, reliability and maintainability of the overall CoS. Understanding the distribution of liabilities among coalition partners is also important to understanding CoS as this provides an indicator of consequences of a partner’s action and its implications for their interests. For instance, in resource constrained situations coalition partners that seek to further their self-interest by generating profit will fulfil responsibilities with large liabilities and renege on those where the liability is small.

There are a number of candidate socio-technical modelling approaches relevant to identifying and assessing dependability threats. Recently there has been a trend for agent goal model based frameworks such as I* (E. Yu et al., 2011) and the TROPOS Goal-Risk framework (Asnar & Giorgini, 2007), however this thesis advocates an agent responsibility based identification approach. Below we provide an overview of agent goal based modelling approaches prior to distinguishing them from our agent responsibility based approach (Lock et al., 2009; Sommerville et al., 2009).

The I* framework has been extended by (Maiden & Jones, 2004; Maiden et al., 2006; Mayer et al., 2007) in order to identify dependability threats and requirements for air traffic management (ATM) and enterprise systems. In the context of ATM this was achieved by means of exploring the consequences of one actor fulfilling two or more roles and whether this affects the system’s overall goal attainment (Maiden & Jones, 2004; Maiden et al., 2006). This work primarily focused on identifying system dependability related to overloading operators. In the context of enterprise systems, threats to security goals were identified by modelling and discovering business assets, constraints and security requirements. This work primarily focused on gathering security requirements and transforming these requirements into high-level controls.

The TROPOS Goal-Risk framework was used in (Asnar & Giorgini, 2007; Asnar et al., 2008) as an approach to analyse and mitigate threats to the goal accomplishment in an ATM system and a manufacturing organisation. The systems under analysis were modelled as a configuration of related goals, tasks and events. The framework comprises a goal layer representing the goals of actors

that should be achieved, an event layer that represents potential threats to goals, and a treatment layer that comprises possible threat management strategies. This approach primarily focuses on the analysis of threats and the design of appropriate high level controls rather than their identification.

Despite the agent responsibility abstraction having some similarities to goal modelling based approaches it differs significantly. Responsibility modelling uses the concept of responsible agents (human / organisational agents) and their interactions to represent a situation and identify hazards in terms of failures of agents to fulfil responsibilities. The concept of responsibility foregrounds notions of obligations, liabilities, and conformance to norms, or standards, such that it is important how an agent acts. For example, a doctor that has performed procedures in accordance with legal and domain standards may have successfully discharged their responsibility for patient care even if their patient dies. Similarly if a patient lives but their treatment was unethical then the doctor will be held accountable. Unlike responsibilities, goals principally focus on what has to be achieved.

The responsibility modelling based approach offers a number of attractive characteristics that may make it suitable for identifying threats to CoS. Firstly the agent responsibility abstraction provides a natural way of identifying the threats associated with relying on other parties to discharge responsibilities. Secondly responsibilities are relatively unproblematic to elicit as people find them ‘natural’ to articulate in comparison to ‘technical’ constructs such as functions or goals. Thirdly responsibility modelling is relatively rapid to perform as, unlike typical goal based identification approaches, tasks and their dependencies are not elicited. The responsibility modelling approach presented here is primarily a threat/risk identification technique and should be viewed as complementary to the previous approaches discussed and more general threat/risk analysis approaches such as CORAS (Braber et al., 2003). Responsibility modelling has been used to analyse the failure of socio-technical systems including E-counting systems in the Scottish elections and UK civil emergency planning (Lock et al., 2009; Sommerville et al., 2009).

Documento similar