Case Study in Survivable Network System Analysis

Abstract : This paper presents a method for analyzing the survivability of distributed network systems and an example of its application. Survivability is the capability of a system to fulfill its mission, in a timely manner, in the presence of attacks, failures, or accidents. Survivability requires capabilities for intrusion resistance, recognition, and recovery. The Survivable Network Analysis (SNA) method builds on the Information Security Evaluation previously developed by permitting assessment of survivability strategies at the architecture level. Steps in the SNA method include system mission and architecture definition, essential capability definition, compromisable capability definition, and survivability analysis of architectural softspots that are both essential and compromisable. Intrusion scenarios play a key role in the method. SNA results are summarized in a Survivability Map which links recommended survivability strategies for resistance, recognition, and recovery to the system architecture and requirements. This case study summarizes the application and results of applying the SNA method to a subsystem of a large scale, distributed healthcare system. The study recommended specific modifications to the subsystem architecture to support survivability objectives. Positive client response to study recommendations suggests that the method can provide significant added value for ensuring survivability of system operations. As a result of this case study, the SNA method, artifacts, and lessons learned will be available to apply architectural analysis for survivability to proposed and legacy DoD distributed systems.

[1]  Nancy R. Mead,et al.  Requirements definition for survivable network systems , 1998, Proceedings of IEEE International Symposium on Requirements Engineering: RE '98.

[2]  Nancy R. Mead,et al.  Survivable Network Systems: An Emerging Discipline , 1997 .

[3]  R. Grossman,et al.  On the Line , 2008 .

[4]  Veena B. Mendiratta Assessing the reliability impacts of software fault-tolerance mechanisms , 1996, Proceedings of ISSRE '96: 7th International Symposium on Software Reliability Engineering.

[5]  Rita C. Summers Secure Computing: Threats and Safeguards , 1996 .

[6]  John D. Musa,et al.  Software reliability - measurement, prediction, application , 1987, McGraw-Hill series in software engineering and technology.

[7]  Jerome H. Saltzer,et al.  End-to-end arguments in system design , 1984, TOCS.