being applied so far but they did not comply with requirements for real-time and
safety-critical applications.
Effective recovery is based on evaluating of the impact on the DCS and its
elements, applying a concept ASAP and ALAP (better from the design phase of
DCS). For DCS and its model we analyze the interdependencies of elements in
terms of thread propagation using a graph Fig. 18.2 where the elements (routers,
switches) are the vertices and edges are the links that connect the vertices.
The strength of the dependence between the vertexes is defined by the thickness
of the edges. It is also important to stress that dependencies among vertexes are not
symmetrical, this means that vertex 10 might have higher impact on vertex 7 than
vertex 7 might have on 10. In this case, dependencies in terms of problem propagation might be presented as square non-symmetrical matrix where the indices
represent the vertices and the dependencies are represented by contents, this is
illustrated [4, 5, 8, 9] in Fig. 18.2.
The propagation of thread in the network can be defined as a vector P of
predicates {p i } that represents the condition for each vertex [4]:
P ¼ p 1 m 1 v 1 d 1 ðtÞ
ð
Þ
ð
Þ
ð
Þ ; p 2 m 2 v 2 d 2 ðtÞ
ð
Þ
ð
Þ
ð
Þ ; . . .; p k m k v k d k ðtÞ
ð
Þ
ð
Þ
ð
Þ
f
g
ð18:3Þ
where m 1 …m k represents the models of vertexes in terms of vulnerability to thread,
v 1 …v k are vertices and d 1 …d k are data related to each vertex conditions. This data
can be gathered using various methods such as testing, and online-checking.
For networked systems it is important to evaluate flood-like thread propagation,
for instance all the vertexes to the initial point, which can be named vertex 1 need to
consider adjacency with 2, 6, 9th vertexes, vertex 11 need to consider adjacency to
vertex 3 and 10th and so on. The initiation of recovery process might have various
reasons, but it becomes an essential part of extended GAFT [1–7].
18.3.1 Implementation Steps
The framework assumes two algorithms involved in the recoverability procedures
of connected computer systems (networked systems), namely Forwarding tracing
and Backward tracing. How this works? When a thread is identified, via symptoms
noted through changes in the behavior of elements, the tracing algorithms searches
the Dependency Matrix related to the threat propagation through the system with
the aim to identify the consequences or the problems, starting from the vertex where
the thread was primarily identified [1–5, 10].
Example of thread dependency graph in the matrix form is presented by
Table 18.2.
Executing the tracing forwarding algorithm involves the calculation of a
cumulative probability along all the possible paths until a termination threshold e is
reached. This threshold is defined empirically and should be considered as a constant for a particular network configuration [3, 4, 10].
18.3 Resilience and Recoverability in Networked System
257
safety-critical applications.
Effective recovery is based on evaluating of the impact on the DCS and its
elements, applying a concept ASAP and ALAP (better from the design phase of
DCS). For DCS and its model we analyze the interdependencies of elements in
terms of thread propagation using a graph Fig. 18.2 where the elements (routers,
switches) are the vertices and edges are the links that connect the vertices.
The strength of the dependence between the vertexes is defined by the thickness
of the edges. It is also important to stress that dependencies among vertexes are not
symmetrical, this means that vertex 10 might have higher impact on vertex 7 than
vertex 7 might have on 10. In this case, dependencies in terms of problem propagation might be presented as square non-symmetrical matrix where the indices
represent the vertices and the dependencies are represented by contents, this is
illustrated [4, 5, 8, 9] in Fig. 18.2.
The propagation of thread in the network can be defined as a vector P of
predicates {p i } that represents the condition for each vertex [4]:
P ¼ p 1 m 1 v 1 d 1 ðtÞ
ð
Þ
ð
Þ
ð
Þ ; p 2 m 2 v 2 d 2 ðtÞ
ð
Þ
ð
Þ
ð
Þ ; . . .; p k m k v k d k ðtÞ
ð
Þ
ð
Þ
ð
Þ
f
g
ð18:3Þ
where m 1 …m k represents the models of vertexes in terms of vulnerability to thread,
v 1 …v k are vertices and d 1 …d k are data related to each vertex conditions. This data
can be gathered using various methods such as testing, and online-checking.
For networked systems it is important to evaluate flood-like thread propagation,
for instance all the vertexes to the initial point, which can be named vertex 1 need to
consider adjacency with 2, 6, 9th vertexes, vertex 11 need to consider adjacency to
vertex 3 and 10th and so on. The initiation of recovery process might have various
reasons, but it becomes an essential part of extended GAFT [1–7].
18.3.1 Implementation Steps
The framework assumes two algorithms involved in the recoverability procedures
of connected computer systems (networked systems), namely Forwarding tracing
and Backward tracing. How this works? When a thread is identified, via symptoms
noted through changes in the behavior of elements, the tracing algorithms searches
the Dependency Matrix related to the threat propagation through the system with
the aim to identify the consequences or the problems, starting from the vertex where
the thread was primarily identified [1–5, 10].
Example of thread dependency graph in the matrix form is presented by
Table 18.2.
Executing the tracing forwarding algorithm involves the calculation of a
cumulative probability along all the possible paths until a termination threshold e is
reached. This threshold is defined empirically and should be considered as a constant for a particular network configuration [3, 4, 10].
18.3 Resilience and Recoverability in Networked System
257
