The Etiology of Cybersecurity

Michele Ambrosi, Francesco Beltramini, Federico De Meo, Oliviero Nardi, Mattia Pacchin, Marco Rocchetto

Published: 2022, Last Modified: 23 Mar 2026ACNS Workshops 2022EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: The objective of this research is to lay the foundations for the development of a scientific theory that determines (all and only) the possible insecure and secure configurations of any abstract system to be used for the risk assessment of systems. We claim that cybersecurity weaknesses (i.e. errors) are at the beginning of the causality chain that leads to cybersecurity attacks. We formulate a hypothesis that we use to predict the weaknesses in the architectural design of a system. Our hypothesis allows for the definition of a mathematical formula which describes the cybersecurity of a system. We implemented a prototype cybersecurity risk assessment tool that, based on our hypothesis, predicts the weaknesses in a UML model of a (cyber-physical) system.
Loading