Transcription of Advanced services for critical infrastructures …
1 J Ambient Intell Human Comput (2015) 6:783 795. DOI ORIGINAL research . Advanced services for critical infrastructures protection Rafa Kozik1 Micha Choras 1 Adam Flizikowski1 Marianthi Theocharidou2 . Vittorio Rosato3 Erich Rome4. Received: 28 February 2015 / Accepted: 29 May 2015 / Published online: 6 June 2015. The Author(s) 2015. This article is published with open access at Abstract In this paper an overview of the first results of 1 Introduction FP7 CIPRNet project is presented. Particularly, we demonstrate CIPRNet services for critical infrastructure critical infrastructures (CI) protection (CIP) is a complex protection (CIP) stakeholders. The role of the proposed and delicate task. From one hand, decisions taken for CIP. services is to support decisions in the CIP domain. More- purposes may impact human lives and material goods, over, those services are expected to serve as the under- threatened by both natural phenomena as well as the con- pinnings for the European infrastructures Simulation and sequences of human errors.
2 From the other hand, such Analysis Centre (EISAC) which, similarly to the US decisions must be taken in real-time particularly during NISAC, should provide operational services on CIP, for the the CI-related crisis (European Council 2008). Most often benefits of CI operators, stakeholders and the Public such decisions are taken by analysing a large amount of Authorities committed to CIP. heterogeneous data. In CIP domain, this challenge can be presented in three dimensions, called 3 V model of Big Data problem Keywords critical infrastructure protection CIPRNet (Gartner Inc. 2011). These three dimensions include: project Decision support services Modelling and simulation Volume of data, that must be processed to build an actual picture of operation needed to take the appro- priate decision in given time;. Velocity of the constantly changing data provided to & Micha Choras the decision maker from various sources, and.
3 Variety of data that come from heterogeneous sources, Rafa Kozik challenging the reasoning and information correlation. Marianthi Theocharidou In this paper, the services for CIP community and decision makers are presented to support decision-making Vittorio Rosato process in CIP, both in the preparedness ( cold'') phase, as well as in the crisis ( hot'') phase. Erich Rome The goal of such services development is to increase the situational awareness of decision makers by extraction of the most necessary information from the large amount of 1. University of Science and Technology, UTP, Bydgoszcz, heterogeneous data coming from different sources (such as Poland real-time sensorial data). 2. European Commission, Joint research Center, Institute for Specification and development of the services proposed the protection and the Security of the Citizen, Ispra, Italy in this paper are the objectives of the critical Infrastructure 3.
4 ENEA Casaccia research Centre, Rome, Italy Preparedness and Resilience research Network (CIPRNet). 4. Fraunhofer IAIS, Sankt Augustin, Germany project ongoing security research , co-funded by the 123. 784 R. Kozik et al. European Commission's 7th research Framework Program Providing knowledge and technology to end users for (FP7) (CIPRNet 2015). improving their understanding of the role of CI in crises In the first phase of the project, the end-users commu- and emergencies: simulators, middleware, models, nity was asked to express and share their needs and Providing long-lasting end-user support by establishing expectations related to increase effectiveness of modelling, a Virtual Centre of Competence and Expertise in CIP. simulation and CIP-related analysis environment and (VCCC). decision making process. The project started on March 2013 and will be com- In this paper, the analysis of their requirements is pro- pleted on February vided as well as the description of the demanded services that will later be designed in the CIPRNet project.
5 The rest of this paper is structured as follows: 3 CIP end-user views collection Section 2 presents the CIPRNet project, Section 3 focuses on end-users views and needs that One of the first tasks performed by the CIPRNet consor- contributed to the specification of CIPRNet services , tium was to identify the needs arising from CIP commu- Sections 4 and 5 present CIPRNet DSS services and nities, by a direct interaction with end-users and domains'. CIPRNet VCCC services , respectively, stakeholders. The identified stakeholders relevant to the Section 6 discusses non-technical aspects of CIPRNet project represented the public, private, research and aca- services , demia domains. The methods for gathering user views in Section 7 concludes the paper. the CIPRNet project were face-to-face meetings, remote user interviews and the CIPRNet questionnaire, filled in by the project end-users and domain experts. Outcomes of the collected questionnaires were a starting point in require- 2 CIPRNet project ments specification process towards specification of solu- tions described in this paper.
6 The critical Infrastructure Preparedness and Resilience The questionnaire was designed in order to provide a research Network or CIPRNet (CIPRNet 2015) establishes a broad view on current end-user problems, limitations and Network of Excellence in CIP. CIPRNet performs research expectations, including big data issues. Most of the ques- and development addressing a wide range of stakeholders tions were presented in an open or semi-open format. including (multi)national emergency management, critical Therefore, respondents were neither limited in expression infrastructure operators, policy makers, and public authori- of their opinions, nor biased by pre-defined options to ties. By integrating resources of the CIPRNet partners choose. acquired in more than 60 EU co-funded research projects, Generally, the questionnaire has been divided into four CIPRNet is going to create new Advanced capabilities for its blocks of questions, namely: stakeholders.
7 A key technology for the new capabilities will General information about the respondents, particularly be modelling, simulation and analysis for CIP. In order to their organisations, range of activities, matter in which achieve its mission, CIPRNet's Joint Programme of Activi- he/she acts, ties has four major threads: Questions related to accessing the information, partic- Providing new capabilities to end users for better ularly concerning availability of information about CI. preparedness for CI-related emergencies: coming from private and public sectors and used during CI-related crisis, An Advanced decision support system enabling the Questions about using decision support systems during prediction of risk on CI based on consequence respondent duties, providing information about deci- analysis, sion support mechanisms and tools, their limitations, What if' analysis for exploring different courses data exchange, standards, etc.
8 , of action, Questions about simulation and modelling for CI crisis Support of secure design of next generation management purposes. infrastructures , Ask the expert' service for demonstrating timely, Respondents, who filled in the questionnaire, represent actionable, risk-informed CIP analyses and strate- various organisations from local and regional CI-related gies for authorities, organisations to Pan-European agencies, and from Building required capacities by educating and training 1. More information about the CIPRNet project can be found at experts and researchers (reaching a critical mass), project website: 123. Advanced services for critical infrastructures protection 785. academic and applied researchers to CI-operators. How- organisations) use internally developed tools for specific ever, the majority of respondents are representatives of purposes of their organisation, or alternatively, that they organisations that operate within nationwide range, and use various loosely coupled data sources (such as GIS.
9 Usually as public emergency/crisis management centre. resources, the weather data, etc.) to support decisions. Specific DSS tools used by interviewees have been listed, Accessing the information such as C3 M, IPCR or WebEOC. These systems are exploited for the crisis response planning, reporting, pro- The respondents assessed availability of various informa- cedure and policy creating, resource allocation and tion related to CI from various sectors and sources and tracking. gave them ratings. According to respondents' ratings, When asked about the analytical capabilities, as well as generally there are no significant differences between about usefulness and effectiveness of these systems during levels of availability of information, when comparing crisis-related decision-making, respondents presented dif- public and private sectors. The average ratings for public ferent views. About half of them admitted that the used vs.
10 Private CI information availability ( geo-localisation (DSS) systems do not meet their needs and that these data, operational data and sensitive data about these systems are not tailored to the specific needs of their infrastructures ) are at the similar level. Considering infor- operation. As respondents emphasised, the main weakness mation about CI dependences, it is noticeable that such of these systems is the need for Advanced customisation information during normal operation is significantly easier (costly in terms of time, efforts, financing, etc.). accessible than during non-normal state of operation. Other drawbacks include: The questionnaire analysis shows that the hardest cate- Lack of interconnectivity with the other systems ( gories of information to be accessed include: used by entities cooperating with stakeholder's organ- Operational data of private sector CI, isation during CI-related crisis), Information about CI across the national/regional Lack of possibility to integrate the data from other borders, entities/systems, hampering the cooperation between Information about CI across public private sector various organisations, borders, Limited capabilities of spatial visualisation of threats, Information about CI dependencies during non-normal and operation.