Upload
grace-alcaraz
View
221
Download
0
Embed Size (px)
Citation preview
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 1/45www.ysecurity.net 1
Jere Peltonen
Estimate of Multiple Adversary SequenceInterruption
Jere Peltonen, CPPlinkedin.com/in/jerepeltonen
J E R E
P E L T O N E N
EASI
EASI (Estimate of Adversary
Sequence Interruption) Sandia National Laboratories
U.S. Department of Energy
EASI has been used to analyze e.g.physical security arrangements of nuclear facilities
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 2/45www.ysecurity.net 2
Jere Peltonen
J E R E P E L T O N E N
What is analyzed?
Structural arrangements
Surveillance
J E R E
P E L T O N E N
What are the results?
probability of failure of unauthorized
entry
in other words
probability of successful interruption
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 3/45www.ysecurity.net 3
Jere Peltonen
J E R E P E L T O N E N
EASI
can be used easily to analyzearrangements that follow theprinciple of concentric protectionlayers
J E R E
P E L T O N E N
EASI / TUREAN
Basic EASI does not calculate
alternative routes of entry
TUREAN application of EASIcalculates all alternative routes
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 4/45www.ysecurity.net 4
Jere Peltonen
J E R E P E L T O N E N
Why to use?
To get more reliable information
J E R E
P E L T O N E N
Why to use?
Security arrangements cost money
On the other hand, to not use anyarrangements can be very costly mistake
We must find the optimum solution, thatdoes not cost too much, but gives adequateprotection
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 5/45www.ysecurity.net 5
Jere Peltonen
J E R E P E L T O N E N
Why to use?
The security expert or manager needs tomake his/her case to the people that havethe money
He/she must demonstrate the vulnerabilitiesof existing arrangements
He/she must demonstrate the effectivenessof planned arrangements with regard toprotection of assets
J E R E
P E L T O N E N
Why to use?
Existing or planned arrangements may
be good as such, but the chain is onlyas strong as its weakest link
TUREAN finds the weakest links
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 6/45www.ysecurity.net 6
Jere Peltonen
J E R E P E L T O N E N
Why to use?
To get clear numerical informationthat can be used to
find the existing weaknesses
test the effectiveness of planned
arrangements
justify the necessary new arrangements
J E R E
P E L T O N E N
Why to use?
TUREAN is an excellent tool for
teaching analytical approach
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 7/45www.ysecurity.net 7
Jere Peltonen
J E R E P E L T O N E N
How to get numerical information?
calculate the probability of successfulldetection and alarm
And
calculate the probability that remainingtime will be enough to interrupt theentry
J E R E
P E L T O N E N
How to get numerical information?
the probability of successful detection
and alarm is calculated using thereliability of detection elements anddetection-to-response reliability
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 8/45www.ysecurity.net 8
Jere Peltonen
J E R E P E L T O N E N
Detection elements
anything that may detect theunauthorized entry and execute thealarm (intrusion detectors, localguards, passers-by)
J E R E
P E L T O N E N
How to get numerical information?
the probability that remaining timeallows interruption is calculated by
adding up delay values of all delayelements, taking into account the realworld uncertainties of the values, and
comparing it to the response time value,taking into account the uncertainty
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 9/45www.ysecurity.net 9
Jere Peltonen
J E R E P E L T O N E N
Delay elements
Anything that may delay the intruder(door, window, wall, fence, lock,etc.)
J E R E
P E L T O N E N
3 most essential terms
Delay
Detection Response time
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 10/45www.ysecurity.net 10
Jere Peltonen
J E R E P E L T O N E N
Other terms
Probability
Normal distribution
Expected value
Standard deviation
Type
Sequence of events
Zone
Intrusion route
J E R E
P E L T O N E N
Concentric layers of protection
GATEDOOR
DOORWINDOW
WINDOW
SAFE
FENCE
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 11/45www.ysecurity.net 11
Jere Peltonen
J E R E P E L T O N E N
Intrusion route
J E R E
P E L T O N E N
Sequence of events
12
3
45
67
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 12/45www.ysecurity.net 12
Jere Peltonen
J E R E P E L T O N E N
Alternative events(=alternative routes)
12
3
45
67
3
1
3
5
1
J E R E
P E L T O N E N
Alternative events
12
345
67
3
1
3
5
1
1 Crossing the fence
1 Locked gate
1 Through the fence
1
1
1
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 13/45www.ysecurity.net 13
Jere Peltonen
J E R E P E L T O N E N
Alternative events
12
3
45
67
3
1
3
5
1
2 Moving across the yard
1
1
1
2
J E R E
P E L T O N E N
Alternative events
12
345
67
3
1
3
5
1
3 Making a hole
3 Window
3 Locked door
1
1
1
2
3
3
3
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 14/45www.ysecurity.net 14
Jere Peltonen
J E R E P E L T O N E N
Alternative events
12
3
45
67
3
1
3
5
1
4 Moving inside
1
1
1
2
3
3
3
4
J E R E
P E L T O N E N
Alternative events
12
345
67
3
1
3
5
1
5 Making a hole
5 Locked door
1
1
1
2
3
3
3
45
5
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 15/45www.ysecurity.net 15
Jere Peltonen
J E R E P E L T O N E N
Alternative events
12
3
4567
3
1
3
5
1
6 Moving inside
1
1
2 3
3
45
56
1 3
J E R E
P E L T O N E N
Alternative events
12
345
67
3
1
3
5
1
7 Safe
1
1
1
2
3
3
3
45
56 7
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 16/45www.ysecurity.net 16
Jere Peltonen
J E R E P E L T O N E N
Alternative events
12
3
45
67
3
1
3
5
1
8 Going back the same ordifferent route
1
1
1
2
3
3
3
45
56 7 8
J E R E
P E L T O N E N
Alternative events
12
345
67
3
1
3
5
1
1
1
1
2
3
3
3
45
56 7 8
18 ALTERNATIVE INTRUSION ROUTES
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 17/45www.ysecurity.net 17
Jere Peltonen
J E R E P E L T O N E N
Delay
30 s
30 s
Event 1
Total
J E R E
P E L T O N E N
Delay
30 s
60 s
90 s
Event 1
Event 2
Total
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 18/45www.ysecurity.net 18
Jere Peltonen
J E R E P E L T O N E N
Delay
30 s
45 s
60 s
135 s
Event 1
Event 2
Event 3
Total
J E R E
P E L T O N E N
Delay
30 s
45 s
60 s
45 s
180 s
Event 1
Event 2
Event 3
Event 4
Total
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 19/45www.ysecurity.net 19
Jere Peltonen
J E R E P E L T O N E N
Delay, detection
30 s
45 s
60 s
45 s
180 s
Event 1
Event 2
Event 3
Event 4
Total
1stpossibility of
detection->detection
J E R E
P E L T O N E N
Delay, detection, response time
30 s
45 s
60 s
45 s
180 s
105 s
Responsetime
Event 1
Event 2
Event 3
Event 4
Total
1stpossibility of
detection->detection
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 20/45www.ysecurity.net 20
Jere Peltonen
J E R E P E L T O N E N
Delay, detection, response time
successful interruption
30 s
45 s
60 s
45 s
180 s
105 sResponse
time
1stpossibility of
detection
Interruption
Event 1
Event 2
Event 3
Event 4
Total
->detection
J E R E
P E L T O N E N
Delay, detection, response time???
30 s
45 s
60 s
45 s
180 s
but NO detection
Event 1
Event 2
Event 3
Event 4
Total
Responsetime
1stpossibility of
detection
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 21/45www.ysecurity.net 21
Jere Peltonen
J E R E P E L T O N E N
Delay, detection, response time
???
30 s
45 s
60 s
45 s
180 s
1stdetection
Event 1
Event 2
Event 3
Event 4
Total
Responsetime
but NO detection
1stpossibility of
detection
J E R E
P E L T O N E N
Delay, detection, response time???
30 s
45 s
60 s
45 s
180 s
105 s
Event 1
Event 2
Event 3
Event 4
Total
Responsetime
1stdetection
but NO detection
1stpossibility of
detection
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 22/45www.ysecurity.net 22
Jere Peltonen
J E R E P E L T O N E N
Delay, detection, response time
unsuccessful interruption
30 s
45 s
60 s
45 s
180 s
105 s
Interruption
Event 1
Event 2
Event 3
Event 4
Total
Responsetime
1stdetection
but NO detection
1stpossibility of
detection
J E R E
P E L T O N E N
Delay, detection, responsetime
the example uses exact times for the
sake of concept simplicity
in the real world, there exists a levelof uncertainty that has to be takeninto account somehow
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 23/45www.ysecurity.net 23
Jere Peltonen
J E R E P E L T O N E N
Delay, detection, responsetime
uncertainty is modelled by assumingthat all times follow the normaldistribution (Gaussian curve)
J E R E
P E L T O N E N
Normal distribution
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 24/45www.ysecurity.net 24
Jere Peltonen
J E R E P E L T O N E N
Normal distribution
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
= single measurement measurements 0
J E R E
P E L T O N E N
Normal distribution ??
= single measurement measurements 10
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
10
value 50 is measured 10 times
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 25/45www.ysecurity.net 25
Jere Peltonen
J E R E P E L T O N E N
Normal distribution= single measurement measurements 10
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
10
value 50 is measured 10 times
J E R E
P E L T O N E N
Normal distribution
= single measurement measurements 11
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
2 1 1 11 1 1 2 1
value 50 is measured 2 times
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 26/45www.ysecurity.net 26
Jere Peltonen
J E R E P E L T O N E N
Normal distribution= single measurement measurements 41
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
5 4 4 3 3 2 2 11 2 2 3 3 2 4
value 50 is measured 5 times
J E R E
P E L T O N E N
Normal distribution
= single measurement measurements 86
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
10 9 9 8 5 3 2 1 1 2 11 1 1 2 2 2 4 4 9 81
value 50 is measured 10 times
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 27/45www.ysecurity.net 27
Jere Peltonen
J E R E P E L T O N E N
Normal distribution
50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 6634 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49
10 9 9 8 5 3 2 1 1 2 11 1 1 2 2 2 4 4 9 81
= single measurement measurements 86
value 50 is measured 10 times
J E R E
P E L T O N E N
Standard deviation
standard deviation is a value that
shows how much and how often realworld times vary around theexpected value
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 28/45www.ysecurity.net 28
Jere Peltonen
J E R E P E L T O N E N
Standard deviation
+s-s µ
standard deviation 3,8
Real world times varyquite lot and oftenfrom the expectedvalue µ
J E R E
P E L T O N E N
Standard deviation
+s-s µ
Real world times varynot so much and not sooften as in previousexample
standard deviation 2,2
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 29/45www.ysecurity.net 29
Jere Peltonen
J E R E P E L T O N E N
Type
when delay and detection elementsexist at the same event
type tells how much delay has beenused before detection
three types in the model
J E R E
P E L T O N E N
Type H
no delay before detection
whole delay is calculated for example: a PIR detector that
detects an intruder at the beginningof a hallway
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 30/45www.ysecurity.net 30
Jere Peltonen
J E R E P E L T O N E N
Type K
half of delay before detection
half of delay is calculated
for example: a PIR detector thatdetects an intruder when he hasmoved midway of a hallway
J E R E
P E L T O N E N
Type J
all delay before detection
no delay of particular delay elementis taken into accounct in calculation
for example: magnetic contacts at adoor, which give detection only afterthe lock has been picked and dooropens
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 31/45www.ysecurity.net 31
Jere Peltonen
J E R E P E L T O N E N
Example
Door
Window
WallSafe
95%/H/7200s/3000s
95%/H/30s/10s
95%/J/300s/100s0%/7200s/3000s
J E R E
P E L T O N E N
Example
Door
95%/J/300s/100s
Please note that the terminology in TUREANscreenshots used in this presentation is in Finnish.
The TUREAN tool is available in English also.
Check www.yhteisturvallisuus.net orwww.ysecurity.net
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 32/45www.ysecurity.net 32
Jere Peltonen
J E R E P E L T O N E N
Example
Window
95%/H/30s/10s
J E R E
P E L T O N E N
Example
Wall
0%/7200s/3000s
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 33/45www.ysecurity.net 33
Jere Peltonen
J E R E P E L T O N E N
Example
Safe
95%/H/7200s/3000s!
J E R E
P E L T O N E N
Example
Going back
95%/H/60s/20s!
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 34/45www.ysecurity.net 34
Jere Peltonen
J E R E P E L T O N E N
Example
J E R E
P E L T O N E N
Example
Report
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 35/45www.ysecurity.net 35
Jere Peltonen
J E R E P E L T O N E N
Example
J E R E
P E L T O N E N
Example
The worst probability of interruption is withthe route that goes through the wall!!
WHY??
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 36/45www.ysecurity.net 36
Jere Peltonen
J E R E P E L T O N E N
EXERCISE
analyze using the following values
J E R E
P E L T O N E N
Alternative events
2
345
67
3
0%/600s/200s
3
50%/60s/20s
0%/120s/20s
1
1
1
1 Crossing fence
1 Locked gate
1 Going through
0% / 600s / 200s 0% / 60s / 20s 0% / 120s / 20s
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 37/45www.ysecurity.net 37
Jere Peltonen
J E R E P E L T O N E N
J E R E
P E L T O N E N
Alternative events
13
45
67
3
1
3
5
1
2 Moving accross the yard
1
1
1
2
0%/60s/10s
0% / 60s / 10s
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 38/45www.ysecurity.net 38
Jere Peltonen
J E R E P E L T O N E N
Alternative events
124
567
1
5
1
3 Going through
3 Window
3 Locked door
1
1
1
2
3
3
3
0%/7200s/3000s
95%/J/300s/100s
95%/H/30s/10s
0% / 7200s / 3000s 95% / H / 30s / 10s 95% / J / 300s / 100s
J E R E
P E L T O N E N
Alternative events
12
3
567
3
1
3
5
1
4 Moving inside
1
1
1
2
3
3
3
4
95%/H/60s/10s
95% / H / 60s / 10s
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 39/45www.ysecurity.net 39
Jere Peltonen
J E R E P E L T O N E N
Alternative events
12
3
4
67
3
1
3
1
5 Going through
5 Locked door
1
1
1
2
3
3
3
45
5
0%/3600s/1000s95%/J/300s/100s
0% / 3600s / 1000s 95% / J / 300s / 100s
J E R E
P E L T O N E N
Alternative events
12
345
7
3
1
3
5
1
6 Moving inside
1
1
2 3
3
45
56
1 3
95%/H/20s/5s
95% / H / 20s / 5s
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 40/45www.ysecurity.net 40
Jere Peltonen
J E R E P E L T O N E N
Alternative events
12
3
45
6
3
1
3
5
1
7 Safe
1
1
1
2
3
3
3
45
56 7
95%/H/7200s/3000s
95% / H / 7200s / 3000s
J E R E
P E L T O N E N
Alternative events
12
345
67
3
1
3
5
1
8 Going back
1
1
1
2
3
3
3
45
56 7 8
95%/H/300s/100s
95% / H / 300s / 100s
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 41/45www.ysecurity.net 41
Jere Peltonen
J E R E P E L T O N E N
Other values
response time 900 s / standarddeviation 300 s
reliability 95%
J E R E
P E L T O N E N
First results
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 42/45www.ysecurity.net 42
Jere Peltonen
J E R E P E L T O N E N
Sorted and colored result list
J E R E
P E L T O N E N
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 43/45www.ysecurity.net 43
Jere Peltonen
J E R E P E L T O N E N
EXERCISE
the safe is open
delay 0 s, standard deviation 0 s
J E R E
P E L T O N E N
Results
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 44/45www.ysecurity.net 44
Jere Peltonen
J E R E P E L T O N E N
Results
{
J E R E
P E L T O N E N
8/8/2019 Ture an Presentation English
http://slidepdf.com/reader/full/ture-an-presentation-english 45/45
Jere Peltonen
J E R E P E L T O N E N
Questions?
TUREAN tool is available for freeat
www.yhteisturvallisuus.netor
www.ysecurity.net