Chaire de cyberdéfense des systèmes navals
  • 🇫🇷 Français
  • News
  • Alumni
  • Naval cyber-range
  • Ongoing Theses
  • Supervisory Team
  • Who are we?
  • Governance

Bastien Sultan

Directeur(s): Yvon Kermarrec
Encadrant(s):

risk analysis, vulnerabilities, patches

SUJET DE THÈSE

Security Patch Management for Naval Systems

Context

In response to the goal of acquiring cybersecurity skills and technologies set out in the 2013 White Paper on Defense, the Naval Systems Cyberdefense Chair was established through academic and industrial cooperation between Télécom Bretagne, the École Navale, DCNS, and Thales. The application of cybersecurity research to the naval sector is particularly crucial at a time when ships—both civilian and military—are integrating numerous IT systems that control critical mechanical actuators or enable the vessel to communicate, navigate, and perceive its operational environment.

Although beneficial in terms of efficiency and precision, the presence of these IT systems can create vulnerabilities that attackers may exploit. These vulnerabilities may be software-based, hardware-related, organizational, or human, raising challenges in their detection and remediation. The objective of this PhD research, which began in October 2015, is to design processes and tools for managing the deployment of countermeasures that mitigate potential vulnerabilities in these complex cyber-physical systems. To achieve this, we have developed a behavioral modeling and knowledge maintenance process for ships, spanning the entire lifecycle of the system (tasks 1-1 to 1-3), which serves as the foundation for the vulnerability response process (tasks 2-1 to 2-4).

 

Task 2-2, "Impact Analysis," is the scientific core of this research. Based on a behavioral modeling approach using finite state automata, this task results in the expression of the impact of an atomic modification on the overall system behavior and its ability to perform critical missions, represented in the form of a metric.

This process has been validated through simulation, and an experiment is currently underway to confirm its applicability to real-world systems.

Publications

Bastien Sultan, under the supervision of Yvon Kermarrec. Mastering Security Patches for Naval Systems. Ecole nationale supérieure Mines-Télécom Atlantique Bretagne Pays de la Loire.
Bastien Sultan, Fabien Dagnat, Caroline Fontaine. A Methodology to Assess Vulnerabilities and Countermeasures Impact on the Missions of a Naval System. CyberICPS'2017: International Workshop on the Security of Industrial Control Systems and Cyber-Physical Systems, Sep 2017, Oslo, Norway. pp.63 - 76, ⟨10.1007/978-3-319-72817-9_5⟩. ⟨hal-01836378⟩
Bastien Sultan, Fabien Dagnat, Caroline Fontaine. Mastering Security Patches for Naval Systems. CIEL 2016: 5th Conference on Software Engineering, Jun 2016, Besançon, France. pp.1 - 6. ⟨hal-01431543⟩
Retour
  • Naval Systems Cyber Defense Chair
  • École navale
  • BCRM Brest - CC 600
  • 29240 BREST Cedex 9
  • chairecyber@ecole-navale.fr
Legal Notice
Supported by
cybersecurity
cybersecurity research
naval cybersecurity
Shortcuts
  • Students
  • Researchers
  • Industry partners
  • The Chair
  • PhD Research
  • Alumni
  • Publications
  • Supervisory Team
  • Naval cyber-range
  • News
Contact Us
cyberdefense cybersecurity research naval cybersecurity