SlideShare a Scribd company logo
Experience Report:


Modelling and Simulation of 

Railway Emergency Response Plans
ITU ProSec, May 2nd, 2016
Søren Debois
Joint work with Thomas Hildebrandt & Lene Sandberg
Plan
• Cyber-threats to Critical Infrastructure
• The method
• The Great Belt Bridge incident case
• Collaborative mapping & simulation
• Conclusions
Cyber-threats & Infrastructure
Cyber-physical attacks on 

Critical Infrastructure
• Operators (DSB, BaneDanmark) robust against
physical incidents, including terrorism.
• Operators IT system landscape very large and
varied.
• However, traditional “No-IT” approach to train
operators still form foundations of day-to-day
operations.
The potential weakness
• Cyber-physical assault: Combined physical &
cyber attack.
• Do emergency response plans hold up when both
IT and physical infrastructure is physically
attacked?
How to investigate?
• Extensive emergency response plans exist. Drills are
performed regularly.
• Let’s simulate!
• But wait! Paper-based rehearsals don’t actually use ICT
systems. How to simulate?
• We need to simulate both the actions of drill participants
and breakdowns of IT systems.
• We have to be sure no-one “cheats” by accidentally
assuming some system is functioning.
Declarative Process Models
• Formal model of emergency response process.
• Give enormous freedom within a set of rules.
• No-one cheats accidentally; the model won’t allow
it.
Example
How do we try this out?


How do we get the process model?
Case: Great Belt Bridge
Collaborative mapping
• Extensive documentation of emergency response
procedures exists.
• We sat down with domain experts from DSB &
BaneDanmark and constructed a model based on
that documentation.
Modelling and Simulation of the response process for an emergency at the Great Belt bridge
How do we know whether
this model is meaningful?
Collaborative simulation
• Simulation gives the ability to explore un-
anticipated paths and “what-if” scenarios.
• Collaborative simulation brings a new level of
realism, especially for coordination problems of
emergency response scenarios.
Simulation study, Metropol
• At Metropol, students of Emergency and Risk
Management as participants.
• Tool provided insufficient overview.
• Tool did not hide available and executed actions of
other participants .
Simulation study, DSB
• At DSB, with DSB emergency response team lead
and experienced train driver.
• Recommendations: 

Pictures, text, documentation in-tool.
Conclusions
Conclusions
• Collaborative mapping and simulation of
emergency response processes is a viable means
of studying ICT/Cyber-physical vulnerabilities.
• DCR Formalism accessible to domain experts (with
assistance)
• DCR Tooling almost there.
Future work
• Integrating the IT system landscape into the model.
Thank you!
Søren Debois

More Related Content

PDF
Stateless load balancing - Research overview
PPTX
A Preliminary Study on Architecting Cyber-Physical Systems
PDF
Full_resume_Dr_Russell_John_Childs
PDF
[Thesis] Tangible Collaboration applied in Space Systems Concurrent Engineeri...
PDF
Capella Days 2021 | Using MBSE to Integrate Engineering Undergraduate Courses...
PDF
The Green Lab - [13 B] Future research challenges
PDF
Taming the Beast - Some Thoughts On Exascale Resiliency
PPTX
Workshop8 18 12 09 Ingles
Stateless load balancing - Research overview
A Preliminary Study on Architecting Cyber-Physical Systems
Full_resume_Dr_Russell_John_Childs
[Thesis] Tangible Collaboration applied in Space Systems Concurrent Engineeri...
Capella Days 2021 | Using MBSE to Integrate Engineering Undergraduate Courses...
The Green Lab - [13 B] Future research challenges
Taming the Beast - Some Thoughts On Exascale Resiliency
Workshop8 18 12 09 Ingles

Viewers also liked (20)

POTX
Proof of Concept af en fleksibel løsning til små online møder
PDF
Proactive prevention of obligation violations
PDF
Process-oriented Security Risk Analysis and Requirements Engineering
PPTX
Gamification workshop Marianne Hilton
PDF
Udforskning af problem gennem forslag til dets løsning
PDF
Procesarbejdet i Nykredit, John Nielsen, Nykredit
PDF
Gamification workshop Thomas Hildebrandt
PPTX
Gamification workshop Tine Weirsøe
PDF
Gamification workshop michelle
PDF
Process modelling at BaneDanmark
PDF
Systematisk brug af pair programming
PDF
Overview of the ProSec project
PDF
Fleksibel procesdigitalisering
PPTX
Di sc workplace profile infinit clean
PDF
Værdiskabelse i projekter
PDF
Projektledelse og softwareinnovation
PDF
Agilitet i hurtigt voksende softwarevirksomheder
PDF
Introduktion til udviklingsprocesser og agile processer
PDF
Produktudvikling hos Grundfos igennem underleverandør
PPTX
Value Creation in SaaS Development
Proof of Concept af en fleksibel løsning til små online møder
Proactive prevention of obligation violations
Process-oriented Security Risk Analysis and Requirements Engineering
Gamification workshop Marianne Hilton
Udforskning af problem gennem forslag til dets løsning
Procesarbejdet i Nykredit, John Nielsen, Nykredit
Gamification workshop Thomas Hildebrandt
Gamification workshop Tine Weirsøe
Gamification workshop michelle
Process modelling at BaneDanmark
Systematisk brug af pair programming
Overview of the ProSec project
Fleksibel procesdigitalisering
Di sc workplace profile infinit clean
Værdiskabelse i projekter
Projektledelse og softwareinnovation
Agilitet i hurtigt voksende softwarevirksomheder
Introduktion til udviklingsprocesser og agile processer
Produktudvikling hos Grundfos igennem underleverandør
Value Creation in SaaS Development
Ad

Similar to Modelling and Simulation of the response process for an emergency at the Great Belt bridge (20)

PDF
What the cloud has to do with a burning house?
PDF
IRJET- Criminal Recognization in CCTV Surveillance Video
PPTX
BsidesLVPresso2016_JZeditsv6
PPTX
Spatio Temporal Data Mining
PDF
Collaborative Research with UK MOD - an Academic's Experience ((John Fitzgerald)
PPTX
The Path to Digital Engineering
PPTX
ppt for mini project .pptx
PPTX
Applications of Machine Learning
PPTX
DIGITAL TWIN FOR ENHANCING ASSETS INTEGRITY VALUE
PPTX
Rise of the machines -- Owasp israel -- June 2014 meetup
PPTX
Era ofdataeconomyv4short
PPTX
Derek Wright: risk v uncertainty case study
PDF
LLM Agents and Tool Use Data and Web Science Group IE686 Large Language Model...
PDF
SBSE-class1.pdf
PDF
ExaLearn Overview - ECP Co-Design Center for Machine Learning
PPTX
Human_assault project using jetson nano new
PPTX
Novel Optimized Models for Deep Learning
PPTX
Edge computing system for large scale distributed sensing systems
PDF
[Keynote] predictive technologies and the prediction of technology - Bob Will...
PDF
Pydata Chicago - work hard once
What the cloud has to do with a burning house?
IRJET- Criminal Recognization in CCTV Surveillance Video
BsidesLVPresso2016_JZeditsv6
Spatio Temporal Data Mining
Collaborative Research with UK MOD - an Academic's Experience ((John Fitzgerald)
The Path to Digital Engineering
ppt for mini project .pptx
Applications of Machine Learning
DIGITAL TWIN FOR ENHANCING ASSETS INTEGRITY VALUE
Rise of the machines -- Owasp israel -- June 2014 meetup
Era ofdataeconomyv4short
Derek Wright: risk v uncertainty case study
LLM Agents and Tool Use Data and Web Science Group IE686 Large Language Model...
SBSE-class1.pdf
ExaLearn Overview - ECP Co-Design Center for Machine Learning
Human_assault project using jetson nano new
Novel Optimized Models for Deep Learning
Edge computing system for large scale distributed sensing systems
[Keynote] predictive technologies and the prediction of technology - Bob Will...
Pydata Chicago - work hard once
Ad

More from InfinIT - Innovationsnetværket for it (20)

PDF
Erfaringer med-c kurt-noermark
PDF
Object orientering, test driven development og c
PDF
Embedded softwaredevelopment hcs
PDF
C og c++-jens lund jensen
PDF
PDF
C som-programmeringssprog-bt
PDF
PDF
Not your grandfathers BPM
PDF
Kmd workzone - an evolutionary approach to revolution
PDF
Martin Wickins Chatbots i fronten
PDF
Marie Fenger ai kundeservice
PDF
Leif Howalt NNIT Service Support Center
PDF
Jan Neerbek NLP og Chatbots
PDF
Anders Soegaard NLP for Customer Support
PDF
Stephen Alstrup infinit august 2018
PDF
Innovation og værdiskabelse i it-projekter
PDF
Rokoko infin it presentation
Erfaringer med-c kurt-noermark
Object orientering, test driven development og c
Embedded softwaredevelopment hcs
C og c++-jens lund jensen
C som-programmeringssprog-bt
Not your grandfathers BPM
Kmd workzone - an evolutionary approach to revolution
Martin Wickins Chatbots i fronten
Marie Fenger ai kundeservice
Leif Howalt NNIT Service Support Center
Jan Neerbek NLP og Chatbots
Anders Soegaard NLP for Customer Support
Stephen Alstrup infinit august 2018
Innovation og værdiskabelse i it-projekter
Rokoko infin it presentation

Recently uploaded (20)

PDF
Machine learning based COVID-19 study performance prediction
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Getting Started with Data Integration: FME Form 101
PPTX
Big Data Technologies - Introduction.pptx
PDF
Approach and Philosophy of On baking technology
PDF
cuic standard and advanced reporting.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPTX
1. Introduction to Computer Programming.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Empathic Computing: Creating Shared Understanding
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
Machine Learning_overview_presentation.pptx
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PPTX
Spectroscopy.pptx food analysis technology
PDF
Network Security Unit 5.pdf for BCA BBA.
Machine learning based COVID-19 study performance prediction
Agricultural_Statistics_at_a_Glance_2022_0.pdf
SOPHOS-XG Firewall Administrator PPT.pptx
Getting Started with Data Integration: FME Form 101
Big Data Technologies - Introduction.pptx
Approach and Philosophy of On baking technology
cuic standard and advanced reporting.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Assigned Numbers - 2025 - Bluetooth® Document
1. Introduction to Computer Programming.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Empathic Computing: Creating Shared Understanding
MYSQL Presentation for SQL database connectivity
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Machine Learning_overview_presentation.pptx
Programs and apps: productivity, graphics, security and other tools
Accuracy of neural networks in brain wave diagnosis of schizophrenia
Spectroscopy.pptx food analysis technology
Network Security Unit 5.pdf for BCA BBA.

Modelling and Simulation of the response process for an emergency at the Great Belt bridge

  • 1. Experience Report: 
 Modelling and Simulation of 
 Railway Emergency Response Plans ITU ProSec, May 2nd, 2016 Søren Debois Joint work with Thomas Hildebrandt & Lene Sandberg
  • 2. Plan • Cyber-threats to Critical Infrastructure • The method • The Great Belt Bridge incident case • Collaborative mapping & simulation • Conclusions
  • 4. Cyber-physical attacks on 
 Critical Infrastructure • Operators (DSB, BaneDanmark) robust against physical incidents, including terrorism. • Operators IT system landscape very large and varied. • However, traditional “No-IT” approach to train operators still form foundations of day-to-day operations.
  • 5. The potential weakness • Cyber-physical assault: Combined physical & cyber attack. • Do emergency response plans hold up when both IT and physical infrastructure is physically attacked?
  • 6. How to investigate? • Extensive emergency response plans exist. Drills are performed regularly. • Let’s simulate! • But wait! Paper-based rehearsals don’t actually use ICT systems. How to simulate? • We need to simulate both the actions of drill participants and breakdowns of IT systems. • We have to be sure no-one “cheats” by accidentally assuming some system is functioning.
  • 7. Declarative Process Models • Formal model of emergency response process. • Give enormous freedom within a set of rules. • No-one cheats accidentally; the model won’t allow it.
  • 9. How do we try this out? 
 How do we get the process model?
  • 11. Collaborative mapping • Extensive documentation of emergency response procedures exists. • We sat down with domain experts from DSB & BaneDanmark and constructed a model based on that documentation.
  • 13. How do we know whether this model is meaningful?
  • 14. Collaborative simulation • Simulation gives the ability to explore un- anticipated paths and “what-if” scenarios. • Collaborative simulation brings a new level of realism, especially for coordination problems of emergency response scenarios.
  • 15. Simulation study, Metropol • At Metropol, students of Emergency and Risk Management as participants. • Tool provided insufficient overview. • Tool did not hide available and executed actions of other participants .
  • 16. Simulation study, DSB • At DSB, with DSB emergency response team lead and experienced train driver. • Recommendations: 
 Pictures, text, documentation in-tool.
  • 18. Conclusions • Collaborative mapping and simulation of emergency response processes is a viable means of studying ICT/Cyber-physical vulnerabilities. • DCR Formalism accessible to domain experts (with assistance) • DCR Tooling almost there.
  • 19. Future work • Integrating the IT system landscape into the model.