Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal
Safety methods for cyber security: using statecharts for the analysis of a cyber attack
EDF R&D Palaiseau, France.
EDF R&D Palaiseau, France.
EDF R&D Palaiseau, France.
ABSTRACT
The significant increase in cyberattacks targeting the OT domain since 2022 and the growing number of cybersecurity requirements applicable to critical infrastructure require to implement more effective and practical cybersecurity risk management. Cyberattacks can be a potential source of failure in safety systems, thereby impacting safety, availability, and the lifespan of critical infrastructure such as nuclear power plants. Operational safety has long provided methods to analyze and quantify the risk associated to differents scenarios raising from an initiating event. and tools can therefore be suitable for the analysis of a cyberattack scenarios. Boolean methods (fault trees and event trees) have been historically used in probabilistic risk and safety assessment. Dynamic probabilistic risk and safety assessment methods are developed to explicitly account for timings of event in the accidental scenarios. In this work, we use statecharts, a formalism recently adopted for dynamic probabilistic risk assessment, for the analysis of a cyber-attack. Current approaches used in cyber analysis are mostly IT-oriented. These methods do not allow for a graphical representation and probabilities are only accounted in a qualitative way. The statecharts are a graphical approach that allow to visualize the systems, and account explicitly for dynamic interactions and the inter-dependencies amongst different part of the system. Moreover, the approach allows to integrate probabilities for quantitative insights. We analysed the following cyber-attack: a user receives emails containing malicious links, the user, who may inadvertently click on such links, regularly accesses a high-performance computing system - the ultimate target of the attack. The model incorporates protective measures such as antivirus software, system updates, and firewalls. Risk importance measures are calculated to gain insights and assess the efficiency of different security barriers.
Keywords: Dynamic PSA, statecharts, cyber-security.

