Capturing Agents in Security Models
Total Page:16
File Type:pdf, Size:1020Kb
Delft University of Technology Capturing Agents in Security Models Agent-based Security Risk Management using Causal Discovery Janssen, Stef DOI 10.4233/uuid:f9bbff72-b9b4-4694-a188-b2f1451449af Publication date 2020 Document Version Final published version Citation (APA) Janssen, S. (2020). Capturing Agents in Security Models: Agent-based Security Risk Management using Causal Discovery. https://doi.org/10.4233/uuid:f9bbff72-b9b4-4694-a188-b2f1451449af Important note To cite this publication, please use the final published version (if applicable). Please check the document version above. Copyright Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons. Takedown policy Please contact us and provide details if you believe this document breaches copyrights. We will remove access to the work immediately and investigate your claim. This work is downloaded from Delft University of Technology. For technical reasons the number of authors shown on this cover page is limited to a maximum of 10. CAPTURING AGENTS IN SECURITY MODELS AGENT-BASED SECURITY RISK MANAGEMENT USING CAUSAL DISCOVERY CAPTURING AGENTS IN SECURITY MODELS AGENT-BASED SECURITY RISK MANAGEMENT USING CAUSAL DISCOVERY Dissertation for the purpose of obtaining the degree of doctor at Delft University of Technology, by the authority of the Rector Magnificus, prof. dr. ir. T.H.J.J. van der Hagen, chair of the Board for Doctorates, to be defended publicly on Thursday 9 April 2020 at 12:30 o’clock By Stef Antoine Maria JANSSEN Master of Science in Operations Research, Maastricht University, Maastricht, The Netherlands, born in Arcen en Velden, The Netherlands. This dissertation has been approved by the promotors. Composition of the doctoral committee: Rector Magnificus, chairperson Prof. dr. K. G. Langendoen, Delft University of Technology, promotor Prof. dr. R. Curran, Delft University of Technology, promotor Dr. O. A. Sharpans’kykh, Delft University of Technology, copromotor Independent members: Dr. J. Skorupski, Warsaw University of Technology, Poland Dr. A. I. Barros, TNO Dr. M. T. J. Spaan, Delft University of Technology Prof. dr. ir. G. L. L. M. E. Reniers, Delft University of Technology Prof. dr. ir. J. M. Hoekstra, Delft University of Technology, reserve member This research was partly funded by the Dutch Ministry of Economic Affairs under the Topsectoren policy for High Tech Systems and Materials. Keywords: Security Risk Management, Agent-based Modelling, Causal Discovery, Airport Terminal Printed by: Ipskamp Printing, Enschede Front & Back: W.J.J.C. van Wijlick Copyright © 2020 by S.A.M. Janssen ISBN 000-00-0000-000-0 An electronic version of this dissertation is available at http://repository.tudelft.nl/. ACKNOWLEDGEMENTS This thesis is the result of four years of work, which would have been impossible with- out the support of many people. I arrived in Delft without knowing anybody and now finished my PhD with a large group of people that I want to express my gratitude to. Working in both the Air Transport & Operations and the Embedded & Networked Systems groups came with some advantages. First and foremost, my supervisory team consisted of one daily supervisor and additionally two promotors instead of one. Alexei, throughout my PhD you have given me the opportunity to explore the world of academic research with practical guidance and countless opportunities to do new things. You trusted me to develop my own line of research in the agent-based commu- nity and gave me the freedom to do it my way. Without your trust and support, I would not have been able to present my work to all kinds of different audiences, supervise dif- ferent students and interact with various experts in the field. Also on a personal level, I really enjoyed the meetings that we had, that oftentimes were about special holiday destinations, politics or cultures around the world. Koen, on the first day I met you, I got to know you as a fun, honest and direct per- son that I immediately enjoyed working with. While my PhD ended up outside your immediate field of expertise, you provided me with extremely detailed feedback on the writing, presentations, and content I developed. Throughout our meetings, we had a lot of laughs about work, about current-day events and newly thought out government or university policies. You have gradually become a mentor for me that provided me with career and life advice whenever I needed it. We enjoyed a lot of things outside of work as well: swimming, running, biking, and all the group activities we did together were especially nice for me. Ricky, your never-ending enthusiasm and optimism throughout my PhD was really special to experience. You always managed to find positivity in any situation, regardless of the circumstances. You never ceased to amaze me at the speed you had your security- related jokes ready, making our meetings apart from useful also enjoyable. Outside of work I got to experience the same enthusiasm that I saw in the office, during our many ATO trips or at one of your Koperen Kat performances. Another advantage of working in two groups is that I got to meet and work with twice as many colleagues, of which many I now consider friends. Hemmo and Vis, you were among the first people I got to know in Delft and I am very happy I did. We have done countless things together, of which our weekends abroad were major highlights. The stroopwafel incident after the Golden Ten run stands out as well. Elise, thanks to you I never missed any news about my research domain: you provided me with countless tips and contacts that helped shape this thesis. You were always there for a quick chat and a coffee, making my time at the office more fun. Matt, you entered my office and made it a more fun place. We oftentimes shared ideas about each other’s work but also got to enjoy several activities outside the office, such as visiting Noordeinde Palace. Vinh, v vi we got to know each other over a few games of tennis early in my PhD, and we became friends along the way. I really enjoyed visiting you in Vietnam, in which you introduced me to your friends and family, as well as Vietnamese culture and food. Eric, we moved into an office together halfway into my PhD, and I have always en- joyed your company. The major highlight for me was visiting you in your hometown Ezhou in China, in which we got to enjoy good company, delicious food, skillful karaoke performances, and a typical Chinese game bar. Jorik and Belma, I really enjoyed the board game nights, pancake baking adventure and the never-ending stream of random news facts entering our group chat. While writing my PhD thesis, I was lucky to work with many talented Bachelor and Master students. The works of Arjan and Diogo made a vital impact on Chapters3 and5 of this thesis, while contributions of Anne-Nynke, Arthur, and Adin made tangible differ- ences to the development of the models described in this thesis. Finally, the enthusiasm and dedicated data collection effort of Régis allowed me to develop the data-driven ap- proach which now forms Chapter6 of this thesis. I could not have done this research without the help of several people from Rotter- dam The Hague Airport. First, thanks to Steven for enabling this collaboration, and in- troducing me to Alexander. I have got to know you, Alexander, as a very positive person, with whom I really enjoyed working with. You enabled me to combine academic re- search with the practical aspects of airport security, which was a unique experience. A special thanks also to Bas Simons for his help with collecting the data. Outside of Delft, I have also enjoyed the personal support of many people. Thanks to my friends in and outside Limburg for coming to visit me in Delft. And a special thanks to Wessel for designing the cover art of this book. I especially want to thank my family for always being there for me. My parents, for supporting me in whatever challenge, trip, or adventure I decided to undertake. Also thanks to my sisters Sanne, Shenna, and Sharon for their support and company in and outside Velden. Thanks to oma, for the countless lunches, Skip Bo games and a never- ending supply of drop. Finally, I want to thank Sjoukje for coming into my life, bringing more joy and hap- piness. Thank you for all the exciting moments and trips that we experienced together, and for all the times that you were there when I needed it. I am looking forward to much more of that in the future. SUMMARY Airports are important transportation hubs that reside in the heart of modern civiliza- tions. They are of major economic and symbolic value for countries but are therefore also attractive targets for adversaries. Over the years we have observed successful and unsuccessful terrorist attacks at airports, of which the recent Brussels Airport attack and Istanbul Atatürk Airport attack are two examples. A widely-used method to defend airports against these types of events is that of se- curity risk management. Following this approach, security risks are quantified based on threats, vulnerabilities, and consequences. These risks are then used as a basis to imple- ment security measures that can reduce the risks to acceptable levels. Several security risk management approaches were proposed before, such as attack trees and security games, but they struggle to include diverse human factors in their analysis.