Securing Convergent Ultra-large Scale Infrastructures
Lead Research Organisation:
University of Bristol
Department Name: Computer Science
Abstract
Digital infrastructures are seeing convergence and connectivity at unprecedented scale. This is true for both current critical national infrastructures and emerging future systems, e.g., smart cities, intelligent transportation, high-value manufacturing and Industry 4.0. Cyber security of such ultra-large scale infrastructures faces unprecedented complexity. Diverse legacy and non-legacy software and hardware compose on-the-fly to deliver services to millions of users with varying requirements and unpredictable actions. This complexity is compounded by intricate supply-chains and the need to deliver resilient operations in the presence of untrusted, partially trusted or compromised elements. The integrated exploration of such ultra-large scale, compositionally secure infrastructures is an imperative need, yet to be comprehensively scoped in the research community. There is an urgent need to pivot our perspective away from piecemeal solutions to one that takes a compositional, adaptive view, anticipating and addressing the security challenges arising from hitherto unprecedented complexity, heterogeneity and connectivity. Furthermore, shifting established research paradigms from an ideal vision of security-by-design to the reality of securing-a-compromised-system is imperative.
SCULI will drive this paradigm-shift to predictable security assurances in the presence of uncertainty. This holds the key to addressing the grand challenge of provisioning security at the societal scale—highly interconnected, dynamic, structureless, on-demand systems and services. To do so, it will deliver rapid research advances in four fundamental but interlinked research challenges:
Predictability at ultra-large scale: How to elicit, specify and validate security assurances for service composition in the presence of uncertainty, dynamism and human behaviour (including addressing direct and indirect dependencies and resulting systemic risks)?
Composition at ultra-large scale: How to compose and orchestrate security provision across diverse and heterogeneous evolving infrastructures with legacy and non-legacy elements that change over a long infrastructure lifespan?
Continual assurance at ultra-large scale: How to reason, to requisite levels of accuracy and at an appropriate pace, about the security state at runtime to provide continuity of oversight and trust, when several elements may be partially trusted, under attack, vulnerable or compromised?
Incident response at ultra-large scale: How to orchestrate incident response in a manner that accounts for heterogeneous incident response practices in constituent systems and provides situational awareness at the necessary pace and resolution for human-machine decision-making?
SCULI's research advances will deliver future security provision in digital infrastructures underpinning society for the next several decades. From a practical standpoint, embracing the challenges of delivering security in the context of such highly distributed, independent (individually) yet co-dependent (collectively), infrastructures is the only way to build a resilient digital backbone for industry and society. From a policy perspective, this is critical to the UK's socio-economic prosperity as reflected in the National Cyber Strategy (December 2021). From a citizens and public discourse perspective, this is key to transforming the narrative on cyber security from fear, uncertainty and doubt to predictable, continual assurance, and accountable decision-making when securing societal-scale infrastructures.
SCULI will drive this paradigm-shift to predictable security assurances in the presence of uncertainty. This holds the key to addressing the grand challenge of provisioning security at the societal scale—highly interconnected, dynamic, structureless, on-demand systems and services. To do so, it will deliver rapid research advances in four fundamental but interlinked research challenges:
Predictability at ultra-large scale: How to elicit, specify and validate security assurances for service composition in the presence of uncertainty, dynamism and human behaviour (including addressing direct and indirect dependencies and resulting systemic risks)?
Composition at ultra-large scale: How to compose and orchestrate security provision across diverse and heterogeneous evolving infrastructures with legacy and non-legacy elements that change over a long infrastructure lifespan?
Continual assurance at ultra-large scale: How to reason, to requisite levels of accuracy and at an appropriate pace, about the security state at runtime to provide continuity of oversight and trust, when several elements may be partially trusted, under attack, vulnerable or compromised?
Incident response at ultra-large scale: How to orchestrate incident response in a manner that accounts for heterogeneous incident response practices in constituent systems and provides situational awareness at the necessary pace and resolution for human-machine decision-making?
SCULI's research advances will deliver future security provision in digital infrastructures underpinning society for the next several decades. From a practical standpoint, embracing the challenges of delivering security in the context of such highly distributed, independent (individually) yet co-dependent (collectively), infrastructures is the only way to build a resilient digital backbone for industry and society. From a policy perspective, this is critical to the UK's socio-economic prosperity as reflected in the National Cyber Strategy (December 2021). From a citizens and public discourse perspective, this is key to transforming the narrative on cyber security from fear, uncertainty and doubt to predictable, continual assurance, and accountable decision-making when securing societal-scale infrastructures.
Organisations
- University of Bristol (Lead Research Organisation)
- National Cyber Security Centre (Project Partner)
- Hewlett-Packard Limited (Project Partner)
- SETsquared Partnership (Project Partner)
- Engine Shed (Project Partner)
- Singapore University of Tech & Design (Project Partner)
- BAE (Project Partner)
- BT plc (Project Partner)
- Airbus Group Limited(Airbus Group Ltd) (Project Partner)
- Academia Sinica Taiwan (Project Partner)
- DUKE (Project Partner)
- Vodafone UK Limited (Project Partner)
- CMU (Project Partner)
- RISE - Research Institutes of Sweden AB (Project Partner)
| Description | CySpace working group |
| Form Of Engagement Activity | Participation in an activity, workshop or similar |
| Part Of Official Scheme? | No |
| Geographic Reach | National |
| Primary Audience | Other audiences |
| Results and Impact | Members of the SCULI team from both the University of Bristol and Lancaster University attended a workshop from the CySpace working group on 25 February 2025. |
| Year(s) Of Engagement Activity | 2025 |
| Description | Interview on Cybersecurity Risks of Cloud Technology |
| Form Of Engagement Activity | A talk or presentation |
| Part Of Official Scheme? | No |
| Geographic Reach | National |
| Primary Audience | Other audiences |
| Results and Impact | SCULI co-I Neeraj Suri was invited to be interviewed by the Department of Science, Innovation and Technology (DSIT) on Cybersecurity Risks on Cloud Technology on 07 February 2025. |
| Year(s) Of Engagement Activity | 2025 |
| Description | Interview with BBC News - NHS hospital cyber attack |
| Form Of Engagement Activity | A press release, press conference or response to a media enquiry/interview |
| Part Of Official Scheme? | No |
| Geographic Reach | International |
| Primary Audience | Public/other audiences |
| Results and Impact | Professor Awais Rashid was invited to be interviewed by BBC News regarding a cyber attack on a London NHS hospital in June 2024. |
| Year(s) Of Engagement Activity | 2024 |
| URL | https://www.bbc.co.uk/news/articles/c288n8rkpvno |
| Description | Interview with Channel 5 on NHS hospital cyber attack |
| Form Of Engagement Activity | A press release, press conference or response to a media enquiry/interview |
| Part Of Official Scheme? | No |
| Geographic Reach | International |
| Primary Audience | Public/other audiences |
| Results and Impact | Professor Awais Rashid was invited to be interviewed by Channel 5 News regarding a cyber attack on a London NHS hospital in June 2024. |
| Year(s) Of Engagement Activity | 2024 |
| Description | Meeting with ESA/Airbus - Cybersecurity Retreat (Busum) |
| Form Of Engagement Activity | A formal working group, expert panel or dialogue |
| Part Of Official Scheme? | No |
| Geographic Reach | International |
| Primary Audience | Other audiences |
| Results and Impact | Professor Neeraj Suri from Lancaster University attended the Cybersecurity Retreat in Busum, Germany on 25-29 October 2024 to discuss further collaboration activities with ESA and Airbus. |
| Year(s) Of Engagement Activity | 2024 |
| Description | Meeting with Philips/NXP at Free Univ, A.Legal (TUV Nord) |
| Form Of Engagement Activity | A formal working group, expert panel or dialogue |
| Part Of Official Scheme? | No |
| Geographic Reach | International |
| Primary Audience | Industry/Business |
| Results and Impact | Professor Neeraj Suri from Lancaster University met with Philips/NXP to discuss further collaboration with them at Free Univ, A.Legal, TUV Nord in The Netherlands on 14-16 November 2024. |
| Year(s) Of Engagement Activity | 2024 |
| Description | Panel member at RossFest Symposium |
| Form Of Engagement Activity | A formal working group, expert panel or dialogue |
| Part Of Official Scheme? | No |
| Geographic Reach | National |
| Primary Audience | Other audiences |
| Results and Impact | Awais Rashid was invited to be part of a thematic panel at the RossFest Symposium held in Cambridge on 25 March 2025. |
| Year(s) Of Engagement Activity | 2025 |
| URL | https://www.cl.cam.ac.uk/events/rossfest/ |
| Description | Presentation at Industrial Control Systems - Community of Interest event |
| Form Of Engagement Activity | A talk or presentation |
| Part Of Official Scheme? | No |
| Geographic Reach | National |
| Primary Audience | Other audiences |
| Results and Impact | Awais Rashid was invited to speak at the ICS-COI where he gave an overview of the SCULI programme of work on 06 November 2024. |
| Year(s) Of Engagement Activity | 2024 |
| URL | https://ritics.org/ics-coi/#events |
| Description | Presentation at RITICS Showcase 2025 |
| Form Of Engagement Activity | A talk or presentation |
| Part Of Official Scheme? | No |
| Geographic Reach | National |
| Primary Audience | Other audiences |
| Results and Impact | Awais Rashid was invited to attend the annual RITICS Showcase held in London on 29 January 2025 to give an overview of the SCULI programme. |
| Year(s) Of Engagement Activity | 2024 |
| URL | https://ritics.org/event/ritics-showcase-2025/ |
