Research

Logic and formal methods for safety and cybersecurity risk, including fault trees, attack trees, model checking, and ontology.
S.M. Nicoletti

// RESEARCH

Formal methods for risk.

My research combines logic and formal methods with threat and failure modelling for the analysis of safety and cybersecurity risk.

CURRENT DIRECTION

Risk reasoning across safety and cybersecurity

At the University of Twente, I develop formal techniques for safety and cybersecurity risk management. I study risk models that support granular qualitative and quantitative reasoning: What is the minimum cost of attacking a system? What is the probability that a component fails? What changes when an attacker takes a particular step, or when a component does not function as intended?

METHODS

Logics and model checking

I design logics, formal models, and model-checking algorithms for risk assessment. The resulting methods state properties of a model and check them systematically.

MODELS

Fault trees and attack trees

Fault trees represent failures, while attack trees represent adversarial routes. I specify properties over both formal models, including combined models, to analyse safety and security together.

GROWING CONNECTION

Risk modelling and ontology

Ontology now informs part of this work. It clarifies what risk models represent and how they relate, and it supports interoperability across methods and domains. I use it alongside logical and model-checking techniques. See related work ↗