Analysis

For both types, petri-nets and log-files, SWAT can carry out security related analyses. This function is available after selecting the analyses mode within the toolbar. The user interface will show additional functions relevant for the analyses on the right side of the editor. From here, new analysis rules can be selected, configured, retrieved or stored. Also the result of the analysis will show up on the right side of SWAT. For Petri-Nets only a small subset of rules are available, however there is a full list of rules available for log-files.
Each rule has different parameters that can be selected by the user. For example, the “Exits P” rule has one parameter. This parameter can be selected by the user and corresponds to a single activity within the log-file or the petri-net model. A drop-down list provides the user with possible inputs, see the following picture.

Rule editor with active and parametrized rule (Four-Eyes Principal)

Rule editor with active and parametrized rule (Four-Eyes Principal)