首页> 外文会议>International Conference on Microelectronics >A Security Qualification Matrix to Efficiently Measure Security in Cyber-Physical Systems
【24h】

A Security Qualification Matrix to Efficiently Measure Security in Cyber-Physical Systems

机译:安全资格矩阵,以有效地测量网络 - 物理系统安全性

获取原文

摘要

Implementations of Cyber-Physical Systems (CPS), like the Internet of Things, Smart Factories or Smart Grid gain more and more impact in their fields of application, as they extend the functionality and quality of the offered services significantly. However, the coupling of safety-critical embedded systems and services of the cyber-space domain introduce many new challenges for system engineers. Especially, the goal to achieve a high level of security throughout CPS presents a major challenge. However, it is necessary to develop and deploy secure CPS, as vulnerabilities and threats may lead to a non- or maliciously modified functionality of the CPS. This could ultimately cause harm to life of involved actors, or at least sensitive information can be leaked or lost. Therefore, it is essential that system engineers are aware of the level of security of the deployed CPS. For this purpose, security metrics and security evaluation frameworks can be utilized, as they are able to quantitatively express security, based on different measurements and rules. However, existing security scoring solutions may not be able to generate accurate security scores for CPS, as they insufficiently consider the typical CPS characteristics, like the communication of heterogeneous systems of physical- and cyber-space domain in an unpredictable manner. Therefore, we propose a security analysis framework, called Security Qualification Matrix (SQM). The SQM is capable to analyses multiple attacks on a System-of-Systems level simultaneously. With this approach, dependencies, potential side effects and the impact of mitigation concepts can quickly be identified and evaluated.
机译:像物联网,智能工厂或智能电网的实施方式,智能工厂或智能电网在其应用领域的影响,因为它们显着扩展了所提供的服务的功能和质量。然而,网络 - 空间域的安全关键嵌入式系统和服务的耦合为系统工程师带来了许多新的挑战。特别是,在整个CPS中实现高度安全的目标会提出重大挑战。但是,有必要开发和部署安全CP,因为漏洞和威胁可能导致CPS的非暴力或恶意修改的功能。这可能最终导致涉及参与者的生活危害,或者至少可以泄露或丢失敏感信息。因此,系统工程师必须了解已部署的CP的安全性。为此目的,可以使用安全度量和安全评估框架,因为它们能够根据不同的测量和规则定量表达安全性。然而,现有的安全评分解决方案可能无法为CPS产生准确的安全分数,因为它们不充分地考虑典型的CPS特性,如以不可预测的方式的物理和网络空间域的异构系统的通信。因此,我们提出了一种被称为安全资格矩阵(SQM)的安全分析框架。 SQM能够同时分析系统系统上的多次攻击。通过这种方法,可以快速识别和评估依赖性,潜在的副作用和缓解概念的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号