首页> 外文期刊>Computers & Security >Attacks on the Industrial Internet of Things - Development of a multi-layer Taxonomy
【24h】

Attacks on the Industrial Internet of Things - Development of a multi-layer Taxonomy

机译:对工业互联网的攻击 - 多层分类的发展

获取原文
获取原文并翻译 | 示例
       

摘要

The Industrial Internet of Things (IIoT) provides new opportunities to improve process and production efficiency, which enable new business models. At the same time, the high degree of cross-linking and decentralization increases the complexity of IloT systems and creates new vulnerabilities. Hence, organizations are not only vulnerable to conventional IT threats, but also to a multitude of new, IIoT-specific attacks. Yet, a literature-based and empirically evaluated understanding of attacks on the IIoT is still lacking. Against this backdrop, we develop a multi-layer taxonomy that helps researchers and practitioners to identify similarities and differences between attacks on the IIoT. Based on the latest literature and a sample of about 50 attacks, we deductively and inductively determine attack characteristics and dimensions. We demonstrate the usefulness and practical relevance of our taxonomy by applying it to a real-world incident affecting a German steel facility. By combining IT security, IIoT, and risk management to form an interdisciplinary approach, we contribute to the descriptive knowledge in these fields. Industry experts confirm that our taxonomy enables a detailed classification of attacks, which supports the identification, documentation, and communication of incidents within organizations and their value-creation networks. With this, our taxonomy provides a profound basis for the further development of IT security management and the derivation of mitigation measures.
机译:工业互联网(IIT)为提高流程和生产效率提供了新的机会,实现了新的商业模式。与此同时,高度的交联和分散化增加了ILOT系统的复杂性并创造了新的漏洞。因此,组织不仅容易遭受传统的IT威胁,而且还达到了众多新的IIOT特异性攻击。然而,仍然缺乏文学和经验评估对IIOT攻击的理解。在此背景下,我们开发了一个多层分类,帮助研究人员和从业者确定IIOT攻击之间的相似性和差异。基于最新的文献和约50次攻击的样本,我们减少了攻击性和电感地确定了攻击特征和尺寸。我们通过将其应用于影响德国钢铁工厂的真实事件来证明我们的分类物的有用性和实际相关性。通过将IT安全,IIOR和风险管理组合形成跨学科方法,我们有助于这些领域的描述性知识。行业专家证实,我们的分类系统可以详细分类攻击,支持组织内的识别,文档和传播事件及其价值创建网络。有了这一点,我们的分类系统为进一步发展IT安全管理和缓解措施推导提供了深刻的基础。

著录项

  • 来源
    《Computers & Security》 |2020年第6期|101790.1-101790.19|共19页
  • 作者单位

    Project Group Business & Information Systems Engineering of the Fraunhofer FIT Universitaetsstrasse 12. 86159 Augsburg Germany FIM Research Center. University of Augsburg. Universitaetsstrasse 12 86159 Augsburg. Germany;

    FIM Research Center. University of Augsburg. Universitaetsstrasse 12 86159 Augsburg. Germany;

    Project Group Business & Information Systems Engineering of the Fraunhofer FIT Universitaetsstrasse 12. 86159 Augsburg Germany FIM Research Center University of Bayreuth. Wittelsbacherring 10. 95444 Bayreuth Germany;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Industrial Internet of Things; Industry 4.0; IT Security; Attacks; Taxonomy;

    机译:工业互联网;行业4.0;IT安全;攻击;分类;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号