...
首页> 外文期刊>Computers & Security >Model-based risk assessment for cyber physical systems security
【24h】

Model-based risk assessment for cyber physical systems security

机译:基于模型的网络物理系统安全性风险评估

获取原文
获取原文并翻译 | 示例

摘要

Traditional techniques for Cyber-Physical Systems (CPS) security design either treat the cyber and physical systems independently, or do not address the specific vulnerabilities of real time embedded controllers and networks used to monitor and control physical processes. In this work, we develop and test an integrated model-based approach for CPS security risk assessment utilizing a CPS testbed with real-world industrial controllers and communication protocols. The testbed monitors and controls an exothermic Continuous Stirred Tank Reactor (CSTR) simulated in real-time. CSTR is a fundamental process unit in many industries, including Oil & Gas, Petrochemicals, Water treatment, and nuclear industry. In addition, the process is rich in terms of hazardous scenarios that could be triggered by cyber attacks due to the lack of possible mechanical protection. The paper presents an integrated approach to analyze and design the cyber security system for a given CPS where the physical threats are identified first to guide the risk assessment process. A mathematical model is derived for the physical system using a hybrid automaton to enumerate potential hazardous states of the system. The cyber system is then analyzed using network and data flow models to develop the attack scenarios that may lead to the identified hazards. Finally, the attack scenarios are performed on the testbed and observations are obtained on the possible ways to prevent and mitigate the attacks. The insights gained from the experiments result in several key findings, including the expressive power of hybrid automaton in security risk assessment, the hazard development time and its impact on cyber security design, and the tight coupling between the physical and the cyber systems for CPS that requires an integrated design approach to achieve cost-effective and secure designs.
机译:Cyber​​-Mevice Systems(CPS)安全设计的传统技术无论是独立处理网络和物理系统,还是没有解决用于监视和控制物理过程的实时嵌入式控制器和网络的特定漏洞。在这项工作中,我们开发和测试了利用具有现实世界工业控制器和通信协议的CPS测试的CPS安全风险评估的集成模型方法。试验机监测器并控制实时模拟的放热连续搅拌罐反应器(CSTR)。 CSTR是许多行业的基本流程单位,包括石油和天然气,石化,水处理和核工业。此外,由于缺乏可能的机械保护,该过程就可以通过网络攻击触发的危险场景。本文提出了一种综合方法来分析和设计网络安全系统,了解给定的CPS,首先确定了物理威胁以指导风险评估过程。使用混合自动机的物理系统导出数学模型,以列举系统的潜在危险状态。然后使用网络和数据流模型分析网络系统,以开发可能导致所识别的危险的攻击情景。最后,在测试平台上执行攻击场景,并在可能的方法中获得观察,以防止和减轻攻击。从实验中获得的见解导致了几个关键结果,包括杂交自动化在安全风险评估中的表现力,危险开发时间及其对网络安全设计的影响,以及用于CP的物理和网络系统之间的紧密耦合需要一种集成的设计方法来实现具有成本效益和安全的设计。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号