...
首页> 外文期刊>Journal of software: evolution and process >Security risks in cyber physical systems—A systematic mapping study
【24h】

Security risks in cyber physical systems—A systematic mapping study

机译:网络物理系统中的安全风险 - 系统映射研究

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The increased need for constant connectivity and complete automation of existing systems fuels the popularity of Cyber Physical Systems (CPS) worldwide. Increasingly more, these systems are subjected to cyber attacks. In recent years, many major cyber-attack incidents on CPS have been recorded and, in turn, have been raising concerns in their users' minds. Unlike in traditional IT systems, the complex architecture of CPS consisting of embedded systems integrated with the Internet of Things (IoT) requires rather extensive planning, implementation, and monitoring of security requirements. One crucial step to planning, implementing, and monitoring of these requirements in CPS is the integration of the risk management process in the CPS development life cycle. Existing studies do not clearly portray the extent of damage that the unattended security issues in CPS can cause or have caused, in the incidents recorded. An overview of the possible risk management techniques that could be integrated into the development and maintenance of CPS contributing to improving its security level in its actual environment is missing. In this paper, we are set out to highlight the security requirements and issues specific to CPS that are discussed in scientific literature and to identify the state-of-the-art risk management processes adopted to identify, monitor, and control those security issues in CPS. For that, we conducted a systematic mapping study on the data collected from 312 papers published between 2000 and 2020, focused on the security requirements, challenges, and the risk management processes of CPS. Our work aims to form an overview of the security requirements and risks in CPS today and of those published contributions that have been made until now, towards improving the reliability of CPS. The results of this mapping study reveal (ⅰ) integrity authentication and confidentiality as the most targeted security attributes in CPS, (ⅱ) model-based techniques as the most used risk identification and assessment and management techniques in CPS, (ⅲ) cyber-security as the most common security risk in CPS, (ⅳ) the notion of “mitigation measures” based on the type of system and the underline internationally recognized standard being the most used risk mitigation technique in CPS, (ⅴ) smart grids being the most targeted systems by cyber-attacks and thus being the most explored domain in CPS literature, and (ⅵ) one of the major limitations, according to the selected literature, concerns the use of the fault trees for fault representation, where there is a possibility of runtime system faults not being accounted for. Finally, the mapping study draws implications for practitioners and researchers based on the findings.
机译:增加的需求需求恒定连接和现有系统的完全自动化燃料燃料全球网络物理系统(CPS)的普及。越来越多地,这些系统受到网络攻击。近年来,已记录了许多关于CP的主要网络攻击事件,并反过来,一直在提高用户思想的担忧。与传统的IT系统不同,CPS的复杂架构由集成与物联网(物联网)集成的嵌入式系统需要相当广泛的规划,实施和监控安全要求。规划,实施和监测CPS中这些要求的一个关键步骤是在CPS开发生命周期中的风险管理过程集成。现有的研究没有明确描绘损害的程度,即在录制的事件中可以造成或已经造成的无人看管的安全问题可能导致或已经造成的损害。概述可能集成到CPS的开发和维护的可能风险管理技术缺失在其实际环境中提高其安全级别的CPS。在本文中,我们被列为突出了科学文学中讨论的安全要求和特定于CP的问题,并确定了用于识别,监测和控制这些安全问题的最先进的风险管理进程CPS。为此,我们对2000年至2020年之间发布的312篇论文收集的数据进行了系统的映射研究,专注于CPS的安全要求,挑战和风险管理进程。我们的工作旨在概述今日CPS的安全要求和风险,并于目前展出的那些发布的捐款,以提高CPS的可靠性。该映射研究的结果显示(Ⅰ)完整性认证和机密性作为CPS中最具针对性的安全属性,(Ⅱ)基于模型的技术,作为CPS,(Ⅲ)网络安全中最使用的风险识别和评估和管理技术作为CPS中最常见的安全风险,(ⅳ)基于系统类型的“缓解措施”的概念和强调国际公认的标准是CPS中最常用的风险缓解技术,(ⅴ)智能电网是最有针对性的通过网络攻击的系统,因此是CPS文献中最探索的域,(ⅵ)根据所选文献的主要限制之一,涉及使用故障树用于故障表示,存在运行时的可能性系统故障未被占。最后,映射研究基于调查结果对从业者和研究人员提出了影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号