首页> 外文期刊>Journal of supercomputing >Threats on the horizon: understanding security threats in the era of cyber-physical systems
【24h】

Threats on the horizon: understanding security threats in the era of cyber-physical systems

机译:地平线的威胁:了解网络物理系统时代的安全威胁

获取原文
获取原文并翻译 | 示例

摘要

Disruptive innovations of the last few decades, such as smart cities and Industry 4.0, were made possible by higher integration of physical and digital elements. In today's pervasive cyber-physical systems, connecting more devices introduces new vulnerabilities and security threats. With increasing cybersecurity incidents, cybersecurity professionals are becoming incapable of addressing what has become the greatest threat climate than ever before. This research investigates the spectrum of risk of a cybersecurity incident taking place in the cyber-physical-enabled world using the VERIS Community Database. The findings were that the majority of known actors were from the US and Russia, most victims were from western states and geographic origin tended to reflect global affairs. The most commonly targeted asset was information, with the majority of attack modes relying on privilege abuse. The key feature observed was extensive internal security breaches, most often a result of human error. This tends to show that access in any form appears to be the source of vulnerability rather than incident specifics due to a fundamental trade-off between usability and security in the design of computer systems. This provides fundamental evidence of the need for a major reevaluation of the founding principles in cybersecurity.
机译:通过更高的身体和数字元素的整合,可以实现最近几十年的破坏性创新,如智能城市和行业4.0。在当今普遍的网络物理系统中,连接更多设备介绍了新的漏洞和安全威胁。随着网络安全事件的增加,网络安全专业人员正在无法解决,这些人无法满足最大的威胁气候。本研究通过Veris社区数据库调查了在能够在网络健全的世界中发生的网络安全事件的风险范围。调查结果是,大多数已知的行动者都来自美国和俄罗斯,大多数受害者都来自西方国家,地理来源往往反映全球事务。最常见的资产是信息,大多数攻击模式依赖于特权滥用。观察到的关键特征是广泛的内部安全漏洞,最常见的是人为错误的结果。这倾向于显示任何形式的访问似乎是漏洞的源,而不是事件细节,因为计算机系统设计中的可用性和安全性之间的基本折衷原因。这提供了基本证据证明,需要重新评估网络安全的创始原则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号