首页> 外文OA文献 >STRIDE-based Threat Modeling for Cyber-Physical Systems
【2h】

STRIDE-based Threat Modeling for Cyber-Physical Systems

机译:基于STRIDE的网络物理系统威胁建模

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Critical infrastructures and industrial control systems are complex Cyber-Physical Systems (CPS). To ensure reliable operations of such systems, comprehensive threat modeling during system design and validation is of paramount significance. Previous works in literature mostly focus on safety, risks and hazards in CPS but lack effective threat modeling necessary to eliminate cyber vulnerabilities. Further, impact of cyber attacks on physical processes is not fully understood. This paper presents a comprehensive threat modeling framework for CPS using STRIDE, a systematic approach for ensuring system security at the component level. This paper first devises a feasible and effective methodology for applying STRIDE and then demonstrates it against a real synchrophasor-based synchronous islanding testbed in the laboratory. It investigates (i) what threat types could emerge in each system component based on the security properties lacking, and (ii) how a vulnerability in a system component risks the entire system security. The paper identifies that STRIDE is a light-weight and effective threat modeling methodology for CPS that simplifies the task for security analysts to identify vulnerabilities and plan appropriate component level security measures at the system design stage.
机译:关键基础设施和工业控制系统是复杂的网络物理系统(CPS)。为了确保此类系统的可靠运行,在系统设计和验证过程中进行全面的威胁建模至关重要。先前的文献研究主要集中在CPS中的安全性,风险和危害,但缺乏消除网络漏洞所必需的有效威胁模型。此外,还没有完全了解网络攻击对物理过程的影响。本文提出了使用STRIDE的CPS全面威胁建模框架,STRIDE是在组件级别确保系统安全的系统方法。本文首先设计了一种可行且有效的方法来应用STRIDE,然后在实验室中针对基于实际同步相量的同步孤岛测试平台进行了演示。它研究(i)根据缺乏的安全属性在每个系统组件中可能出现什么威胁类型,以及(ii)系统组件中的漏洞如何危及整个系统的安全性。本文确定STRIDE是CPS的轻量级有效威胁建模方法,可简化安全分析人员在系统设计阶段识别漏洞并计划适当组件级安全措施的任务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号