首页> 外文OA文献 >A Threat-Vulnerability Based Risk Analysis Model for Cyber Physical System Security
【2h】

A Threat-Vulnerability Based Risk Analysis Model for Cyber Physical System Security

机译:基于威胁脆弱性的网络物理系统安全风险分析模型

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The ability to network machinery and devices that are otherwise isolated is highly attractive to industry. This has led to growth in the use of cyber-physical systems (CPSs) with existing infrastructure. However, coupling physical and cyber processes leaves CPSs vulnerable to security attacks. A threat-vulnerability based risk model is developed through a detailed analysis of CPS security attack structures and threats. The Stuxnet malware attack is used to test the viability of the proposed model. An analysis of the Natanz system shows that, with an actual case security-risk score at Mitigation level 5, the infested facilities barely avoided a situation worse than the one which occurred. The paper concludes with a discussion on the need for risk analysis as part of CPS security and highlights the future work of modelling and comparing existing security solutions using the proposed model so to identify the sectors where CPS security is still lacking.
机译:对机械设备进行隔离的网络连接能力对行业非常有吸引力。这导致在现有基础架构中使用电子物理系统(CPS)的增长。但是,物理过程和网络过程的耦合使CPS容易受到安全攻击。通过对CPS安全攻击结构和威胁的详细分析,开发了基于威胁漏洞的风险模型。 Stuxnet恶意软件攻击用于测试所提出模型的可行性。对Natanz系统的分析表明,如果实际案例的安全风险评分为缓解级别5,则受感染的设施几乎无法避免比发生的情况更糟的情况。本文最后讨论了作为CPS安全性一部分的风险分析的必要性,并着重指出了使用建议的模型对现有安全性解决方案进行建模和比较的未来工作,以识别仍缺乏CPS安全性的部门。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号