Which Attacks Lead to Hazards? Combining Safety and Security Analysis for Cyber-Physical Systems

被引:7
作者
Castiglione, Luca Maria [1 ]
Lupu, Emil C. [1 ]
机构
[1] Imperial Coll London, Dept Comp, London SW7 2BX, England
基金
英国工程与自然科学研究理事会;
关键词
Safety; Security; Formal verification; Analytical models; Accidents; Threat modeling; Process control; safety; formal verification; attack graphs; cyber physical systems; THEORETIC APPROACH; REQUIREMENTS; STPA;
D O I
10.1109/TDSC.2023.3309778
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-Physical Systems (CPS) are exposed to a plethora of attacks and their attack surface is only increasing. However, whilst many attack paths are possible, only some can threaten the system's safety and potentially lead to loss of life. Identifying them is of essence. We propose a methodology and develop a tool-chain to systematically analyse and enumerate the attacks leading to safety violations. This is achieved by lazily combining threat modelling and safety analysis with formal verification and with attack graph analysis. We also identify the minimum sets of privileges that must be protected to preserve safety. We demonstrate the effectiveness of our methodology to discover threat scenarios by applying it to a Communication Based Train Control System. Our design choices emphasise compatibility with existing safety and security frameworks, whilst remaining agnostic to specific tools or attack graphs representations.
引用
收藏
页码:2526 / 2540
页数:15
相关论文
共 74 条
[1]  
Abdulkhaleq A, 2016, Arxiv, DOI arXiv:1612.03103
[2]   A comprehensive safety engineering approach for software-intensive systems based on STPA [J].
Abdulkhaleq, Asim ;
Wagner, Stefan ;
Leveson, Nancy .
PROCEEDINGS OF THE 3RD EUROPEAN STAMP WORKSHOP, 2015, 128 :2-11
[3]   Integrated Safety Analysis Using Systems-Theoretic Process Analysis and Software Model Checking [J].
Abdulkhaleq, Asim ;
Wagner, Stefan .
COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2015, 2015, 9337 :121-134
[4]  
Albanese S., 2012, P IEEE IFIP INT C DE, P1
[5]   Towards System Level Security Analysis of Artificial Pancreas via UPPAAL-SMC [J].
Alshalalfah, Abdel-Latif ;
Hamad, Ghaith Bany ;
Mohamed, Otmane Ait .
2019 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2019,
[6]  
Alur R., 1990, Proceedings. Fifth Annual IEEE Symposium on Logic in Computer Science (90CH2897-7), P414, DOI 10.1109/LICS.1990.113766
[7]  
Ammann P., 2002, CCS 02, P217, DOI [DOI 10.1145/586110.586140, 10.1145/586110.586140]
[8]  
[Anonymous], 2018, ED-203A Airworthiness Security Methods and Considerations
[9]  
[Anonymous], 1999, P SYST SAF C ORL FLO
[10]  
[Anonymous], 2007, Defence Standard 00-56