A Security Scoring Framework to Quantify Security in Cyber-Physical Systems

被引:4
作者
Aigner, Andreas [1 ]
Khelil, Abdelmajid [1 ]
机构
[1] Landshut Univ Appl Sci, IDP Inst, Dept Comp Sci, Landshut, Germany
来源
2021 4TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER-PHYSICAL SYSTEMS, ICPS | 2021年
关键词
Security Scoring; Security Rating; Security Metric; Threat Analysis; Industrial Cyber-Physical Systems;
D O I
10.1109/ICPS49255.2021.9468168
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
the need to achieve a suitable level of security in Cyber-Physical Systems (CPS) presents a major challenge for engineers. The unpredictable communication of highly constrained, but safety-relevant systems in a heterogeneous environment, significantly impacts the number and severity of vulnerabilities. Consequently, if security-related weaknesses can successfully be exploited by attackers, the functionality of critical infrastructure could be denied or malfunction. This might consequently threaten life or leak sensitive information. A tool-kit to quantitatively express security is essential for security engineers in order to define security-enhancing measurements. For this purpose, security scoring frameworks, like the established Common Vulnerability Scoring System can be used. However, existing security scoring frameworks may not be able to handle the proposed challenges and characteristics of CPS. Therefore, in this work, we aim to elaborate a security scoring system that is tailored to the needs of CPS. In detail, we analyze security on a System-of-Systems level, while considering multiple attacks, as well as potential side effects to other security-related objects. The positive effects of integrated mitigation concepts should also be abbreviated by our proposed security score. Additionally, we generate the security score for interacting AUTOSAR platforms in a highly-connected Vehicle-to-everything (V2x) environment. We refer to this highly relevant use case scenario to underline the benefits of our proposed scoring framework and to prove its effectiveness in CPS.
引用
收藏
页码:199 / 206
页数:8
相关论文
共 15 条
[1]  
Aigner A., 2020, P 32 IEEE INT C MICR
[2]  
Aigner A., 2020, P 19 IEEE INT C TRUS
[3]  
Aigner A., 2020, P 2 IEEE WORKSH SEC
[4]   Assessment of Model-based Methodologies to Architect Cyber-Physical Systems [J].
Aigner, Andreas ;
Khelil, Abdelmajid .
INTERNATIONAL CONFERENCE ON OMNI-LAYER INTELLIGENT SYSTEMS (COINS), 2019, :146-151
[5]   A Semantic Model-based Security Engineering Framework for Cyber-Physical Systems [J].
Aigner, Andreas ;
Khelil, Abdelmajid .
2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, :1826-1833
[6]  
Al Ghazo A. T., 2019, P 10 IEEE ANN UB COM
[7]  
Bo H, 2010, P INT C INT COMP TEC
[8]  
Chandramouli R, 2006, Emerging Standards, IEEE Security & Privacy, V4
[9]  
Duc A. N., 2017, PROC XP SCI WORKSHOP, P1
[10]   Organizing security patterns [J].
Hafiz, Munawar ;
Adamczyk, Paul ;
Johnson, Ralph E. .
IEEE SOFTWARE, 2007, 24 (04) :52-+