In Quest of Benchmarking Security Risks to Cyber-Physical Systems

被引:65
作者
Amin, Saurabh [1 ]
Schwartz, Galina A. [2 ,3 ]
Hussain, Alefiya [4 ]
机构
[1] MIT, Dept Civil & Environm Engn, Cambridge, MA 02139 USA
[2] Univ Calif Berkeley, Dept Elect Engn & Comp Sci, Berkeley, CA 94720 USA
[3] Univ Calif Berkeley, Dept Econ, Berkeley, CA 94720 USA
[4] Univ So Calif, Inst Informat Sci, Los Angeles, CA 90089 USA
来源
IEEE NETWORK | 2013年 / 27卷 / 01期
关键词
Cyber Physical System;
D O I
10.1109/MNET.2013.6423187
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We present a generic yet practical framework for assessing security risks to cyber-physical systems (CPSs). Our framework can be used to benchmark security risks when information is less than perfect, and interdependencies of physical and computational components may result in correlated failures. Such environments are prone to externalities, and can cause huge societal losses. We focus on the risks that arise from interdependent reliability failures (faults) and security failures (attacks). We advocate that a sound assessment of these risks requires explicit modeling of the effects of both technology-based defenses and institutions necessary for supporting them. Thus, we consider technology-based security defenses grounded in information security tools and fault-tolerant control in conjunction with institutional structures. Our game-theoretic approach to estimating security risks facilitates more effective defenses, especially against correlated failures.
引用
收藏
页码:19 / 24
页数:6
相关论文
共 11 条
[1]  
ALPCAN T., 2011, Network Security: A Decision and Game -theoretic Approach
[2]  
Amin S., 2012, IEEE T CONTROL SYSTE
[3]  
Amin S, 2011, IEEE DECIS CONTR P, P4078, DOI 10.1109/CDC.2011.6161527
[4]  
Benzel T, 2011, 27TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2011), P137
[5]   Catastrophic cascade of failures in interdependent networks [J].
Buldyrev, Sergey V. ;
Parshani, Roni ;
Paul, Gerald ;
Stanley, H. Eugene ;
Havlin, Shlomo .
NATURE, 2010, 464 (7291) :1025-1028
[6]  
Grossi P, 2005, HUEBNER INT SER RISK, V25, P1, DOI 10.1007/b100669
[7]  
Haimes YY., 2009, Risk Modeling, Assessment, and Management
[8]  
Hall C., 2011, P 10 WKSP EC INF SEC
[9]  
Hussain A, 2003, ACM SIGCOMM COMP COM, V33, P99
[10]   Cyber-Physical Security of a Smart Grid Infrastructure [J].
Mo, Yilin ;
Kim, Tiffany Hyun-Jin ;
Brancik, Kenneth ;
Dickinson, Dona ;
Lee, Heejo ;
Perrig, Adrian ;
Sinopoli, Bruno .
PROCEEDINGS OF THE IEEE, 2012, 100 (01) :195-209