A Scoring System to efficiently measure Security in Cyber-Physical Systems

被引:1
|
作者
Aigner, Andreas [1 ]
Khelil, Abdelmajid [1 ]
机构
[1] Landshut Univ Appl Sci, Dept Comp Sci, Landshut, Germany
来源
2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020) | 2020年
关键词
Security Scoring; Security Metrics; Security Analysis; Threat Analysis; Security Engineering; Cyber-Physical Systems; Internet of Things;
D O I
10.1109/TrustCom50675.2020.00151
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
the importance of Cyber-Physical Systems (CPS) gains more and more weight in our daily business and private life. Although CPS build the backbone for major trends, like Industry 4.0 and connected vehicles, they also propose many new challenges. One major challenge can be found in achieving a high level of security within such highly connected environments, in which an unpredictable number of heterogeneous systems with often-distinctive characteristics interact with each other. In order to develop high-level security solutions, system designers must eventually know the current level of security of their specification. To this end, security metrics and scoring frameworks are essential, as they quantitatively express security of a given design or system. However, existing solutions may not be able to handle the proposed challenges of CPS, as they mainly focus on one particular system and one specific attack. Therefore, we aim to elaborate a security scoring mechanism, which can efficiently be used in CPS, while considering all essential information. We break down each system within the CPS into its core functional blocks and analyze a variety of attacks in terms of exploitability, scalability of attacks, as well as potential harm to targeted assets. With this approach, we get an overall assessment of security for the whole CPS, as it integrates the security-state of all interacting systems. This allows handling the presented complexity in CPS in a more efficient way, than existing solutions.
引用
收藏
页码:1142 / 1146
页数:5
相关论文
共 50 条
  • [1] A Security Qualification Matrix to Efficiently Measure Security in Cyber-Physical Systems
    Aigner, Andreas
    Khelil, Abdelmajid
    2020 32ND INTERNATIONAL CONFERENCE ON MICROELECTRONICS (ICM), 2020, : 174 - 177
  • [2] A Benchmark of Security Metrics in Cyber-Physical Systems
    Aigner, Andreas
    Khelil, Abdelmajid
    2020 IEEE INTERNATIONAL CONFERENCE ON SENSING, COMMUNICATION AND NETWORKING (SECONWORKSHOPS), 2020,
  • [3] Modeling security in cyber-physical systems
    Burmester, Mike
    Magkos, Ernmanouil
    Chrissikopoulos, Vassilis
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2012, 5 (3-4) : 118 - 126
  • [4] Security Games for Cyber-Physical Systems
    Vigo, Roberto
    Bruni, Alessandro
    Yuksel, Ender
    SECURE IT SYSTEMS, NORDSEC 2013, 2013, 8208 : 17 - 32
  • [5] A survey on the security of cyber-physical systems
    Wu G.
    Sun J.
    Chen J.
    Control Theory and Technology, 2016, 14 (1) : 2 - 10
  • [6] Understanding the impact of cyber-physical correlation on security analysis of Cyber-Physical Systems
    Jiang, Luanjuan
    Chen, Xin
    2021 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS DASC/PICOM/CBDCOM/CYBERSCITECH 2021, 2021, : 529 - 534
  • [7] A Semantic Security Model for Cyber-Physical Systems to Identify and Evaluate Potential Threats and Vulnerabilities
    Aigner, Andreas
    Khelil, Abdelmajid
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, BIG DATA AND SECURITY (IOTBDS), 2022, : 249 - 257
  • [8] Boosting Cyber-Physical System Security
    Kutzler, Tobias
    Wolter, Alexandra
    Kenner, Andy
    Dassow, Stephan
    IFAC PAPERSONLINE, 2021, 54 (01): : 976 - 981
  • [9] Designed-in Security for Cyber-Physical Systems
    Peisert, Sean
    Margulies, Jonathan
    Nicol, David M.
    Khurana, Himanshu
    Sawall, Chris
    IEEE SECURITY & PRIVACY, 2014, 12 (05) : 9 - 12
  • [10] Incremental Security Enforcement for Cyber-Physical Systems
    Panda, Abhinandan
    Baird, Alex
    Pinisetty, Srinivas
    Roop, Partha
    IEEE ACCESS, 2023, 11 : 18475 - 18498