Towards a Threat Modeling Approach Addressing Security and Safety in OT Environments

被引:14
|
作者
Hollerer, Siegfried [1 ]
Kastner, Wolfgang [1 ]
Sauter, Thilo [2 ,3 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Technol, Vienna, Austria
[3] Danube Univ Krems, Integr Sensor Syst, Krems An Der Donau, Austria
来源
17TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2021 (WFCS 2021) | 2021年
关键词
Threat Modeling; OT Security; Safety; Industry; 4.0; IT/OT convergence;
D O I
10.1109/WFCS46889.2021.9483591
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In Industry 4.0, Information Technology (IT) and Operational Technology (OT) tend to converge further with an increasing interdependence of safety and security issues to be considered. On one hand, cyber attacks are possible which can alter implemented safety functionality leading to situations where people are harmed, serious injuries may occur or the environment gets damaged. On the other side, safety can also impact security. For instance, the misuse of a Safety Instrumented System (SIS) may force a machine or a production line to shut down resulting in a denial of service. To prevent or mitigate risks from such scenarios, this paper proposes a threat modeling technique which addresses an integrated view on safety and security. The approach is tailored to the industrial automation domain considering plausible attacks and evaluating risks based on three different metrics. The metrics selected consist of Common Vulnerability Scoring System (CVSS) used as an international standard for rating cyber security vulnerabilities, Security Level (SL) from IEC 62443 to rate cyber security risks in OT environments w.r.t. the underlying architecture, and Safety Integrity Level (SIL) from IEC 61508 to rate safety risks. Due to the variety of use cases involving the chosen metrics, the approach is also feasible for followup analyses, such as integrated safety and security assessments or audits.
引用
收藏
页码:37 / 40
页数:4
相关论文
共 50 条
  • [1] Risk Assessments Considering Safety, Security, and Their Interdependencies in OT Environments
    Hollerer, Siegfried
    Sauter, Thilo
    Kastner, Wolfgang
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [2] Cyber Security Threat Modeling for Supply Chain Organizational Environments
    Yeboah-Ofori, Abel
    Islam, Shareeful
    FUTURE INTERNET, 2019, 11 (03)
  • [3] Towards an Ontological Approach to Information System Security and Safety Requirement Modeling and Reuse
    Arogundade, O. T.
    Akinwale, A. T.
    Jin, Z.
    Yang, X. G.
    INFORMATION SECURITY JOURNAL, 2012, 21 (03): : 137 - 149
  • [4] NFT Security Matrix: Towards Modeling NFT Ecosystem Threat
    Liao, Peng
    Liu, Chaoge
    Yin, Jie
    Wang, Zhi
    Cui, Xiang
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2024, 139 (03): : 3255 - 3285
  • [5] Security Threat Modeling for Power Transformers Cyber-Physical Environments
    Ahn, BoHyun
    Kim, Taesic
    Smith, Scott C.
    Youn, Young-Woo
    Ryu, Myung-Hyo
    2021 IEEE POWER & ENERGY SOCIETY INNOVATIVE SMART GRID TECHNOLOGIES CONFERENCE (ISGT), 2021,
  • [6] Security threat modeling and analysis: A goal-oriented approach
    Oladimeji, Ebenezer A.
    Supakkul, Sam
    Chung, Lawrence
    PROCEEDINGS OF THE 10TH IASTED INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND APPLICATIONS, 2006, : 178 - 185
  • [7] A Threat-Driven Approach to Modeling a Campus Network Security
    Naagas, Marlon A.
    Palaoag, Thelma D.
    PROCEEDINGS OF 2018 6TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND BROADBAND NETWORKING (ICCBN 2018), 2018, : 6 - 12
  • [8] A Lightweight Threat Analysis Approach Intertwining Safety and Security for the Automotive Domain
    Duerrwang, Juergen
    Beckers, Kristian
    Kriesten, Reiner
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2017, 2017, 10488 : 305 - 319
  • [9] Towards a unified approach to safety and security in automotive systems
    Jesty, Peter H.
    Ward, David D.
    SAFETY OF SYSTEMS, 2007, : 21 - 34
  • [10] Addressing another threat to food safety: Conflict
    Ortega-Beltran, Alejandro
    Bandyopadhyay, Ranajit
    PLANTS PEOPLE PLANET, 2023, 5 (03) : 317 - 323