Towards a Threat Modeling Approach Addressing Security and Safety in OT Environments

被引:14
|
作者
Hollerer, Siegfried [1 ]
Kastner, Wolfgang [1 ]
Sauter, Thilo [2 ,3 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Technol, Vienna, Austria
[3] Danube Univ Krems, Integr Sensor Syst, Krems An Der Donau, Austria
来源
17TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2021 (WFCS 2021) | 2021年
关键词
Threat Modeling; OT Security; Safety; Industry; 4.0; IT/OT convergence;
D O I
10.1109/WFCS46889.2021.9483591
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In Industry 4.0, Information Technology (IT) and Operational Technology (OT) tend to converge further with an increasing interdependence of safety and security issues to be considered. On one hand, cyber attacks are possible which can alter implemented safety functionality leading to situations where people are harmed, serious injuries may occur or the environment gets damaged. On the other side, safety can also impact security. For instance, the misuse of a Safety Instrumented System (SIS) may force a machine or a production line to shut down resulting in a denial of service. To prevent or mitigate risks from such scenarios, this paper proposes a threat modeling technique which addresses an integrated view on safety and security. The approach is tailored to the industrial automation domain considering plausible attacks and evaluating risks based on three different metrics. The metrics selected consist of Common Vulnerability Scoring System (CVSS) used as an international standard for rating cyber security vulnerabilities, Security Level (SL) from IEC 62443 to rate cyber security risks in OT environments w.r.t. the underlying architecture, and Safety Integrity Level (SIL) from IEC 61508 to rate safety risks. Due to the variety of use cases involving the chosen metrics, the approach is also feasible for followup analyses, such as integrated safety and security assessments or audits.
引用
收藏
页码:37 / 40
页数:4
相关论文
共 50 条
  • [11] A Systematic Approach to Threat Modeling and Security Analysis for Software Defined Networking
    Eom, Taehoon
    Hong, Jin B.
    An, Seongmo
    Park, Jong Sou
    Kim, Dong Seong
    IEEE ACCESS, 2019, 7 : 137432 - 137445
  • [12] The insider threat to nuclear safety and security
    Healey, Andrew N.
    SECURITY JOURNAL, 2016, 29 (01) : 23 - 38
  • [13] The insider threat to nuclear safety and security
    Andrew N Healey
    Security Journal, 2016, 29 : 23 - 38
  • [14] Integrated Safety and Security by Design in the IT/OT Convergence of Industrial Systems: A Graph-Based Approach
    Amiri, Amirali
    Steindl, Gernot
    Gorton, Ian
    Hollerer, Siegfried
    Kastner, Wolfgang
    Sauter, Thilo
    2024 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE SERVICES ENGINEERING, SSE 2024, 2024, : 123 - 129
  • [15] Towards a Systematic Threat Modeling Approach for Cyber-physical Systems
    Martins, Goncalo
    Bhatia, Sajal
    Koutsoukos, Xenofon
    Stouffer, Keith
    Tang, CheeYee
    Candell, Richard
    2015 RESILIENCE WEEK (RSW), 2015, : 114 - 119
  • [16] Comparative Analysis of Threat Modeling Methods for Cloud Computing towards Healthcare Security Practice
    Yeng, Prosper K.
    Wulthusen, Stephen D.
    Yang, Bian
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (11) : 772 - 784
  • [17] Threat modeling for aviation computer security
    Baquero, Abraham O.
    Kornecki, Andrew J.
    Zalewski, Janusz
    CrossTalk, 2015, 28 (06): : 21 - 27
  • [18] A Quantitative Threat Modeling Approach to Maximize the Return on Security Investment in Cloud Computing
    Schilling, Andreas
    Werners, Brigitte
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON CLOUD SECURITY MANAGEMENT (ICCSM-2013), 2013, : 68 - 78
  • [19] Aflatoxins posing threat to food safety and security in Pakistan: Call for a one health approach
    Ashraf, Waseela
    Rehman, Abdul
    Rabbani, Masood
    Shaukat, Waseem
    Wang, Jia-Sheng
    FOOD AND CHEMICAL TOXICOLOGY, 2023, 180
  • [20] Addressing Security and Human Rights Challenges in Complex Environments
    Bryden, Alan
    Hernandez, Lucia
    BUSINESS AND HUMAN RIGHTS JOURNAL, 2015, 1 (01) : 153 - 158