Towards a Threat Modeling Approach Addressing Security and Safety in OT Environments

被引:14
|
作者
Hollerer, Siegfried [1 ]
Kastner, Wolfgang [1 ]
Sauter, Thilo [2 ,3 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Technol, Vienna, Austria
[3] Danube Univ Krems, Integr Sensor Syst, Krems An Der Donau, Austria
来源
17TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2021 (WFCS 2021) | 2021年
关键词
Threat Modeling; OT Security; Safety; Industry; 4.0; IT/OT convergence;
D O I
10.1109/WFCS46889.2021.9483591
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In Industry 4.0, Information Technology (IT) and Operational Technology (OT) tend to converge further with an increasing interdependence of safety and security issues to be considered. On one hand, cyber attacks are possible which can alter implemented safety functionality leading to situations where people are harmed, serious injuries may occur or the environment gets damaged. On the other side, safety can also impact security. For instance, the misuse of a Safety Instrumented System (SIS) may force a machine or a production line to shut down resulting in a denial of service. To prevent or mitigate risks from such scenarios, this paper proposes a threat modeling technique which addresses an integrated view on safety and security. The approach is tailored to the industrial automation domain considering plausible attacks and evaluating risks based on three different metrics. The metrics selected consist of Common Vulnerability Scoring System (CVSS) used as an international standard for rating cyber security vulnerabilities, Security Level (SL) from IEC 62443 to rate cyber security risks in OT environments w.r.t. the underlying architecture, and Safety Integrity Level (SIL) from IEC 61508 to rate safety risks. Due to the variety of use cases involving the chosen metrics, the approach is also feasible for followup analyses, such as integrated safety and security assessments or audits.
引用
收藏
页码:37 / 40
页数:4
相关论文
共 50 条
  • [21] EffFeu Project: Towards Mission-Guided Application of Drones in Safety and Security Environments
    Hrabia, Christopher-Eyk
    Hessler, Axel
    Xu, Yuan
    Seibert, Jacob
    Brehmer, Jan
    Albayrak, Sahin
    SENSORS, 2019, 19 (04)
  • [22] Towards an MDRE Approach to Verify Security and Safety of Heterogeneous IoT Apps
    AbuSerrieh, Lobna
    Alalfi, Manar H.
    PROCEEDINGS OF THE 2024 ACM/IEEE 6TH INTERNATIONAL WORKSHOP ON SOFTWARE ENGINEERING RESEARCH & PRACTICES FOR THE INTERNET OF THINGS, SERP4IOT 2024, 2024, : 65 - 72
  • [23] Towards a Formal Approach to Analysing Security of Safety-Critical Systems
    Vistbakka, Inna
    Troubitsyna, Elena
    2018 14TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2018), 2018, : 182 - 189
  • [24] Uniform Approach of Risk Communication in Distributed IT Environments Combining Safety and Security Aspects
    Fruth, Jana
    Nett, Edgar
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, 2014, 8696 : 289 - 300
  • [25] Risk-driven security testing using risk analysis with threat modeling approach
    Palanivel, Maragathavalli
    Selvadurai, Kanmani
    SPRINGERPLUS, 2014, 3 : 1 - 14
  • [26] Cyber Security Threat Modeling of A Telesurgery System
    Al Asif, Md Rashid
    Khondoker, Rahamatullah
    2020 2ND INTERNATIONAL CONFERENCE ON SUSTAINABLE TECHNOLOGIES FOR INDUSTRY 4.0 (STI), 2020,
  • [27] Ransomware Security Threat Modeling for Photovoltaic Systems
    Su, Ying
    Ahn, Bohyun
    Alvee, Syed R. B.
    Kim, Taesic
    Choi, Jinchun
    Smith, Scott C.
    2021 6TH IEEE WORKSHOP ON THE ELECTRONIC GRID (EGRID), 2021,
  • [28] Threat Modeling and Security Issues for the Internet of Things
    Seeam, Amar
    Ogbeh, Ochanya S.
    Guness, Shivanand
    Bellekens, Xavier
    2019 SECOND INTERNATIONAL CONFERENCE ON NEXT GENERATION COMPUTING APPLICATIONS 2019 (NEXTCOMP 2019), 2019,
  • [29] THE HOLY SEE'S APPROACH TOWARDS PUBLIC SECURITY THREAT IN UKRAINE MEDIA IMAGE AND REALITY
    Bylina, Slawomir
    Adamski, Andrzej
    Przywara, Barbara
    EUROPEAN JOURNAL OF SCIENCE AND THEOLOGY, 2020, 16 (04) : 53 - 64
  • [30] Towards Collaborative Cyber Threat Intelligence for Security Management
    Osliak, Oleksii
    Saracino, Andrea
    Martinelli, Fabio
    Dimitrakos, Theo
    ICISSP: PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2021, : 339 - 346