Towards a Threat Modeling Approach Addressing Security and Safety in OT Environments

被引:14
|
作者
Hollerer, Siegfried [1 ]
Kastner, Wolfgang [1 ]
Sauter, Thilo [2 ,3 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Technol, Vienna, Austria
[3] Danube Univ Krems, Integr Sensor Syst, Krems An Der Donau, Austria
来源
17TH IEEE INTERNATIONAL WORKSHOP ON FACTORY COMMUNICATION SYSTEMS 2021 (WFCS 2021) | 2021年
关键词
Threat Modeling; OT Security; Safety; Industry; 4.0; IT/OT convergence;
D O I
10.1109/WFCS46889.2021.9483591
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
In Industry 4.0, Information Technology (IT) and Operational Technology (OT) tend to converge further with an increasing interdependence of safety and security issues to be considered. On one hand, cyber attacks are possible which can alter implemented safety functionality leading to situations where people are harmed, serious injuries may occur or the environment gets damaged. On the other side, safety can also impact security. For instance, the misuse of a Safety Instrumented System (SIS) may force a machine or a production line to shut down resulting in a denial of service. To prevent or mitigate risks from such scenarios, this paper proposes a threat modeling technique which addresses an integrated view on safety and security. The approach is tailored to the industrial automation domain considering plausible attacks and evaluating risks based on three different metrics. The metrics selected consist of Common Vulnerability Scoring System (CVSS) used as an international standard for rating cyber security vulnerabilities, Security Level (SL) from IEC 62443 to rate cyber security risks in OT environments w.r.t. the underlying architecture, and Safety Integrity Level (SIL) from IEC 61508 to rate safety risks. Due to the variety of use cases involving the chosen metrics, the approach is also feasible for followup analyses, such as integrated safety and security assessments or audits.
引用
收藏
页码:37 / 40
页数:4
相关论文
共 50 条
  • [31] Towards a Threat Model and Security Analysis for Data Cooperatives
    Salau, Abiola
    Dantu, Ram
    Morozov, Kirill
    Upadhyay, Kritagya
    Badruddoja, Syed
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 707 - 713
  • [32] A Survey of Ontologies Considering General Safety, Security, and Operation Aspects in OT
    Hollerer, Siegfried
    Sauter, Thilo
    Kastner, Wolfgang
    IEEE OPEN JOURNAL OF THE INDUSTRIAL ELECTRONICS SOCIETY, 2024, 5 : 861 - 885
  • [33] StreamShield: A Stream-Centric Approach Towards Security and Privacy in Data Stream Environments
    Nehme, Rimma V.
    Lim, Hyo-Sang
    Bertino, Elisa
    Rundensteiner, Elke A.
    ACM SIGMOD/PODS 2009 CONFERENCE, 2009, : 1027 - 1029
  • [34] An Approach Addressing Service Availability in Mobile Environments
    Guerrero-Contreras, Gabriel
    Balderas-Diaz, Sara
    Rodriguez-Dominguez, Carlos
    Valenzuela, Aurora
    Luis Garrido, Jose
    WORKSHOP PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON INTELLIGENT ENVIRONMENTS, 2015, 19 : 46 - 57
  • [35] Towards a unified security/safety framework - A design approach to embedded system applications
    Sveda, Miroslav
    Vrba, Radimir R.
    ICSOFT 2007: PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL SE: SOFTWARE ENGINEERING, 2007, : 345 - +
  • [36] Threat-Oriented Security Framework: A Proactive Approach in Threat Management
    Gandotra, Vandana
    Singhal, Archana
    Bedi, Punam
    2ND INTERNATIONAL CONFERENCE ON COMPUTER, COMMUNICATION, CONTROL AND INFORMATION TECHNOLOGY (C3IT-2012), 2012, 4 : 487 - 494
  • [37] Towards Semantic Resolution of Security in Ambient Environments
    Hoffmann, Mario
    Badii, Atta
    Engberg, Stephan
    Nair, Renjith
    Thiemert, Daniel
    Matthess, Manuel
    Schuette, Julian
    DEVELOPING AMBIENT INTELLIGENCE, PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON AMBIENT INTELLIGENCE DEVELOPMENTS (AMI.D'07), 2008, : 13 - 22
  • [38] Threat Modeling Towards Resilience in Smart ICUs
    Baumhoer, Christian
    Henning, Thomas
    Grosse-Kampmann, Matteo
    SECURE AND RESILIENT DIGITAL TRANSFORMATION OF HEALTHCARE, SUNRISE 2023, 2024, 1884 : 37 - 50
  • [39] Towards the Resolution of Safety and Security Conflicts
    Menon, Catherine
    Vidalis, Stilianos
    2021 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2021,
  • [40] The Effects of Safety Behavior Directed Towards a Safety Cue on Perceptions of Threat
    Engelhard, Iris M.
    van Uijen, Sophie L.
    van Seters, Niels
    Velu, Nicolette
    BEHAVIOR THERAPY, 2015, 46 (05) : 604 - 610