Finding Dependencies between Cyber-Physical Domains for Security Testing of Industrial Control Systems

被引:12
|
作者
Castellanos, John H. [1 ]
Ochoa, Martin [2 ]
Zhou, Jianying [1 ]
机构
[1] Singapore Univ Technol & Design, Singapore, Singapore
[2] Univ Rosario, Dept Appl Math & Comp Sci, Bogota, Colombia
来源
34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018) | 2018年
关键词
Cyber-Physical Systems; ICS Security; Information flow; INFORMATION-FLOW;
D O I
10.1145/3274694.3274745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In modern societies, critical services such as transportation, power supply, water treatment and distribution are strongly dependent on Industrial Control Systems (ICS). As technology moves along, new features improve services provided by such ICS. On the other hand, this progress also introduces new risks of cyber attacks due to the multiple direct and indirect dependencies between cyber and physical components of such systems. Performing rigorous security tests and risk analysis in these critical systems is thus a challenging task, because of the non-trivial interactions between digital and physical assets and the domain-specific knowledge necessary to analyse a particular system. In this work, we propose a methodology to model and analyse a System Under Test (SUT) as a data flow graph that highlights interactions among internal entities throughout the SUT. This model is automatically extracted from production code available in Programmable Logic Controllers (PLCs). We also propose a reachability algorithm and an attack diagram that will emphasize the dependencies between cyber and physical domains, thus enabling a human analyst to gauge various attack vectors that arise from subtle dependencies in data and information propagation. We test our methodology in a functional water treatment testbed and demonstrate how an analyst could make use of our designed attack diagrams to reason on possible threats to various targets of the SUT.
引用
收藏
页码:582 / 594
页数:13
相关论文
共 50 条
  • [1] A survey on security control and attack detection for industrial cyber-physical systems
    Ding, Derui
    Han, Qing-Long
    Xiang, Yang
    Ge, Xiaohua
    Zhang, Xian-Ming
    NEUROCOMPUTING, 2018, 275 : 1674 - 1683
  • [2] Hypergames and Cyber-Physical Security for Control Systems
    Bakker, Craig
    Bhattacharya, Arnab
    Chatterjee, Samrat
    Vrabie, Draguna L.
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2020, 4 (04)
  • [3] A cyber-physical experimentation environment for the security analysis of networked industrial control systems
    Genge, Bela
    Siaterlis, Christos
    Fovino, Igor Nai
    Masera, Marcelo
    COMPUTERS & ELECTRICAL ENGINEERING, 2012, 38 (05) : 1146 - 1161
  • [4] Testing Abstractions for Cyber-Physical Control Systems
    Mandrioli, Claudio
    Carlsson, Max Nyberg
    Maggio, Martina
    ACM TRANSACTIONS ON SOFTWARE ENGINEERING AND METHODOLOGY, 2024, 33 (01)
  • [5] Cyber-Physical Systems - Security
    Zseby, T.
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2018, 135 (03): : 249 - 249
  • [6] Cyber-Physical Systems – Security
    Tanja Zseby
    e & i Elektrotechnik und Informationstechnik, 2018, 135 (3) : 249 - 249
  • [7] Security in Cyber-Physical Systems
    Dsouza, Joanita
    Elezabeth, Laura
    Mishra, Ved Prakash
    Jain, Rachna
    PROCEEDINGS 2019 AMITY INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE (AICAI), 2019, : 840 - 844
  • [8] A Systematic Analysis of Security Metrics for Industrial Cyber-Physical Systems
    Gori, Giacomo
    Rinieri, Lorenzo
    Melis, Andrea
    Al Sadi, Amir
    Callegati, Franco
    Prandini, Marco
    ELECTRONICS, 2024, 13 (07)
  • [9] Industrial Cyber-Physical Systems
    Colombo, Armando W.
    Karnouskos, Stamatis
    Shi, Yang
    Yin, Shen
    Kaynak, Okyay
    PROCEEDINGS OF THE IEEE, 2016, 104 (05) : 899 - 903
  • [10] Security framework for industrial collaborative robotic cyber-physical systems
    Khalid, Azfar
    Kirisci, Pierre
    Khan, Zeashan Hameed
    Ghrairi, Zied
    Thoben, Klaus-Dieter
    Pannek, Juergen
    COMPUTERS IN INDUSTRY, 2018, 97 : 132 - 145