Finding Dependencies between Cyber-Physical Domains for Security Testing of Industrial Control Systems

被引:12
作者
Castellanos, John H. [1 ]
Ochoa, Martin [2 ]
Zhou, Jianying [1 ]
机构
[1] Singapore Univ Technol & Design, Singapore, Singapore
[2] Univ Rosario, Dept Appl Math & Comp Sci, Bogota, Colombia
来源
34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018) | 2018年
关键词
Cyber-Physical Systems; ICS Security; Information flow; INFORMATION-FLOW;
D O I
10.1145/3274694.3274745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In modern societies, critical services such as transportation, power supply, water treatment and distribution are strongly dependent on Industrial Control Systems (ICS). As technology moves along, new features improve services provided by such ICS. On the other hand, this progress also introduces new risks of cyber attacks due to the multiple direct and indirect dependencies between cyber and physical components of such systems. Performing rigorous security tests and risk analysis in these critical systems is thus a challenging task, because of the non-trivial interactions between digital and physical assets and the domain-specific knowledge necessary to analyse a particular system. In this work, we propose a methodology to model and analyse a System Under Test (SUT) as a data flow graph that highlights interactions among internal entities throughout the SUT. This model is automatically extracted from production code available in Programmable Logic Controllers (PLCs). We also propose a reachability algorithm and an attack diagram that will emphasize the dependencies between cyber and physical domains, thus enabling a human analyst to gauge various attack vectors that arise from subtle dependencies in data and information propagation. We test our methodology in a functional water treatment testbed and demonstrate how an analyst could make use of our designed attack diagrams to reason on possible threats to various targets of the SUT.
引用
收藏
页码:582 / 594
页数:13
相关论文
共 50 条
  • [21] On modeling of electrical cyber-physical systems considering cyber security
    Wang, Yi-nan
    Lin, Zhi-yun
    Liang, Xiao
    Xu, Wen-yuan
    Yang, Qiang
    Yan, Gang-feng
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2016, 17 (05) : 465 - 478
  • [22] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan WANG
    Zhi-yun LIN
    Xiao LIANG
    Wen-yuan XU
    Qiang YANG
    Gang-feng YAN
    FrontiersofInformationTechnology&ElectronicEngineering, 2016, 17 (05) : 465 - 478
  • [23] Designing Ethical Cyber-Physical Industrial Systems
    Trentesaux, Damien
    Rault, Raphael
    IFAC PAPERSONLINE, 2017, 50 (01): : 14934 - 14939
  • [24] Cybersecurity of Industrial Cyber-Physical Systems: A Review
    Kayan, Hakan
    Nunes, Matthew
    Rana, Omer
    Burnap, Pete
    Perera, Charith
    ACM COMPUTING SURVEYS, 2022, 54 (11S)
  • [25] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan Wang
    Zhi-yun Lin
    Xiao Liang
    Wen-yuan Xu
    Qiang Yang
    Gang-feng Yan
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 : 465 - 478
  • [26] A survey on attack detection, estimation and control of industrial cyber-physical systems
    Zhang, Dan
    Wang, Qing-Guo
    Feng, Gang
    Shi, Yang
    Vasilakos, Athanasios V.
    ISA TRANSACTIONS, 2021, 116 : 1 - 16
  • [27] Industrial Cyber-Physical Systems in Textile Engineering
    Bullon Perez, Juan
    Gonzalez Arrieta, Angelica
    Hernandez Encinas, Ascension
    Queiruga-Dios, Araceli
    INTERNATIONAL JOINT CONFERENCE SOCO'16- CISIS'16-ICEUTE'16, 2017, 527 : 126 - 135
  • [28] Towards Preserving Information Flow Security on Architectural Composition of Cyber-Physical Systems
    Gerking, Christopher
    Schubert, David
    SOFTWARE ARCHITECTURE (ECSA 2018), 2018, 11048 : 147 - 155
  • [29] Cyber-physical modeling and simulation: A reference architecture for designing demonstrators for industrial cyber-physical systems
    Oks, Sascha Julian
    Jalowski, Max
    Fritzsche, Albrecht
    Moeslein, Kathrin M.
    29TH CIRP DESIGN CONFERENCE 2019, 2019, 84 : 257 - 264
  • [30] Enabling Model Testing of Cyber-Physical Systems
    Gonzalez, Carlos A.
    Varmazyar, Mojtaba
    Nejati, Shiva
    Briand, Lionel C.
    Isasi, Yago
    21ST ACM/IEEE INTERNATIONAL CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS (MODELS 2018), 2018, : 176 - 186