Safety Watermark: A Defense Tool for Real-Time Digital Forensic Incident Response in Industrial Control Systems

被引:0
|
作者
Victor, Sim Siang Tze [1 ]
Ahmed, Chuadhry Mujeeb [2 ]
Kelvin, Koh Yoong Keat [3 ]
Zhou, Jianying [1 ]
机构
[1] Singapore Univ Technol & Design, Singapore, Singapore
[2] Newcastle Univ, Newcastle Upon Tyne, England
[3] Publ Util Board, Singapore, Singapore
基金
新加坡国家研究基金会;
关键词
Industrial Control System; Cyber-Physical System Security; Process Hazard Analysis; Safety Watermark; Invariants; Consequence-based Cyber-Informed Engineering;
D O I
10.1007/978-3-031-41181-6_17
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Industrial Control Systems (ICSs) including those executing process safety controls, alarms, and interlocks are becoming more interconnected with other systems. Traditional process hazard analysis (PHA) rarely considered the possibility of cyber-attacks causing safety incidents in the process. Practitioners have viewed safety and security traditionally as systems with different properties. Both communities worked separately using their respective terminologies and frameworks. With the view of limited resources especially in the protection of security, it is important to be able to prioritize. A strategy is to take a top-down approach by identifying system losses that needed protection. This results in a more manageable set of potential losses. Rather than starting from the angle on how best to protect the network against the myriad of threats, a strategic approach would be to know what services and functions require protection. The novelty of this work is to use a subset of the invariants derived using a top-down approach by focusing on hazards manifestations that require protection from being comprisable digitally. This approach is called the safety watermark concept in this paper. In its most basic form, it is successfully shown to alert operators of potential safety risk manifestations with varying importance. In certain situations where the likelihood of the safety risk manifestations increases towards a cyber-attack, the safety watermark raises the alert level to potential cyber incidents. The safety watermark has been effectively utilized to demonstrate the ability in real-time to identify potential indicators of compromises in terms of system components, a yet to be commercially available capability for industrial control systems. The safety watermark possesses the ability to scale, and an example is illustrated for a consequence driven methodology like the Consequence-Based Cyber-Informed Engineering (CCE) by Idaho National Laboratory.
引用
收藏
页码:299 / 320
页数:22
相关论文
共 50 条
  • [1] A Prototype Forensic Toolkit for Industrial-Control-Systems Incident Response
    Carr, Nicholas B.
    Rowe, Neil C.
    CYBER SENSING 2015, 2015, 9458
  • [2] A supervisory tool for real-time industrial automation systems
    Pardi, W
    Pereira, CE
    ISORC 2003: SIXTH IEEE INTERNATIONAL SYMPOSIUM ON OBJECT-ORIENTED REAL-TIME DISTRIBUTED COMPUTING, PROCEEDINGS, 2003, : 230 - 237
  • [3] A tool for controlling response time in real-time systems
    Richard, P
    COMPUTER PERFORMANCE EVALUATION: MODELLING TECHNIQUES AND TOOLS, 2002, 2324 : 339 - 348
  • [4] Real-Time Modeling for Industrial Control Systems
    Estevez, E.
    Marcos, M.
    Irisarri, E.
    2010 IEEE CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2010,
  • [5] REAL-TIME DIGITAL SIMULATION FOR SYSTEMS CONTROL
    SAGE, AP
    SMITH, SL
    PROCEEDINGS OF THE INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS, 1966, 54 (12): : 1802 - &
  • [6] A General Real-Time Control Approach of Intrusion Response for Industrial Automation Systems
    Huang, Shuang
    Zhou, Chunjie
    Xiong, Naixue
    Yang, Shuang-Hua
    Qin, Yuanqing
    Zhang, Qi
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2016, 46 (08): : 1021 - 1035
  • [7] REAL-TIME EXPERT-SYSTEMS FOR INDUSTRIAL CONTROL
    FEDDERWITZ, W
    WITTIG, T
    INTEGRATED COMPUTER-AIDED ENGINEERING, 1995, 2 (03) : 187 - 202
  • [8] A real-time simulation tool for real-time control
    Kwon, WH
    Kim, KB
    Moon, SY
    Choi, SG
    Kim, YS
    ALGORITHMS AND ARCHITECTURES FOR REAL-TIME CONTROL 1997, 1997, : 325 - 329
  • [9] Scilab/Scicos: An Alternative Tool for Real-Time Monitoring and Advanced Control Fieldbus Industrial Systems
    Costa, Thiago V.
    Fileti, Ana M. F.
    Silva, Flavio V.
    10TH INTERNATIONAL SYMPOSIUM ON PROCESS SYSTEMS ENGINEERING, 2009, 27 : 1617 - 1622
  • [10] A Real-Time LoRa Protocol for Industrial Monitoring and Control Systems
    Hoang, Quy Lam
    Jung, Woo-Sung
    Yoon, Taehyun
    Yoo, Daeseung
    Oh, Hoon
    IEEE ACCESS, 2020, 8 : 44727 - 44738