Safety Watermark: A Defense Tool for Real-Time Digital Forensic Incident Response in Industrial Control Systems

被引:0
|
作者
Victor, Sim Siang Tze [1 ]
Ahmed, Chuadhry Mujeeb [2 ]
Kelvin, Koh Yoong Keat [3 ]
Zhou, Jianying [1 ]
机构
[1] Singapore Univ Technol & Design, Singapore, Singapore
[2] Newcastle Univ, Newcastle Upon Tyne, England
[3] Publ Util Board, Singapore, Singapore
基金
新加坡国家研究基金会;
关键词
Industrial Control System; Cyber-Physical System Security; Process Hazard Analysis; Safety Watermark; Invariants; Consequence-based Cyber-Informed Engineering;
D O I
10.1007/978-3-031-41181-6_17
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Industrial Control Systems (ICSs) including those executing process safety controls, alarms, and interlocks are becoming more interconnected with other systems. Traditional process hazard analysis (PHA) rarely considered the possibility of cyber-attacks causing safety incidents in the process. Practitioners have viewed safety and security traditionally as systems with different properties. Both communities worked separately using their respective terminologies and frameworks. With the view of limited resources especially in the protection of security, it is important to be able to prioritize. A strategy is to take a top-down approach by identifying system losses that needed protection. This results in a more manageable set of potential losses. Rather than starting from the angle on how best to protect the network against the myriad of threats, a strategic approach would be to know what services and functions require protection. The novelty of this work is to use a subset of the invariants derived using a top-down approach by focusing on hazards manifestations that require protection from being comprisable digitally. This approach is called the safety watermark concept in this paper. In its most basic form, it is successfully shown to alert operators of potential safety risk manifestations with varying importance. In certain situations where the likelihood of the safety risk manifestations increases towards a cyber-attack, the safety watermark raises the alert level to potential cyber incidents. The safety watermark has been effectively utilized to demonstrate the ability in real-time to identify potential indicators of compromises in terms of system components, a yet to be commercially available capability for industrial control systems. The safety watermark possesses the ability to scale, and an example is illustrated for a consequence driven methodology like the Consequence-Based Cyber-Informed Engineering (CCE) by Idaho National Laboratory.
引用
收藏
页码:299 / 320
页数:22
相关论文
共 50 条
  • [21] Reliability Analysis of Real-time Control Systems in Industrial Wireless Network
    Lee, Wonhee
    Kim, Youngsuk
    Lee, Sangyoon
    Yoo, Myungsik
    2013 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC 2013): FUTURE CREATIVE CONVERGENCE TECHNOLOGIES FOR NEW ICT ECOSYSTEMS, 2013, : 1097 - 1098
  • [22] The Fujaba real-time tool suite - Model-driven development of safety-critical, real-time systems
    Burmester, S
    Giese, H
    Hirsch, M
    Schilling, D
    Tichy, M
    ICSE 05: 27th International Conference on Software Engineering, Proceedings, 2005, : 670 - 671
  • [23] Real-time control systems
    Paul, BO
    Cawlfield, DW
    CHEMICAL PROCESSING, 1997, 60 (07): : 34 - &
  • [24] RELIABILITY AND SAFETY OF REAL-TIME SYSTEMS
    EVERETT, W
    HONIDEN, S
    IEEE SOFTWARE, 1995, 12 (03) : 13 - 16
  • [25] A Rapid Prototyping Tool for Embedded, Real-Time Hierarchical Control Systems
    Rajagopal, Ram
    Ramamoorthy, Subramanian
    Wenzel, Lothar
    Andrade, Hugo
    EURASIP JOURNAL ON EMBEDDED SYSTEMS, 2008, (01)
  • [26] REAL-TIME TOOL CONTROL AND JOB DISPATCHING IN FLEXIBLE MANUFACTURING SYSTEMS
    HAN, MH
    NA, YK
    HOGG, GL
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 1989, 27 (08) : 1257 - 1267
  • [27] An Industrial Control Systems Incident Response Decision Framework
    He, Ying
    Maglaras, Leandros A.
    Janicke, Helge
    Jones, Kevin
    2015 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2015, : 761 - 762
  • [28] Real-Time Incident Prediction for Online Service Systems
    Zhao, Nengwen
    Chen, Junjie
    Wang, Zhou
    Peng, Xiao
    Wang, Gang
    Wu, Yong
    Zhou, Fang
    Feng, Zhen
    Nie, Xiaohui
    Zhang, Wenchi
    Sui, Kaixin
    Pei, Dan
    PROCEEDINGS OF THE 28TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '20), 2020, : 315 - 326
  • [29] Real-time systems safety control considering Human Machine Interface
    Machado, Jose
    Seabra, Eurico
    ICINCO 2008: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON INFORMATICS IN CONTROL, AUTOMATION AND ROBOTICS, VOL SPSMC: SIGNAL PROCESSING, SYSTEMS MODELING AND CONTROL, 2008, : 269 - 274
  • [30] Digital transformation of hospital quality and safety: real-time data for real-time action
    Barnett, Amy
    Winning, Michelle
    Canaris, Stephen
    Cleary, Michael
    Staib, Andrew
    Sullivan, Clair
    AUSTRALIAN HEALTH REVIEW, 2019, 43 (06) : 656 - 661