Architecture-based attack propagation and variation analysis for identifying confidentiality issues in Industry 4.0

被引:1
|
作者
Walter, Maximilian [1 ]
Hahner, Sebastian [1 ]
Bures, Tomas [2 ]
Hnetynka, Petr [2 ]
Heinrich, Robert [1 ]
Reussner, Ralf [1 ]
机构
[1] Karlsruhe Inst Technol KIT, Inst Informat Secur & Dependabil KASTEL, Dependabil Software Intens Syst Grp DSiS, Fasanengarten 5, D-76131 Karlsruhe, Germany
[2] Charles Univ Prague, Fac Math & Phys, Malostranske Namesti 25, Prague 1, Czech Republic
关键词
attack propagation; confidentiality; software architecture;
D O I
10.1515/auto-2022-0135
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Exchanging data between entities is an essential part of Industry 4.0. However, the data exchange should not affect the confidentiality. Therefore, data should only be shared with the intended entities. In exceptional scenarios, it is unclear whether data should be shared or not and what the impact of the access decision is. Runtime access control systems such as role-based access control often do not consider the impact on the overall confidentiality. Static design-time analyses often provide this information. We use architectural design-time analyses together with an uncertainty variation metamodel mitigating uncertainty to calculate impact properties of attack paths. Runtime access control approaches can then use this information to support the access control decision. We evaluated our approach on four case studies based on real-world examples and research cases.
引用
收藏
页码:443 / 452
页数:10
相关论文
共 50 条
  • [21] Enterprise Architecture-Based Risk and Security Modelling and Analysis
    Jonkers, Henk
    Quartel, Dick A. C.
    GRAPHICAL MODELS FOR SECURITY, GRAMSEC 2016, 2016, 9987 : 94 - 101
  • [22] ARCHITECTURE-BASED SOFTWARE RELIABILITY ANALYSIS INCORPORATING CONCURRENCY
    El Kharboutly, Rehab A.
    Gokhale, Swapna S.
    Ammar, Reda A.
    INTERNATIONAL JOURNAL OF RELIABILITY QUALITY & SAFETY ENGINEERING, 2007, 14 (05): : 479 - 499
  • [23] Architecture-based software reliability analysis: Overview and limitations
    Gokhale, Swapna S.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2007, 4 (01) : 32 - 40
  • [24] Design of an architecture for systems and applications in Industry 4.0 based on cloud computing and data analysis
    Belman-Lopez, Carlos E.
    Jimenez-Garcia, Jose A.
    Vazquez-Lopez, Jose A.
    Camarillo-Gomez, Karla A.
    REVISTA IBEROAMERICANA DE AUTOMATICA E INFORMATICA INDUSTRIAL, 2023, 20 (02): : 137 - 149
  • [25] Design of an architecture for systems and applications in Industry 4.0 based on cloud computing and data analysis
    Belman-López C.E.
    Jiménez-García J.A.
    Vázquez-Lopez J.A.
    Camarillo-Gómez K.A.
    RIAI - Revista Iberoamericana de Automatica e Informatica Industrial, 2023, 20 (02): : 137 - 149
  • [26] Attack Resilient Cloud-Based Control Systems for Industry 4.0
    Akbarian, Fatemeh
    Tarneberg, William
    Fitzgerald, Emma
    Kihl, Maria
    IEEE ACCESS, 2023, 11 : 27865 - 27882
  • [27] General Architecture for Data Analysis in Industry 4.0 using SysML and Model Based System Engineering
    Arantes, Marcio
    Bonnard, Renan
    Mattei, Andre Pierre
    de Saqui-Sannes, Peirre
    12TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON2018), 2018, : 420 - 425
  • [28] Software architecture-based analysis and testing: a look into achievements and future challenges
    Antonia Bertolino
    Paola Inverardi
    Henry Muccini
    Computing, 2013, 95 : 633 - 648
  • [29] An Architecture based on IoT and CPS to Organize and Locate Services An architecture focused on Industry 4.0
    Pisching, Marcos A.
    Junqueira, Fabricio
    dos Santos Filho, Diolino J.
    Miyagi, Paulo E.
    2016 IEEE 21ST INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2016,
  • [30] An Extensible Framework for Architecture-Based Data Flow Analysis for Information Security
    Boltz, Nicolas
    Hahner, Sebastian
    Gerking, Christopher
    Heinrich, Robert
    SOFTWARE ARCHITECTURE: ECSA 2023 TRACKS, WORKSHOPS, AND DOCTORAL SYMPOSIUM, ECSA 2023, CASA 2023, AMP 2023, FAACS 2023, DEMESSA 2023, QUALIFIER 2023, TWINARCH 2023, 2024, 14590 : 342 - 358