Architecture-based attack propagation and variation analysis for identifying confidentiality issues in Industry 4.0

被引:1
|
作者
Walter, Maximilian [1 ]
Hahner, Sebastian [1 ]
Bures, Tomas [2 ]
Hnetynka, Petr [2 ]
Heinrich, Robert [1 ]
Reussner, Ralf [1 ]
机构
[1] Karlsruhe Inst Technol KIT, Inst Informat Secur & Dependabil KASTEL, Dependabil Software Intens Syst Grp DSiS, Fasanengarten 5, D-76131 Karlsruhe, Germany
[2] Charles Univ Prague, Fac Math & Phys, Malostranske Namesti 25, Prague 1, Czech Republic
关键词
attack propagation; confidentiality; software architecture;
D O I
10.1515/auto-2022-0135
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Exchanging data between entities is an essential part of Industry 4.0. However, the data exchange should not affect the confidentiality. Therefore, data should only be shared with the intended entities. In exceptional scenarios, it is unclear whether data should be shared or not and what the impact of the access decision is. Runtime access control systems such as role-based access control often do not consider the impact on the overall confidentiality. Static design-time analyses often provide this information. We use architectural design-time analyses together with an uncertainty variation metamodel mitigating uncertainty to calculate impact properties of attack paths. Runtime access control approaches can then use this information to support the access control decision. We evaluated our approach on four case studies based on real-world examples and research cases.
引用
收藏
页码:443 / 452
页数:10
相关论文
共 50 条
  • [41] Mapping the field of Industry 4.0 based on bibliometric analysis
    Janik, Agnieszka
    Ryszko, Adam
    VISION 2020: SUSTAINABLE ECONOMIC DEVELOPMENT AND APPLICATION OF INNOVATION MANAGEMENT, 2018, : 6316 - 6330
  • [42] Cloud-based Speech Recognition for UAV Control Architecture in Industry 4.0
    Eruero, Oghenegueke P.
    Kwu, Modestus O.
    Eric, Favour O.
    Tartibu, Lagouge K.
    2024 7TH INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE, BIG DATA, COMPUTING AND DATA COMMUNICATION SYSTEMS, ICABCD 2024, 2024,
  • [43] A Secure Fog-Based Architecture for Industrial Internet of Things and Industry 4.0
    Sengupta, Jayasree
    Ruj, Sushmita
    Bit, Sipra Das
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (04) : 2316 - 2324
  • [44] An Edge-Based Architecture to Support Efficient Applications for Healthcare Industry 4.0
    Pace, Pasquale
    Aloi, Gianluca
    Gravina, Raffaele
    Caliciuri, Giuseppe
    Fortino, Giancarlo
    Liotta, Antonio
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2019, 15 (01) : 481 - 489
  • [45] Manufacturing Processes in the Era of Industry 4.0. Case Study: Analysis of a System Architecture in Automotive Industry
    Banta, Viorel-Costin
    Sacala, Ioan-Stefan
    Tutui, Daniela
    Cretu, Raluca-Florentina
    Serban, Elena Claudia
    STUDIES IN INFORMATICS AND CONTROL, 2024, 33 (03):
  • [46] SEACON: An Integrated Approach to the Analysis and Design of Secure Enterprise Architecture-Based Computer Networks
    Yadav, Surya B.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY AND PRIVACY, 2008, 2 (01) : 1 - 25
  • [47] Identifying Emerging Issues in the Seafood Industry Based on a Text Mining Approach
    Han, Kiuk
    Yeom, Jaesun
    Chung, Keunsuk
    APPLIED SCIENCES-BASEL, 2024, 14 (05):
  • [48] Architecture-based Assessment and Planning of Software Changes in Information and Automated Production Systems State of the Art and Open Issues
    Vogel-Heuser, B.
    Feldmann, S.
    Folmer, J.
    Roesch, S.
    Heinrich, R.
    Rostami, K.
    Reussner, R.
    2015 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC 2015): BIG DATA ANALYTICS FOR HUMAN-CENTRIC SYSTEMS, 2015, : 687 - 694
  • [49] Industry 4.0 Technologies: A Cross-sector Industry-Based Analysis
    Bortolini, Marco
    Calabrese, Francesca
    Galizia, Francesco Gabriele
    Mora, Cristina
    Ventura, Valentina
    SUSTAINABLE DESIGN AND MANUFACTURING, KES-SDM 2021, 2022, 262 : 140 - 148
  • [50] Quantitative analysis of information leakage in service-oriented architecture-based Web services
    Anjaria, Kushal
    Mishra, Arun
    KYBERNETES, 2017, 46 (03) : 479 - 500