A new safety and security risk analysis framework for industrial control systems

被引:8
|
作者
Kriaa, Siwar [1 ,2 ]
Bouissou, Marc [1 ]
Laarouchi, Youssef [1 ]
机构
[1] EDF, 7 Blvd Gaspard Monge, F-91120 Palaiseau, France
[2] CentraleSupelec, Chatenay Malabry, France
关键词
Industrial control system; safety; security; modeling; risk assessment; cyber-physical system; COMPROMISE; MODEL;
D O I
10.1177/1748006X18765885
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The migration of modern industrial control systems toward information and communication technologies exposes them to cyber-attacks that can alter the way they function, thereby causing adverse consequences on the system and its environment. It has consequently become crucial to consider security risks in traditional safety risk analyses for industrial systems controlled by modern industrial control system. We propose in this article a new framework for safety and security joint risk analysis for industrial control systems. S-cube (for supervisory control and data acquisition safety and security joint modeling) is a new model-based approach that enables, thanks to a knowledge base, formal modeling of the physical and functional architecture of cyber-physical systems and automatic generation of a qualitative and quantitative analysis encompassing safety risks (accidental) and security risks (malicious). We first give the principle and rationale of S-cube and then we illustrate its inputs and outputs on a case study.
引用
收藏
页码:151 / 174
页数:24
相关论文
共 50 条
  • [1] A safety/security risk analysis approach of Industrial Control Systems: A cyber bowtie - combining new version of attack tree with bowtie analysis
    Abdo, H.
    Kaouk, M.
    Flaus, J. -M.
    Masse, F.
    [J]. COMPUTERS & SECURITY, 2018, 72 : 175 - 195
  • [2] A logic-based framework for the security analysis of Industrial Control Systems
    Lemaire L.
    Vossaert J.
    Jansen J.
    Naessens V.
    [J]. Automatic Control and Computer Sciences, 2017, 51 (2) : 114 - 123
  • [3] Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems
    Alanen, Jarmo
    Linnosmaa, Joonas
    Malm, Timo
    Papakonstantinou, Nikolaos
    Ahonen, Toni
    Heikkila, Eetu
    Tiusanen, Risto
    [J]. RELIABILITY ENGINEERING & SYSTEM SAFETY, 2022, 220
  • [4] Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems
    Alanen, Jarmo
    Linnosmaa, Joonas
    Malm, Timo
    Papakonstantinou, Nikolaos
    Ahonen, Toni
    Heikkilä, Eetu
    Tiusanen, Risto
    [J]. Reliability Engineering and System Safety, 2022, 220
  • [5] Automating Safety and Security Risk Assessment in Industrial Control Systems: Challenges and Constraints
    Bhosale, Pushparaj
    Kastner, Wolfgang
    Sauter, Thilo
    [J]. 2022 IEEE 27TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2022,
  • [6] Design and Implementation of a Security Framework for Industrial Control Systems
    Harshe, Omkar A.
    Chiluvuri, N. Teja
    Patterson, Cameron D.
    Baumann, William T.
    [J]. 2015 INTERNATIONAL CONFERENCE ON INDUSTRIAL INSTRUMENTATION AND CONTROL (ICIC), 2015, : 127 - 132
  • [7] A Survey of Cyber Security and Safety in Industrial Control Systems
    Ma, Yi-Wei
    Tu, Yi-Hao
    Tsou, Chia-Wei
    Chiang, Yen-Neng
    Chen, Jiann-Liang
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2024, 25 (04): : 541 - 550
  • [8] Conflict Analysis and Resolution of Safety and Security Boundary Conditions for Industrial Control Systems
    Agbo, Chidi
    Mehrpouyan, Hoda
    [J]. 2022 6TH INTERNATIONAL CONFERENCE ON SYSTEM RELIABILITY AND SAFETY, ICSRS, 2022, : 145 - 156
  • [9] Ontology-based Framework for Boundary Verification of Safety and Security Properties in Industrial Control Systems
    Ukegbu, Chibuzo
    Neupane, Ramesh
    Mehrpouyan, Hoda
    [J]. PROCEEDINGS OF THE 2023 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2023, 2023, : 47 - 52
  • [10] Risk-Based Scheduling of Security Tasks in Industrial Control Systems With Consideration of Safety
    Zhou, Chunjie
    Li, Xuan
    Yang, Shuanghua
    Tian, Yu-Chu
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2020, 16 (05) : 3112 - 3123