Model-based security engineering for cyber-physical systems: A systematic mapping study

被引:60
|
作者
Nguyen, Phu H. [1 ]
Ali, Shaukat [1 ]
Yue, Tao [1 ,2 ]
机构
[1] Simula Res Lab, Martin Linges Vei 25, N-1364 Fornebu, Norway
[2] Univ Oslo, Dept Informat, N-0316 Oslo, Norway
基金
欧盟地平线“2020”;
关键词
Cyber-physical systems; Security; Model-based engineering; Security engineering; Systematic mapping; Snowballing; Survey;
D O I
10.1016/j.infsof.2016.11.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Context: Cyber-physical systems (CPSs) have emerged to be the next generation of engineered systems driving the so-called fourth industrial revolution. CPSs are becoming more complex, open and more prone to security threats, which urges security to be engineered systematically into CPSs. Model-Based Security Engineering (MBSE) could be a key means to tackle this challenge via security by design, abstraction, and automation. Objective: We aim at providing an initial assessment of the state of the art in MBSE for CPSs (MBSE4CPS). Specifically, this work focuses on finding out I) the publication statistics of MBSE4CPS studies; 2) the characteristics of MBSE4CPS studies; and 3) the open issues of MBSE4CPS research. Method: We conducted a systematic mapping study (SMS) following a rigorous protocol that was developed based on the state-of-the-art SMS and systematic review guidelines. From thousands of relevant publications, we systematically identified 48 primary MBSE4CPS studies for data extraction and synthesis to answer predefined research questions. Results: SMS results show that for three recent years (2014-2016) the number of primary MBSE4CPS studies has increased significantly. Within the primary studies, the popularity of using Domain-Specific Languages (DSLs) is comparable with the use of the standardised UML modelling notation. Most primary studies do not explicitly address specific security concerns (e.g., confidentiality, integrity) but rather focus on security analyses in general on threats, attacks or vulnerabilities. Few primary studies propose to engineer security solutions for CPSs. Many focus on the early stages of development lifecycle such as security requirement engineering or analysis. Conclusion: The SMS does not only provide the state of the art in MBSE4CPS, but also points out several open issues that would deserve more investigation, e.g., the lack of engineering security solutions for CPSs, limited tool support, too few industrial case studies, and the challenge of bridging DSLs in engineering secure CPSs. (C) 2016 Elsevier B.V. All rights reserved.
引用
收藏
页码:116 / 135
页数:20
相关论文
共 50 条
  • [1] A Semantic Model-based Security Engineering Framework for Cyber-Physical Systems
    Aigner, Andreas
    Khelil, Abdelmajid
    [J]. 2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1826 - 1833
  • [2] A Systematic Mapping Study on Security Requirements Engineering Frameworks for Cyber-Physical Systems
    Rehman, Shafiq
    Gruhn, Volker
    Shafiq, Saad
    Inayat, Irum
    [J]. SECURITY, PRIVACY, AND ANONYMITY IN COMPUTATION, COMMUNICATION, AND STORAGE (SPACCS 2018), 2018, 11342 : 428 - 442
  • [3] CYBER-PHYSICAL SYSTEMS ENGINEERING: MODEL-BASED SOLUTIONS
    Garro, Alfredo
    Vaccaro, Vittorio
    Dutre, Stefan
    Stegen, Jef
    [J]. PROCEEDINGS OF THE 2019 SUMMER SIMULATION CONFERENCE (SUMMERSIM '19), 2019,
  • [4] Model-based Trustworthiness Evaluation of Autonomous Cyber-Physical Production Systems: A Systematic Mapping Study
    Zahid, Maryam
    Bucaioni, Alessio
    Flammini, Francesco
    [J]. ACM COMPUTING SURVEYS, 2024, 56 (06)
  • [5] A Model-Based Approach to Security Analysis for Cyber-Physical Systems
    Bakirtzis, Georgios
    Carter, Bryan T.
    Elks, Carl R.
    Fleming, Cody H.
    [J]. 12TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON2018), 2018, : 496 - 503
  • [6] Managing Heterogeneity in Model-Based Systems Engineering of Cyber-Physical Systems
    Van Acker, Bert
    Denil, Joachim
    Vangheluwe, Hans
    De Meulenaere, Paul
    [J]. 2015 10TH INTERNATIONAL CONFERENCE ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING (3PGCIC), 2015, : 617 - 622
  • [7] Applications of model-driven engineering in cyber-physical systems: A systematic mapping study
    Mohamed, Mustafa Abshir
    Challenger, Moharram
    Kardas, Geylani
    [J]. JOURNAL OF COMPUTER LANGUAGES, 2020, 59
  • [8] A Systematic Mapping Study on the Verification of Cyber-Physical Systems
    Duan, Pengfei
    Zhou, Ying
    Gong, Xufang
    Li, Bixin
    [J]. IEEE ACCESS, 2018, 6 : 59043 - 59064
  • [9] A systematic literature review of model-driven security engineering for cyber-physical systems
    Geismann, Johannes
    Bodden, Eric
    [J]. JOURNAL OF SYSTEMS AND SOFTWARE, 2020, 169
  • [10] A Conceptual Model-Based Systems Engineering Method for Creating Secure Cyber-Physical Systems
    Larsen, Martin H.
    Muller, Gerrit
    Kokkula, Satyanarayana
    [J]. INCOSE International Symposium, 2022, 32 (S2) : 202 - 213