Cybersecurity of Industrial Cyber-Physical Systems: A Review

被引:54
|
作者
Kayan, Hakan [1 ]
Nunes, Matthew [1 ]
Rana, Omer [1 ]
Burnap, Pete [1 ]
Perera, Charith [1 ]
机构
[1] Cardiff Univ, Queens Bldg,5 Parade, Cardiff CF24 3AA, Wales
基金
英国工程与自然科学研究理事会;
关键词
Cyber-physical systems; industrial control systems; cybersecurity; WIRELESS SENSOR; SECURITY; INTERNET; TAXONOMY; THINGS; NETWORKS; PRIVACY; ATTACKS; TECHNOLOGY; CHALLENGES;
D O I
10.1145/3510410
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Industrial cyber-physical systems (ICPSs) manage critical infrastructures by controlling the processes based on the "physics" data gathered by edge sensor networks. Recent innovations in ubiquitous computing and communication technologies have prompted the rapid integration of highly interconnected systems to ICPSs. Hence, the "security by obscurity" principle provided by air-gapping is no longer followed. As the interconnectivity in ICPSs increases, so does the attack surface. Industrial vulnerability assessment reports have shown that a variety of new vulnerabilities have occurred due to this transition. Although there are existing surveys in this context, very little is mentioned regarding the outputs of these reports. While these reports show that the most exploited vulnerabilities occur due to weak boundary protection, these vulnerabilities also occur due to limited or ill-defined security policies. However, current literature focuses on intrusion detection systems (IDSs), network traffic analysis (NTA) methods, or anomaly detection techniques. Hence, finding a solution for the problems mentioned in these reports is relatively hard. We bridge this gap by defining and reviewing ICPSs from a cybersecurity perspective. In particular, multi-dimensional adaptive attack taxonomy is presented and utilized for evaluating real-life ICPS cyber incidents. Finally, we identify the general shortcomings and highlight the points that cause a gap in existing literature while defining future research directions.
引用
收藏
页数:35
相关论文
共 50 条
  • [41] Cyber-physical Systems
    Vogel-Heuser, Birgit
    Kowalewski, Stefan
    [J]. AT-AUTOMATISIERUNGSTECHNIK, 2013, 61 (10) : 667 - 668
  • [42] Cyber-Physical Systems
    Lamnabhi-Lagarrigue, Francoise
    Di Benedetto, Maria Domenica
    Schoitsch, Erwin
    [J]. ERCIM NEWS, 2014, (97): : 6 - 7
  • [43] Cyber-Physical Systems
    Letichevsky A.A.
    Letychevskyi O.O.
    Skobelev V.G.
    Volkov V.A.
    [J]. Letichevsky, A.A. (aaletichevsky78@gmail.com), 2017, Springer Science and Business Media, LLC (53) : 821 - 834
  • [44] CYBER-PHYSICAL SYSTEMS
    Zanero, Stefano
    [J]. COMPUTER, 2017, 50 (04) : 15 - 16
  • [45] Identifying and Protecting Cyber-Physical Systems- Influential Devices for Sustainable Cybersecurity
    Taha, Kamal
    [J]. IEEE TRANSACTIONS ON SUSTAINABLE COMPUTING, 2023, 8 (04): : 614 - 626
  • [46] Cybersecurity knowledge graph enabled attack chain detection for cyber-physical systems
    Qi, Yulu
    Gu, Zhaoquan
    Li, Aiping
    Zhang, Xiaojuan
    Shafiq, Muhammad
    Mei, Yangyang
    Lin, Kaihan
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2023, 108
  • [47] Proposal of Cybersecurity and Safety Co-engineering Approaches on Cyber-Physical Systems
    Bajan, Pierre-Marie
    Boyer, Martin
    Dubois, Anouk
    Letailleur, Jerome
    Mantissa, Kevin
    Sobieraj, Jeremy
    Tlig, Mohamed
    [J]. COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2022, 2022, 13414 : 175 - 188
  • [48] Managing cybersecurity risks of cyber-physical systems: The MARISMA-CPS pattern
    Rosado, David G.
    Santos-Olmo, Antonio
    Enrique Sanchez, Luis
    Serrano, Manuel A.
    Blanco, Carlos
    Mouratidis, Haralambos
    Fernandez-Medina, Eduardo
    [J]. COMPUTERS IN INDUSTRY, 2022, 142
  • [49] AlphaSOC: Reinforcement Learning-based Cybersecurity Automation for Cyber-Physical Systems
    Silva, Ryan
    Hickert, Cameron
    Sarfaraz, Nicolas
    Brush, Jeff
    Silbermann, Josh
    Sookoor, Tamim
    [J]. 2022 13TH ACM/IEEE INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (ICCPS 2022), 2022, : 290 - 291
  • [50] Automated Knowledge-Based Cybersecurity Risk Assessment of Cyber-Physical Systems
    Phillips, Stephen C.
    Taylor, Steve
    Boniface, Michael
    Modafferi, Stefano
    Surridge, Mike
    [J]. IEEE ACCESS, 2024, 12 : 82482 - 82505