VERCASM-CPS: Vulnerability Analysis and Cyber Risk Assessment for Cyber-Physical Systems

被引:7
|
作者
Northern, Bradley [1 ]
Burks, Trey [1 ]
Hatcher, Marlana [1 ]
Rogers, Michael [1 ]
Ulybyshev, Denis [1 ]
机构
[1] Tennessee Technol Univ, Dept Comp Sci, Cookeville, TN 38505 USA
关键词
cyber-physical systems; industrial control systems; data privacy; moving target defense; cyber-risk score;
D O I
10.3390/info12100408
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Since Cyber-Physical Systems (CPS) are widely used in critical infrastructures, it is essential to protect their assets from cyber attacks to increase the level of security, safety and trustworthiness, prevent failure developments, and minimize losses. It is necessary to analyze the CPS configuration in an automatic mode to detect the most vulnerable CPS components and reconfigure or replace them promptly. In this paper, we present a methodology to determine the most secure CPS configuration by using a public database of cyber vulnerabilities to identify the most secure CPS components. We also integrate the CPS cyber risk analysis with a Controlled Moving Target Defense, which either replaces the vulnerable CPS components or re-configures the CPS to harden it, while the vulnerable components are being replaced. Our solution helps to design a more secure CPS by updating the configuration of existing CPS to make them more resilient against cyber attacks. In this paper, we will compare cyber risk scores for different CPS configurations and show that the Windows(R) 10 build 20H2 operating system is more secure than Linux Ubuntu(R) 20.04, while Red Hat(R) Enterprise(R) Linux is the most secure in some system configurations.
引用
收藏
页数:23
相关论文
共 50 条
  • [21] Towards automatic discovery and assessment of vulnerability severity in cyber-physical systems
    Jiang, Yuning
    Atif, Yacine
    ARRAY, 2022, 15
  • [22] SCADA modeling for performance and vulnerability assessment of integrated cyber-physical systems
    Stefanov, Alexandru
    Liu, Chen-Ching
    Govindarasu, Manimaran
    Wu, Shinn-Shyan
    INTERNATIONAL TRANSACTIONS ON ELECTRICAL ENERGY SYSTEMS, 2015, 25 (03): : 498 - 519
  • [23] Vulnerability Analysis and Risk Assessment of EV Charging System under Cyber-Physical Threats
    Reeh, Devin
    Tapia, Francisco Cruz
    Chung, Yu-Wei
    Khaki, Behnam
    Chu, Chicheng
    Gadh, Rajit
    2019 IEEE TRANSPORTATION ELECTRIFICATION CONFERENCE AND EXPO (ITEC), 2019,
  • [24] Quality Assessment in Cyber-Physical Systems
    Redko, Sergey G.
    Shadrin, Alexander D.
    CYBER-PHYSICAL SYSTEMS AND CONTROL, 2020, 95 : 124 - 130
  • [25] Effectiveness assessment of Cyber-Physical Systems
    Rocher, Gerald
    Tigli, Jean-Yves
    Lavirotte, Stephane
    Nhan Le Thanh
    INTERNATIONAL JOURNAL OF APPROXIMATE REASONING, 2020, 118 (118) : 112 - 132
  • [26] An Assessment of Security Analysis Tools for Cyber-Physical Systems
    Lemaire, Laurens
    Vossaert, Jan
    De Decker, Bart
    Naessens, Vincent
    RISK ASSESSMENT AND RISK-DRIVEN QUALITY ASSURANCE, RISK 2016, 2017, 10224 : 66 - 81
  • [27] Understanding the impact of cyber-physical correlation on security analysis of Cyber-Physical Systems
    Jiang, Luanjuan
    Chen, Xin
    2021 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS DASC/PICOM/CBDCOM/CYBERSCITECH 2021, 2021, : 529 - 534
  • [28] Special Issue on Cyber-Physical Systems (CPS) Part I
    Guo, Song
    Frey, Hannes
    Kato, Nei
    Liu, Yunhao
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2013, 1 (01) : 6 - 9
  • [29] CPS-Heart: Cyber-Physical Systems for Cardiovascular Diseases
    Verma, Dhwaj
    PROCEEDINGS OF THE WORKSHOP PROGRAM OF THE 19TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING AND NETWORKING (ICDCN'18), 2018,
  • [30] Specification, Analyzing Challenges and Approaches for Cyber-Physical Systems (CPS)
    Wan, Kaiyu
    Man, K. L.
    Hughes, D.
    ENGINEERING LETTERS, 2010, 18 (03)