Pattern-Based Modeling of Cyber-Physical Systems For Analyzing Security

被引:8
|
作者
Maidl, Monika [1 ]
Wirtz, Roman [2 ]
Zhao, Tiange [1 ]
Heisel, Maritta [2 ]
Wagner, Marvin [2 ]
机构
[1] Siemens, Munich, Germany
[2] Univ Duisburg Essen, Duisburg, Germany
关键词
security analysis; cyber-physical system; system overview; model-based engineering;
D O I
10.1145/3361149.3361172
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyber-physical systems are a crucial part of many infrastructure or production systems, and are spreading into other domains as part of the IoT (Internet-of-Things) wave. As cyber-physical systems act on the physical world, attacks could have severe consequences. At the same time, cyber-physical systems can be attacked like other IT systems. So it is essential that developers consider security during the design phase of software, to design adequate security protection for the system. This fact requires a structured security analysis right from the beginning. The initial input of such a security analysis is a system overview, e.g. in form of an architecture. It is a challenging task to provide the appropriate abstraction level of the system that allows identifying security threats and weaknesses. In the present paper, we describe a pattern that assists software developers in creating an architecture which captures the relevant elements for a security analysis. The interfaces of components may not only be accessible for authorized entities, but also for attackers. Therefore, we specify different interface types which enables one to identify relevant attacks for a specific interface type. We first present the solution part of our pattern as a meta-model, for which we then provide guidelines for its instantiation. As an example, we instantiate the pattern for a typical automation and control system. Last, we evaluate the suitability of our pattern by discussing how typical threats could be mapped to the different interface types.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] A Pattern-Based Approach for Designing Reliable Cyber-Physical Systems
    Petroulakis, Nikolaos E.
    Spanoudakis, George
    Askoxylakis, Ioannis G.
    Miaoudakis, Andreas
    Traganitis, Apostolos
    2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,
  • [2] Modeling security in cyber-physical systems
    Burmester, Mike
    Magkos, Ernmanouil
    Chrissikopoulos, Vassilis
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2012, 5 (3-4) : 118 - 126
  • [3] Pattern-based Business Model Development for Cyber-Physical Production Systems
    Rudtsch, Vinzent
    Gausemeier, Juergen
    Gesing, Judith
    Mittag, Tobias
    Peter, Stefan
    8TH INTERNATIONAL CONFERENCE ON DIGITAL ENTERPRISE TECHNOLOGY - DET 2014 DISRUPTIVE INNOVATION IN MANUFACTURING ENGINEERING TOWARDS THE 4TH INDUSTRIAL REVOLUTION, 2014, 25 : 313 - 319
  • [4] Pattern-Based Conceptual Modeling of Interaction with Cyber Physical Systems
    Wang, Junfeng
    Yu, Suihuai
    Wang, Ning
    INTERNATIONAL JOURNAL OF ONLINE ENGINEERING, 2016, 12 (01) : 69 - 73
  • [5] On modeling of electrical cyber-physical systems considering cyber security
    Wang, Yi-nan
    Lin, Zhi-yun
    Liang, Xiao
    Xu, Wen-yuan
    Yang, Qiang
    Yan, Gang-feng
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2016, 17 (05) : 465 - 478
  • [6] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan WANG
    Zhi-yun LIN
    Xiao LIANG
    Wen-yuan XU
    Qiang YANG
    Gang-feng YAN
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 (05) : 465 - 478
  • [7] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan Wang
    Zhi-yun Lin
    Xiao Liang
    Wen-yuan Xu
    Qiang Yang
    Gang-feng Yan
    Frontiers of Information Technology & Electronic Engineering, 2016, 17 : 465 - 478
  • [8] Fundamental Challenges of Cyber-Physical Systems Security Modeling
    Bakirtzis, Georgios
    Ward, Garrett L.
    Deloglos, Christopher J.
    Elks, Carl R.
    Horowitz, Barry M.
    Fleming, Cody H.
    2020 50TH ANNUAL IEEE-IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS-SUPPLEMENTAL VOLUME (DSN-S), 2020, : 33 - 36
  • [9] A Method for Modeling and Evaluation of the Security of Cyber-Physical Systems
    Orojloo, Hamed
    Azgomi, Mohammad Abdollahi
    2014 11TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2014, : 131 - 136
  • [10] Cyber-Physical Systems - Security
    Zseby, T.
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2018, 135 (03): : 249 - 249