Pattern-Based Modeling of Cyber-Physical Systems For Analyzing Security

被引:8
|
作者
Maidl, Monika [1 ]
Wirtz, Roman [2 ]
Zhao, Tiange [1 ]
Heisel, Maritta [2 ]
Wagner, Marvin [2 ]
机构
[1] Siemens, Munich, Germany
[2] Univ Duisburg Essen, Duisburg, Germany
关键词
security analysis; cyber-physical system; system overview; model-based engineering;
D O I
10.1145/3361149.3361172
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyber-physical systems are a crucial part of many infrastructure or production systems, and are spreading into other domains as part of the IoT (Internet-of-Things) wave. As cyber-physical systems act on the physical world, attacks could have severe consequences. At the same time, cyber-physical systems can be attacked like other IT systems. So it is essential that developers consider security during the design phase of software, to design adequate security protection for the system. This fact requires a structured security analysis right from the beginning. The initial input of such a security analysis is a system overview, e.g. in form of an architecture. It is a challenging task to provide the appropriate abstraction level of the system that allows identifying security threats and weaknesses. In the present paper, we describe a pattern that assists software developers in creating an architecture which captures the relevant elements for a security analysis. The interfaces of components may not only be accessible for authorized entities, but also for attackers. Therefore, we specify different interface types which enables one to identify relevant attacks for a specific interface type. We first present the solution part of our pattern as a meta-model, for which we then provide guidelines for its instantiation. As an example, we instantiate the pattern for a typical automation and control system. Last, we evaluate the suitability of our pattern by discussing how typical threats could be mapped to the different interface types.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Cyber-physical systems and their security issues
    Alguliyev, Rasim
    Imamverdiyev, Yadigar
    Sukhostat, Lyudmila
    COMPUTERS IN INDUSTRY, 2018, 100 : 212 - 223
  • [22] Safety and security of cyber-physical systems
    Biro, Miklos
    Mashkoor, Atif
    Sametinger, Johannes
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2023, 35 (07)
  • [23] Analysis of security in cyber-physical systems
    CHEN Jie
    ZHANG Fan
    SUN Jian
    Science China(Technological Sciences), 2017, (12) : 1975 - 1977
  • [24] Cyber-Physical Systems: A Security Perspective
    Konstantinou, Charalambos
    Maniatakos, Michail
    Saqib, Fareena
    Hu, Shiyan
    Plusquellic, Jim
    Jin, Yier
    2015 20TH IEEE EUROPEAN TEST SYMPOSIUM (ETS), 2015,
  • [25] Cyber-Physical Systems Security and Privacy
    Henkel, Jorg
    IEEE DESIGN & TEST, 2017, 34 (04) : 4 - 4
  • [26] A Survey on Cyber-Physical Systems Security
    Yu, Zhenhua
    Gao, Hongxia
    Cong, Xuya
    Wu, Naiqi
    Song, Houbing Herbert
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (24) : 21670 - 21686
  • [27] Security Enumerations for Cyber-Physical Systems
    Schlette, Daniel
    Menges, Florian
    Baumer, Thomas
    Pernul, Guenther
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXIV, DBSEC 2020, 2020, 12122 : 64 - 76
  • [28] Pattern-based Interactive Configuration Derivation for Cyber-physical System Product Lines
    Lu, Hong
    Yue, Tao
    Ali, Shaukat
    ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2020, 4 (04)
  • [29] Security Games for Cyber-Physical Systems
    Vigo, Roberto
    Bruni, Alessandro
    Yuksel, Ender
    SECURE IT SYSTEMS, NORDSEC 2013, 2013, 8208 : 17 - 32
  • [30] Analysis of security in cyber-physical systems
    CHEN Jie
    ZHANG Fan
    SUN Jian
    Science China(Technological Sciences), 2017, 60 (12) : 1975 - 1977