Pattern-Based Modeling of Cyber-Physical Systems For Analyzing Security

被引:8
|
作者
Maidl, Monika [1 ]
Wirtz, Roman [2 ]
Zhao, Tiange [1 ]
Heisel, Maritta [2 ]
Wagner, Marvin [2 ]
机构
[1] Siemens, Munich, Germany
[2] Univ Duisburg Essen, Duisburg, Germany
关键词
security analysis; cyber-physical system; system overview; model-based engineering;
D O I
10.1145/3361149.3361172
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyber-physical systems are a crucial part of many infrastructure or production systems, and are spreading into other domains as part of the IoT (Internet-of-Things) wave. As cyber-physical systems act on the physical world, attacks could have severe consequences. At the same time, cyber-physical systems can be attacked like other IT systems. So it is essential that developers consider security during the design phase of software, to design adequate security protection for the system. This fact requires a structured security analysis right from the beginning. The initial input of such a security analysis is a system overview, e.g. in form of an architecture. It is a challenging task to provide the appropriate abstraction level of the system that allows identifying security threats and weaknesses. In the present paper, we describe a pattern that assists software developers in creating an architecture which captures the relevant elements for a security analysis. The interfaces of components may not only be accessible for authorized entities, but also for attackers. Therefore, we specify different interface types which enables one to identify relevant attacks for a specific interface type. We first present the solution part of our pattern as a meta-model, for which we then provide guidelines for its instantiation. As an example, we instantiate the pattern for a typical automation and control system. Last, we evaluate the suitability of our pattern by discussing how typical threats could be mapped to the different interface types.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Modeling Architectures of Cyber-Physical Systems
    Kusmenko, Evgeny
    Roth, Alexander
    Rumpe, Bernhard
    von Wenckstern, Michael
    MODELLING FOUNDATIONS AND APPLICATIONS, ECMFA 2017, 2017, 10376 : 34 - 50
  • [42] Context modeling for cyber-physical systems
    Daun, Marian
    Tenbergen, Bastian
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2023, 35 (07)
  • [43] Challenges in Modeling Cyber-Physical Systems
    Broy, Manfred
    2013 ACM/IEEE INTERNATIONAL CONFERENCE ON INFORMATION PROCESSING IN SENSOR NETWORKS (IPSN), 2013, : 5 - 5
  • [44] Compositional Cyber-Physical Systems Modeling
    Bakirtzis, Georgios
    Vasilakopoulou, Christina
    Fleming, Cody H.
    ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2021, (333): : 125 - 138
  • [45] Analyzing Early Requirements of Cyber-Physical Systems Through Structure and Goal Modeling
    Liu, Chun
    Zhang, Wei
    Zhao, Haiyan
    Jin, Zhi
    2013 20TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2013), VOL 1, 2013, : 140 - 147
  • [46] A framework for modeling and analyzing cyber-physical systems using statistical model checking
    Alshalalfah, Abdel-Latif
    Mohamed, Otmane Ait
    Ouchani, Samir
    INTERNET OF THINGS, 2023, 22
  • [47] Formal modeling and analyzing high-confidence software of cyber-physical systems
    Yu, Zhen-Hua, 1857, Systems Engineering Society of China (34):
  • [48] A first Cyber-Physical Systems of Systems modeling
    Maurice, Olivier
    2018 13TH ANNUAL CONFERENCE ON SYSTEM OF SYSTEMS ENGINEERING (SOSE), 2018, : 9 - 13
  • [49] Cyber-physical systems security: A systematic review
    Harkat, Houda
    Camarinha-Matos, Luis M.
    Goes, Joao
    Ahmed, Hasmath F. T.
    COMPUTERS & INDUSTRIAL ENGINEERING, 2024, 188
  • [50] A Benchmark of Security Metrics in Cyber-Physical Systems
    Aigner, Andreas
    Khelil, Abdelmajid
    2020 IEEE INTERNATIONAL CONFERENCE ON SENSING, COMMUNICATION AND NETWORKING (SECONWORKSHOPS), 2020,