STRIDE-based Threat Modeling for Cyber-Physical Systems

被引:0
|
作者
Khan, Rafiullah [1 ]
McLaughlin, Kieran [1 ]
Laverty, David [1 ]
Sezer, Sakir [1 ]
机构
[1] Queens Univ Belfast, Belfast, Antrim, North Ireland
基金
英国工程与自然科学研究理事会;
关键词
Cyber physical systems; smart grid; synchrophasors; STRIDE; threat modeling; cyber security;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Critical infrastructures and industrial control systems are complex Cyber-Physical Systems (CPS). To ensure reliable operations of such systems, comprehensive threat modeling during system design and validation is of paramount significance. Previous works in literature mostly focus on safety, risks and hazards in CPS but lack effective threat modeling necessary to eliminate cyber vulnerabilities. Further, impact of cyber attacks on physical processes is not fully understood. This paper presents a comprehensive threat modeling framework for CPS using STRIDE, a systematic approach for ensuring system security at the component level. This paper first devises a feasible and effective methodology for applying STRIDE and then demonstrates it against a real synchrophasor-based synchronous islanding testbed in the laboratory. It investigates (i) what threat types could emerge in each system component based on the security properties lacking, and (ii) how a vulnerability in a system component risks the entire system security. The paper identifies that STRIDE is a light-weight and effective threat modeling methodology for CPS that simplifies the task for security analysts to identify vulnerabilities and plan appropriate component level security measures at the system design stage.
引用
收藏
页数:6
相关论文
共 50 条
  • [1] STRIDE-based Cyber Security Threat Modeling for IoT-enabled Precision Agriculture Systems
    Al Asif, Md Rashid
    Hasan, Khondokar Fida
    Islam, Md Zahidul
    Khondoker, Rahamatullah
    [J]. 2021 3RD INTERNATIONAL CONFERENCE ON SUSTAINABLE TECHNOLOGIES FOR INDUSTRY 4.0 (STI), 2021,
  • [2] Threat modeling in cyber-physical systems
    Fernandez, Eduardo B.
    [J]. 2016 IEEE 14TH INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, 14TH INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, 2ND INTL CONF ON BIG DATA INTELLIGENCE AND COMPUTING AND CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/DATACOM/CYBERSC, 2016, : 448 - 453
  • [3] STRIDE-Based Threat Modeling for MySQL Databases
    Sanfilippo, James
    Abegaz, Tamirat
    Payne, Bryson
    Salimi, Abi
    [J]. PROCEEDINGS OF THE FUTURE TECHNOLOGIES CONFERENCE (FTC) 2019, VOL 2, 2020, 1070 : 368 - 378
  • [4] Threat Modeling of Cyber-Physical Systems in Practice
    Jamil, Ameerah-Muhsinah
    Ben Othmane, Lotfi
    Valani, Altaz
    [J]. RISKS AND SECURITY OF INTERNET AND SYSTEMS (CRISIS 2021), 2022, 13204 : 3 - 19
  • [5] On Threat Modeling and Mitigation of Medical Cyber-Physical Systems
    Almohri, Hussain
    Cheng, Long
    Yao, Danfeng
    Alemzadeh, Homa
    [J]. 2017 IEEE/ACM SECOND INTERNATIONAL CONFERENCE ON CONNECTED HEALTH - APPLICATIONS, SYSTEMS AND ENGINEERING TECHNOLOGIES (CHASE), 2017, : 114 - 119
  • [6] Towards a Systematic Threat Modeling Approach for Cyber-physical Systems
    Martins, Goncalo
    Bhatia, Sajal
    Koutsoukos, Xenofon
    Stouffer, Keith
    Tang, CheeYee
    Candell, Richard
    [J]. 2015 RESILIENCE WEEK (RSW), 2015, : 114 - 119
  • [7] Modeling Cyber-Physical Systems
    Derler, Patricia
    Lee, Edward A.
    Vincentelli, Alberto Sangiovanni
    [J]. PROCEEDINGS OF THE IEEE, 2012, 100 (01) : 13 - 28
  • [8] Sensor Threat Isolation for Cyber-Physical Systems
    Zhang, Kangkang
    Kasis, Andreas
    Keliris, Christodoulos
    Polycarpou, Marios M.
    Parisini, Thomas
    [J]. IFAC PAPERSONLINE, 2023, 56 (02): : 11324 - 11329
  • [9] Model-Based Threat Modeling for Cyber-Physical Systems: A Computer-Aided Approach
    Maidl, Monika
    Muenz, Gerhard
    Seltzsam, Stefan
    Wagner, Marvin
    Wirtz, Roman
    Heisel, Maritta
    [J]. SOFTWARE TECHNOLOGIES (ICSOFT 2020), 2021, 1447 : 158 - 183
  • [10] Threat Modeling of Cyber-Physical Systems-A Case Study of a Microgrid System
    Khalil, Shaymaa Mamdouh
    Bahsi, Hayretdin
    Dola, Henry Ochieng'
    Korotko, Tarmo
    McLaughlin, Kieran
    Kotkas, Vahur
    [J]. COMPUTERS & SECURITY, 2023, 124