Towards Formal Security Analysis of Industrial Control Systems

被引:24
|
作者
Rocchetto, Marco [1 ]
Tippenhauer, Nils Ole [2 ]
机构
[1] Univ Luxembourg, Secur & Trust Software Syst, Luxembourg, Luxembourg
[2] Singapore Univ Technol & Design, Informat Syst Technol & Design, Singapore, Singapore
基金
新加坡国家研究基金会;
关键词
D O I
10.1145/3052973.3053024
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We discuss the use of formal modeling to discover potential attacks on Cyber-Physical systems, in particular Industrial Control Systems. We propose a general approach to achieve that goal considering physical-layer interactions, time and state discretization of the physical process and logic, and the use of suitable attacker profiles. We then apply the approach to model a real-world water treatment testbed using ASLan++ and analyze the resulting transition system using CL-AtSe, identifying four attack classes. To show that the attacks identified by our formal assessment represent valid attacks, we compare them against practical attacks on the same system found independently by six teams from industry and academia. We find that 7 out of the 8 practical attacks were also identified by our formal assessment. We discuss limitations resulting from our chosen level of abstraction, and a number of modeling shortcuts to reduce the runtime of the analysis.
引用
收藏
页码:114 / 126
页数:13
相关论文
共 50 条
  • [21] A logic-based framework for the security analysis of Industrial Control Systems
    Lemaire L.
    Vossaert J.
    Jansen J.
    Naessens V.
    [J]. Automatic Control and Computer Sciences, 2017, 51 (2) : 114 - 123
  • [22] A new safety and security risk analysis framework for industrial control systems
    Kriaa, Siwar
    Bouissou, Marc
    Laarouchi, Youssef
    [J]. PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2019, 233 (02) : 151 - 174
  • [23] A formal component concept for the specification of industrial control systems
    Braatz, B
    Klein, M
    Schröter, G
    Bengel, M
    [J]. INTEGRATION OF SOFTWARE SPECIFICATION TECHNIQUES FOR APPLICATIONS IN ENGINEERING, 2004, 3147 : 69 - 88
  • [24] The drift of industrial control systems to pseudo security
    Donnelly, Peter
    Abuhmida, Mabrouka
    Tubb, Christopher
    [J]. INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2022, 38
  • [25] Strategic Security Protection for Industrial Control Systems
    Takagi, Hitomi
    Morita, Takahito
    Matta, Masafumi
    Moritani, Hiroki
    Hamaguchi, Takashi
    Jing, Sun
    Koshijima, Ichiro
    Hashimoto, Yoshihiro
    [J]. 2015 54TH ANNUAL CONFERENCE OF THE SOCIETY OF INSTRUMENT AND CONTROL ENGINEERS OF JAPAN (SICE), 2015, : 986 - 992
  • [26] Industrial Control Systems Security: What is happening?
    Krotofil, Maryna
    Gollmann, Dieter
    [J]. 2013 11TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2013, : 670 - 675
  • [27] Cyber Security Provision for Industrial Control Systems
    Amanowicz, Marek
    Jarmakiewicz, Jacek
    [J]. TRENDS IN ADVANCED INTELLIGENT CONTROL, OPTIMIZATION AND AUTOMATION, 2017, 577 : 611 - 620
  • [28] Industrial Control Systems Security: What is happening?
    Krotofil, Marina
    Gollmann, Dieter
    [J]. 2013 11TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2013, : 664 - 669
  • [29] Deep Security Scanner for Industrial Control Systems
    Mahendra, Lagineni
    Hareesh, Reddi
    Kalluri, Rajesh
    Kumar, R. K. Senthil
    Bindhumadhava, B. S.
    [J]. 2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 447 - 452
  • [30] Techniques for Enhancing Security in Industrial Control Systems
    Varadharajan, Vijay
    Tupakula, Uday
    Karmakar, Kallol Krishna
    [J]. ACM TRANSACTIONS ON CYBER-PHYSICAL SYSTEMS, 2024, 8 (01)