Managing cybersecurity risks of cyber-physical systems: The MARISMA-CPS pattern

被引:11
|
作者
Rosado, David G. [1 ]
Santos-Olmo, Antonio [1 ]
Enrique Sanchez, Luis [1 ]
Serrano, Manuel A. [2 ]
Blanco, Carlos [3 ]
Mouratidis, Haralambos [4 ]
Fernandez-Medina, Eduardo [1 ]
机构
[1] Univ Castilla La Mancha, GSyA Res Grp, Ciudad Real, Spain
[2] Univ Castilla La Mancha, Alarcos Res Grp, Ciudad Real, Spain
[3] Univ Cantabria, ISTR Res Grp, Dept Comp Sci & Elect, Santander, Spain
[4] Univ Essex, Inst Analyt & Data Sci, Colchester, Essex, England
基金
欧盟地平线“2020”;
关键词
Risk analysis; Risk assessment; MARISMA; Cyber-physical system; SECURITY; MANAGEMENT;
D O I
10.1016/j.compind.2022.103715
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Cyber-physical systems (CPSs) are smart systems that include engineered interacting networks of physical and computational components. CPSs have an increasingly presence on critical infrastructures and an impact in almost every aspect of our daily life, including transportation, healthcare, electric power, and advanced manufacturing. However, CPSs face a growing and serious security issue due to the widespread connectivity between the cyber world and the physical world. Although risk assessment methods for traditional IT systems are now very mature, these are not adequate for risk assessment of CPSs due to the different characteristics of the later. As such, there is an urgent need to define approaches that will adequately support risk assessment for CPSs. To contribute to this important challenge, we propose a novel risk analysis technique for CPSs based on MARISMA, a security management methodology, and eMARISMA, a technological environment in the cloud. Our work contributes to the state of the art through the definition of the MARISMA-CPS pattern that incorporates a set of reusable and adaptable elements that allows risks in CPSs to be managed and controlled, which is aligned with the main CPSs frameworks, such as those defined by NIST and ENISA. A case study for a smart hospital is presented, showing how the reusability and adaptability of the proposal allows the proposed MARISMA-CPS pattern to be easily adapted to any CPS environment. Such adaptability is important to ensure wide application in the domain of CPSs. (C) 2022 Published by Elsevier B.V.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Managing the Risks of Cyber-Physical Systems
    Axelrod, C. Warren
    [J]. 2013 NINTH ANNUAL CONFERENCE ON LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY (LISAT 2013), 2013,
  • [2] Cybersecurity in Cyber-Physical Power Systems
    Ribas Monteiro, Luiz Fernando
    Rodrigues, Yuri R.
    Zambroni de Souza, A. C.
    [J]. ENERGIES, 2023, 16 (12)
  • [3] Analytics for Cybersecurity Policy of Cyber-Physical Systems
    Choucri, Nazli
    Agarwal, Gaurav
    [J]. 2022 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2022,
  • [4] Cybersecurity of Industrial Cyber-Physical Systems: A Review
    Kayan, Hakan
    Nunes, Matthew
    Rana, Omer
    Burnap, Pete
    Perera, Charith
    [J]. ACM COMPUTING SURVEYS, 2022, 54 (11S)
  • [5] Proactive Measures for Cyber-Physical Systems Cybersecurity
    Taha, Kamal
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 353 - 358
  • [6] CYBER-PHYSICAL SYSTEMS (CPS): THE "SYSTEMS-OF-SYSTEMS" CHALLENGES
    Schoitsch, Erwin
    [J]. IDIMT-2010: INFORMATION TECHNOLOGY - HUMAN VALUES, INNOVATION AND ECONOMY, 2010, 32 : 163 - 176
  • [7] Security Reference Architecture for Cyber-Physical Systems (CPS)
    Moreno, Julio
    Rosado, David G.
    Sanchez, Luis E.
    Serrano, Manuel A.
    Fernandez-Medina, Eduardo
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2021, 27 (06) : 609 - 634
  • [8] Autonomous mitigation of cyber risks in the Cyber-Physical Systems
    Kholidy, Hisham A.
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 115 : 171 - 187
  • [9] Cybersecurity for Battery Management Systems in Cyber-Physical Environments
    Kumbhar, Sourabh
    Faika, Tasnimun
    Makwana, Darshan
    Kim, Taesic
    Lee, Young
    [J]. 2018 IEEE TRANSPORTATION AND ELECTRIFICATION CONFERENCE AND EXPO (ITEC), 2018, : 934 - 938
  • [10] CRYSTAL framework: Cybersecurity assurance for cyber-physical systems
    Moradi, Fereidoun
    Asadollah, Sara Abbaspour
    Pourvatan, Bahman
    Moezkarimi, Zahra
    Sirjani, Marjan
    [J]. JOURNAL OF LOGICAL AND ALGEBRAIC METHODS IN PROGRAMMING, 2024, 139