Authors:
Elias Seid
;
Oliver Popov
and
Fredrik Blix
Affiliation:
Department of Computer and Systems Sciences, Stockholm University, Sweden
Keyword(s):
Cyber Physical-Systems, Industrial Internet of Things, Security Requirements, Goal Model, Attack Pattern, Domain Assumption.
Abstract:
In today’s software systems, security is one of the a major issues that need to be considered when designing Cyber Physical-Systems(CPS). CPS are engineered systems built from, and depend upon, the seamless integration of computational algorithms and physical components. Security breaches are on the rise, and CPS are challenged by a catastrophic damage which resulted in billions of losses. Security solutions to the Cyber Physical-Systems that we have are likely to become obsolete. Even though security agents issue new sets of vulnerability indicators and patches to address the security breach, these vulnerability indicators change over time, which is a perpetual process. We argue that any security solution for the Cyber Physical-Systems should be adaptive, based on the type of attacks and their frequency. The security solution should monitor its environment continuously to defend itself from a cyber-attack by modifying its defensive mechanism. We propose a framework for modelling, an
alyzing and monitoring security attacks (events) in the social, cyber and physical infrastructure realms of CPS. The framework is evaluated by using security attack scenarios taken from a recognized security knowledge repository.
(More)