论文标题
基于模型的网络物理系统安全风险评估
Model-Based Risk Assessment for Cyber Physical Systems Security
论文作者
论文摘要
用于网络物理系统(CPS)安全设计的传统技术要么独立处理网络和物理系统,要么无法解决用于监视和控制物理过程的实时嵌入式控制器和网络的特定漏洞。在这项工作中,我们利用具有现实世界中工业控制器和通信协议的CPS测试的CPS测试来开发和测试一种基于集成的模型的CPS安全风险评估。测试台监测并控制实时模拟的放热连续搅拌储罐反应器(CSTR)。 CSTR是许多行业的基本过程单元,包括石油\&天然气,石化,水处理和核工业。此外,由于缺乏可能的机械保护,由于网络攻击可能触发的危险情况,该过程很丰富。本文提出了一种综合方法,用于分析和设计给定CPS的网络安全系统,在该系统中首先确定物理威胁以指导风险评估过程。使用混合自动机列举系统的潜在危险状态,为物理系统得出了数学模型。然后,使用网络和数据流模型对网络系统进行分析,以开发可能导致已确定危害的攻击方案。最后,在测试台上执行攻击方案,并在预防和减轻攻击的可能方法上获得观察。从实验中获得的见解导致了几个关键发现,包括混合自动机在安全风险评估中的表现力,危害开发时间及其对网络安全设计的影响以及CPS的物理和网络系统之间的紧密耦合,这需要集成设计方法来实现成本效益和安全设计。
Traditional techniques for Cyber-Physical Systems (CPS) security design either treat the cyber and physical systems independently, or do not address the specific vulnerabilities of real time embedded controllers and networks used to monitor and control physical processes. In this work, we develop and test an integrated model-based approach for CPS security risk assessment utilizing a CPS testbed with real-world industrial controllers and communication protocols. The testbed monitors and controls an exothermic Continuous Stirred Tank Reactor (CSTR) simulated in real-time. CSTR is a fundamental process unit in many industries, including Oil \& Gas, Petrochemicals, Water treatment, and nuclear industry. In addition, the process is rich in terms of hazardous scenarios that could be triggered by cyber attacks due to the lack of possible mechanical protection. The paper presents an integrated approach to analyze and design the cyber security system for a given CPS where the physical threats are identified first to guide the risk assessment process. A mathematical model is derived for the physical system using a hybrid automaton to enumerate potential hazardous states of the system. The cyber system is then analyzed using network and data flow models to develop the attack scenarios that may lead to the identified hazards. Finally, the attack scenarios are performed on the testbed and observations are obtained on the possible ways to prevent and mitigate the attacks. The insights gained from the experiments result in several key findings, including the expressive power of hybrid automaton in security risk assessment, the hazard development time and its impact on cyber security design, and the tight coupling between the physical and the cyber systems for CPS that requires an integrated design approach to achieve cost-effective and secure designs.