A Model-Based Approach to Security Analysis for Cyber-Physical Systems
arXiv:1710.11442 · doi:10.1109/SYSCON.2018.8369518
Abstract
Evaluating the security of cyber-physical systems throughout their life cycle is necessary to assure that they can be deployed and operated in safety-critical applications, such as infrastructure, military, and transportation. Most safety and security decisions that can have major effects on mitigation strategy options after deployment are made early in the system's life cycle. To allow for a vulnerability analysis before deployment, a sufficient well-formed model has to be constructed. To construct such a model we produce a taxonomy of attributes; that is, a generalized schema for system attributes. This schema captures the necessary specificity that characterizes a possible real system and can also map to the attack vector space associated with the model's attributes. In this way, we can match possible attack vectors and provide architectural mitigation at the design phase. We present a model of a flight control system encoded in the Systems Modeling Language, commonly known as SysML, but also show agnosticism with respect to the modeling language or tool used.
8 pages, 5 figures, conference
Cited by in corpus (5)
- Data Driven Vulnerability Exploration for Design Phase System Analysis
- Looking for a Black Cat in a Dark Room: Security Visualization for Cyber-Physical System Design and Analysis
- Fundamental Challenges of Cyber-Physical Systems Security Modeling
- A Systematic Literature Review on Model-driven Engineering for Cyber-Physical Systems
- Towards formally analyzed Cyber-Physical Systems