Cyber-physical system security for networked industrial processes

Cyber-physical system security for networked industrial processes
复制标题

DOI:
10.1007/s11633-015-0923-9
复制
发表时间:
2015-11
影响因子:
4.3
通讯作者:
Shuang Huang;Chunjie Zhou;Shuanghua Yang;Yuanqing Qin
Shuang Huang;Chunjie Zhou;Shuanghua Yang;Yuanqing Qin
中科院分区:
计算机科学4区
文献类型:
--
作者:
Shuang Huang;Chunjie Zhou;Shuanghua Yang;Yuanqing Qin

文献摘要

相似文献

信息物理系统(CPS)是网络、计算和物理过程的集成,其中嵌入式计算设备通过网络持续感知、监视和控制物理过程。将Internet、实时计算机控制系统和工业过程结合在一起的网络化工业过程是典型的CPS。随着网络攻击的日益频繁,安全问题逐渐成为CPS面临的关键问题。提出了一种面向网络化工业过程的信息物理系统安全防护方法,工业CPSs,提出。在这种方法中,从一般信息技术(IT)安全保护到主动保护,再到入侵容忍和物理安全保护,逐层处理攻击。在实时控制系统中实现入侵容忍是最关键的一层,因为真实的实时控制系统直接影响到物理层。这种新的入侵容忍方案的闭环防御框架考虑到工业CPS的特殊要求。为了说明CPS的安全保护方法的有效性,网络水位控制系统的架构分析和设计语言(AADL)环境中的案例研究。仿真结果表明,该方法可以快速防御3种注入式攻击。
Cyber-physical systems (CPSs) are integrations of networks, computation and physical processes, where embedded computing devices continually sense, monitor, and control the physical processes through networks. Networked industrial processes combining internet, real-time computer control systems and industrial processes together are typical CPSs. With the increasingly frequent cyber-attack, security issues have gradually become key problems for CPSs. In this paper, a cyber-physical system security protection approach for networked industrial processes, i.e., industrial CPSs, is proposed. In this approach, attacks are handled layer by layer from general information technology (IT) security protection, to active protection, then to intrusion tolerance and physical security protection. The intrusion tolerance implemented in real-time control systems is the most critical layer because the real time control system directly affects the physical layer. This novel intrusion tolerance scheme with a closed loop defense framework takes into account the special requirements of industrial CPSs. To illustrate the effectiveness of the CPS security protection approach, a networked water level control system is described as a case study in the architecture analysis and design language (AADL) environment. Simulation results show that 3 types of injected attacks can be quickly defended by using the proposed protection approach.