STRIDE-based threat modeling for cyber-physical systems

STRIDE-based threat modeling for cyber-physical systems
复制标题

DOI:
10.1109/isgteurope.2017.8260283
复制
发表时间:
2017-09
期刊:
2017 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe)
影响因子:
--
通讯作者:
Rafiullah Khan;K. Mclaughlin;D. Laverty;S. Sezer
Rafiullah Khan;K. Mclaughlin;D. Laverty;S. Sezer
中科院分区:
其他
文献类型:
--
作者:
Rafiullah Khan;K. Mclaughlin;D. Laverty;S. Sezer

文献摘要

相似文献

关键基础设施和工业控制系统是复杂的信息物理系统(CPS)。为了确保这些系统的可靠运行,在系统设计和验证期间进行全面的威胁建模至关重要。以往的文献主要集中在CPS的安全性,风险和危害,但缺乏有效的威胁建模所需的消除网络漏洞。此外,网络攻击对物理过程的影响尚未完全了解。本文提出了一个全面的威胁建模框架CPS使用STRIDE,系统的方法,以确保系统的安全性,在组件级。本文首先设计了一个可行的和有效的方法来应用STRIDE,然后证明它对一个真实的同步相量为基础的同步孤岛实验台在实验室。它调查了(i)基于缺乏的安全属性,每个系统组件中可能出现的威胁类型,以及(ii)系统组件中的漏洞如何危及整个系统的安全。该文件确定,STRIDE是一个轻量级和有效的威胁建模方法CPS,简化了安全分析师的任务,以确定漏洞和计划适当的组件级安全措施,在系统设计阶段。
Critical infrastructures and industrial control systems are complex Cyber-Physical Systems (CPS). To ensure reliable operations of such systems, comprehensive threat modeling during system design and validation is of paramount significance. Previous works in literature mostly focus on safety, risks and hazards in CPS but lack effective threat modeling necessary to eliminate cyber vulnerabilities. Further, impact of cyber attacks on physical processes is not fully understood. This paper presents a comprehensive threat modeling framework for CPS using STRIDE, a systematic approach for ensuring system security at the component level. This paper first devises a feasible and effective methodology for applying STRIDE and then demonstrates it against a real synchrophasor-based synchronous islanding testbed in the laboratory. It investigates (i) what threat types could emerge in each system component based on the security properties lacking, and (ii) how a vulnerability in a system component risks the entire system security. The paper identifies that STRIDE is a light-weight and effective threat modeling methodology for CPS that simplifies the task for security analysts to identify vulnerabilities and plan appropriate component level security measures at the system design stage.