Digital Twin-Enhanced Incident Response for Cyber-Physical Systems

Digital Twin-Enhanced Incident Response for Cyber-Physical Systems
复制标题

网络物理系统的数字孪生增强事件响应

DOI:
10.1145/3600160.3600195
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Allison D
Allison D
中科院分区:
--
文献类型:
--
作者:
Allison D

文献摘要

参考文献

被引文献

相似文献

网络物理系统支撑着我们社会的许多关键基础设施。确保他们的网络安全既重要又复杂。这方面的一项主要活动是应对网络安全事件,其主要目标是检测和减轻网络攻击,以确保服务的连续性和复原力。对于网络物理系统来说,这尤其具有挑战性,因为它需要来自网络和物理(流程)领域的洞察力,以及不严格关注网络安全的利益攸关方的参与。一项备受关注的技术是数字双胞胎,即现实世界(网络-物理)系统的虚拟表示。它们可用于支持诸如评估系统状态和探索干预活动(例如升级)的后果等任务。在本文中,我们研究了使用数字双胞胎来支持网络安全。具体地说,我们的新贡献是提供了对活动类型的全面分析,以及如何将不同形式的数字双重使用应用于网络安全事件响应的各个阶段。在此分析的基础上,我们提出了一种结构化的方法来增强网络安全攻略,用于使用数字双胞胎来应对网络物理系统的事件。行动手册是事件响应的重要组成部分,可确保多学科团队有效应对网络安全事件;因此,改进执行可提高应变能力。为了说明我们的方法,我们将其用于与减轻对关键工业设备的网络攻击有关的攻略。
Cyber-physical systems underpin many of our society’s critical infrastructures. Ensuring their cyber security is important and complex. A major activity in this regard is cyber security incident response, whose primary goal is to detect and mitigate cyber-attacks in order to ensure the continuity and resilience of services. For cyber-physical systems this is particularly challenging because it requires insights both from the cyber and physical (process) domains and the engagement of stakeholders that are not strictly concerned with cyber security. A technology that is receiving a lot of attention are digital twins – virtual representations of real-world (cyber-physical) systems. They can be used to support tasks such as estimating the state of a system and exploring the consequences of interventional activities (e.g., upgrades).In this paper, we examine the use of digital twins to support cyber security. Specifically, our novel contribution is to provide a comprehensive analysis of the types of activities and how different modalities of digital twin use can be applied to the phases of cyber security incident response. Building on this analysis, we propose a structured approach to enhancing cyber security playbooks for cyber-physical systems incident response with digital twins. Playbooks are an essential component of incident response, ensuring that multi-disciplinary teams are effective in responding to cyber security incidents; therefore, improvements in their execution can result in increased resilience. To illustrate our approach, we present its use for a playbook that is concerned with mitigating a cyber-attack to critical industrial equipment.
智能电网安全测试和标准化的数字孪生方法
DOI: --
发表时间: 2020
期刊: 2020 IEEE International Workshop on Metrology for Industry 4.0 & IoT
影响因子: --
作者:
Manolya Atalay;Pelin Angin
通讯作者: Pelin Angin
Rogue 7:Rogue 工程师站对 S 7 Simatic PLC 进行攻击
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者:
E. Biham;Sara Bitan;Aviad Carmel;Alon Dankner;Uriel Malin;A. Wool
通讯作者: A. Wool
SOAR4IoT:利用数字孪生保护物联网资产
DOI: --
发表时间: 2022
期刊: ARES
影响因子: --
作者:
Philip Empl;Daniel Schlette;Daniel Zupfer;G. Pernul
通讯作者: G. Pernul
DOI: 10.1145/3241036
发表时间: 2019-03-01
影响因子: 22.7
作者:
Pearl, Judea
通讯作者: Pearl, Judea
确定核电厂运行人员程序化事故管理活动的复原力
DOI: --
发表时间: 2014
期刊:
影响因子: --
作者:
P. Savioja;L. Norros;Leena Salo;Iina Aaltonen
通讯作者: Iina Aaltonen