The Impact of Network Design Interventions on the Security of Interdependent Systems

The Impact of Network Design Interventions on the Security of Interdependent Systems
复制标题

DOI:
10.1109/tcns.2023.3272849
复制
发表时间:
2023-02
影响因子:
4.2
通讯作者:
Pradeep Sharma Oruganti;Parinaz Naghizadeh;Qadeer Ahmed
Pradeep Sharma Oruganti;Parinaz Naghizadeh;Qadeer Ahmed
中科院分区:
计算机科学3区
文献类型:
--
作者:
Pradeep Sharma Oruganti;Parinaz Naghizadeh;Qadeer Ahmed

文献摘要

相似文献

在本文中,我们研究了网络物理系统(CPS)的防御问题,该系统由相互依赖的组件组成,对投资具有异质敏感性。除了对有限安全资源进行优化配置外,我们还分析了以网络设计干预形式的正交防御策略集对CPS的影响,以保护其免受攻击者的攻击。我们首先提出了一种算法,将CPS攻击图简化为等效形式,从而减少了表征防御者最优安全投资的计算需求。然后,我们以在攻击图中添加节点的形式评估网络中四种类型的设计干预,解释为:1)引入额外的保护措施;2)引入结构性冗余;3)引入功能冗余;4)引入新的功能。我们确定了加强CPS内部组成部分的干预措施可能比传统方法(如外围防御)更有益的情况。我们在两个实际用例中展示了我们提出的方法:1)对工业CPS的远程攻击和2)对汽车系统的远程攻击。我们强调了我们的结果如何与安全组织提出的建议紧密匹配,并讨论了我们的发现对CPS设计的影响。
In this article, we study the problem of defending a cyber-physical system (CPS) consisting of interdependent components with heterogeneous sensitivity to investments. In addition to the optimal allocation of limited security resources, we analyze the impact of an orthogonal set of defense strategies in the form of network design interventions in the CPS to protect it against the attacker. We first propose an algorithm to simplify the CPS attack graph to an equivalent form, which reduces the computational requirements for characterizing the defender's optimal security investments. We then evaluate four types of design interventions in the network in the form of adding nodes in the attack graph, interpreted as: 1) introducing additional safeguards; 2) introducing structural redundancies; 3) introducing functional redundancies; and 4) introducing new functionalities. We identify scenarios in which interventions that strengthen internal components of the CPS may be more beneficial than traditional approaches, such as perimeter defense. We showcase our proposed approach in two practical use cases: 1) a remote attack on an industrial CPS and 2) a remote attack on an automotive system. We highlight how our results closely match recommendations made by security organizations and discuss the implications of our findings for CPS design.