Cyber-Physical Security of Air Traffic Surveillance Systems

Cyber-Physical Security of Air Traffic Surveillance Systems
复制标题

DOI:
10.1007/978-3-030-62840-6_1
复制
发表时间:
2020-03
期刊:
--
影响因子:
--
通讯作者:
Anusha Thudimilla;B. McMillin
Anusha Thudimilla;B. McMillin
中科院分区:
其他
文献类型:
--
作者:
Anusha Thudimilla;B. McMillin

文献摘要

相似文献

网络物理系统安全是关键基础设施中的一个重要问题。网络和物理组件之间的强烈相互依赖性使得网络物理系统极易受到完整性攻击,例如注入恶意数据和投射虚假传感器测量结果。传统的安全模型将网络物理系统划分为两个域:高域和低域。这种绝对分区不太适合网络物理系统,因为它们包含多个重叠分区。信息流属性模拟系统的输入如何影响其跨安全分区的输出,是网络物理系统中的重要考虑因素。信息流支持可追溯性分析,有助于检测漏洞和异常源,有助于缓解措施的实施。本章介绍了一种具有基于图形的信息流遍历的自动化模型,用于识别民用航空使用的自动相关监视广播(ADS-B)系统中的信息流路径,然后将信息流划分到安全域中。结果有助于识别 ADS-B 系统的故障和攻击漏洞,并确定潜在的缓解措施。
Cyber-physical system security is a significant concern in the critical infrastructure. Strong interdependencies between cyber and physical components render cyber-physical systems highly susceptible to integrity attacks such as injecting malicious data and projecting fake sensor measurements. Traditional security models partition cyber-physical systems into just two domains – high and low. This absolute partitioning is not well suited to cyber-physical systems because they comprise multiple overlapping partitions. Information flow properties, which model how inputs to a system affect its outputs across security partitions, are important considerations in cyber-physical systems. Information flows support traceability analysis that helps detect vulnerabilities and anomalous sources, contributing to the implementation of mitigation measures.This chapter describes an automated model with graph-based information flow traversal for identifying information flow paths in the Automatic Dependent Surveillance-Broadcast (ADS-B) system used in civilian aviation, and subsequently partitioning the flows into security domains. The results help identify ADS-B system vulnerabilities to failures and attacks, and determine potential mitigation measures.