A Model-based Approach to Interdependency between Safety and Security in ICS.
File(s)p31-li.pdf (991.42 KB)
Published version
Author(s)
Li, T
Hankin, C
Type
Conference Paper
Abstract
Wide use of modern ICT technologies brings not only communication efficiency, but also security vulnerabilities into industrial control systems. Traditional physically-isolated systems are now required to take cyber security into consideration, which might also lead to system failures. However, integrating security and safety analysis has always been a challenging issue and the various interdependencies between them make it even more difficult, because they might mutually enhance, or undermine. The paper proposes an integrating framework to (i) formalise the desired and undesired properties to be safe(unsafe) or secure(insecure), including the dependencies between them, (ii) evaluate if a query state reaches a safe(unsafe) or secure(insecure) state, and further quantify how safe or secure the state is. In this way,we can accurately capture the benign and harmful relations between safety and security, particularly detecting and measuring conflicting impacts on them. Finally, this framework is implemented by answer set programming to enable automatic evaluation, which is demonstrated by a case study on pipeline transportation.
Editor(s)
Janicke, H
Jones, K
Date Issued
2016-09-18
Date Acceptance
2015-09-17
Citation
3rd International Symposium for ICS & SCADA Cyber Security Research 2015, 2016
Publisher
BCS
Journal / Book Title
3rd International Symposium for ICS & SCADA Cyber Security Research 2015
Copyright Statement
© Li et al. Published by BCS Learning & Development Ltd.
Sponsor
Engineering & Physical Science Research Council (EPSRC)
Identifier
http://ewic.bcs.org/category/18535
Grant Number
EP/L021013/1
Source
ICS-CSR 2015
Publication Status
Published
Start Date
2015-09-17
Finish Date
2015-09-18
Coverage Spatial
Ingolstadt, Germany