11
IRUS Total
Downloads
  Altmetric

Identifying security-critical cyber-physical components in industrial control systems

File Description SizeFormat 
1905.04796v1.pdfWorking paper1.21 MBAdobe PDFView/Open
Title: Identifying security-critical cyber-physical components in industrial control systems
Authors: Barrère, M
Hankin, C
Nicolau, N
Eliades, DG
Parisini, T
Item Type: Working Paper
Abstract: In recent years, Industrial Control Systems (ICS) have become an appealing target for cyber attacks, having massive destructive consequences. Security metrics are therefore essential to assess their security posture. In this paper, we present a novel ICS security metric based on AND/OR graphs that represent cyber-physical dependencies among network components. Our metric is able to efficiently identify sets of critical cyber-physical components, with minimal cost for an attacker, such that if compromised, the system would enter into a non-operational state. We address this problem by efficiently transforming the input AND/OR graph-based model into a weighted logical formula that is then used to build and solve a Weighted Partial MAX-SAT problem. Our tool, META4ICS, leverages state-of-the-art techniques from the field of logical satisfiability optimisation in order to achieve efficient computation times. Our experimental results indicate that the proposed security metric can efficiently scale to networks with thousands of nodes and be computed in seconds. In addition, we present a case study where we have used our system to analyse the security posture of a realistic water transport network. We discuss our findings on the plant as well as further security applications of our metric.
Issue Date: 12-May-2019
URI: http://hdl.handle.net/10044/1/73782
Publisher: arxiv
Copyright Statement: © 2019 The Authors.
Sponsor/Funder: Horizon2020
Funder's Grant Number: Project ID: 739551
Keywords: cs.CR
cs.CR
cs.NI
cs.SY
cs.CR
cs.CR
cs.NI
cs.SY
Notes: Keywords: Security metrics, industrial control systems, cyber-physical systems, AND-OR graphs, MAX-SAT resolution
Publication Status: Published
Appears in Collections:Computing
Faculty of Engineering