透過您的圖書館登入
IP:3.149.237.146
  • 會議論文
  • OpenAccess

資訊物理系統資安弱點分析

Vulnerability Analysis for cyber physical systems

摘要


資訊物理系統(cyber physical system, CPS)所控制的物理程序若遭受惡意攻擊,可能危害人的生命或汙染環境,故其設計階段的弱點分析極為重要。要破壞CPS物理程序,不僅需要資訊技術(Information Technology, IT)的知識,更需要有系統操作技術(Operation Technology, OT)的領域知識。現行資通安全研究較少討論OT層次的攻擊,本文則著重於OT部分的弱點分析;我們發展了一有系統的方法,可產生OT階段惡意攻擊劇情序列,並建立以斷言(assertions)為主的動態攻擊偵測機制。我們透過案例顯示所提方法之可行性、有效性,並陳述實驗所得之洞見。

並列摘要


If the physical processes controlled by the cyber physical system (CPS) are under malicious attacks, the consequences may endanger human life or pollute environment. Thus, vulnerability analysis at the design stage is crucial. In order to sabotage physical processes, the attacker needs not only IT (Informational Technology) part knowledge, but also the OT (Operational Technology) part knowledge. Most current cybersecurity research emphasizes IT part attacks. Nevertheless, this work focuses on vulnerability analysis of the OT part. We develop a systematical method to generate malicious attack scenarios along with corresponding run-time detection mechanism using assertions. We demonstrate the feasibility and effectiveness of the proposed method by a case study. We also present insights obtained from our experiments.

延伸閱讀