首页> 外文会议>Software quality days conferenceSWQD >Security Challenges in Cyber-Physical Production Systems
【24h】

Security Challenges in Cyber-Physical Production Systems

机译:网络物理生产系统中的安全挑战

获取原文

摘要

Within the last decade, Security became a major focus in the traditional IT-Industry, mainly through the interconnection of systems and especially through the connection to the Internet. This opened up a huge new attack surface, which resulted in major takedowns of legitimate services and new forms of crime and destruction. This led to the development of a multitude of new defense mechanisms and strategies, as well as the establishing of Security procedures on both, organizational and technical level. Production systems have mostly remained in isolation during these past years, with security typically focused on the perimeter. Now, with the introduction of new paradigms like Industry 4.0, this isolation is questioned heavily with Physical Production Systems (PPSs) now connected to an IT-world resulting in cyber-physical systems sharing the attack surface of traditional web based interfaces while featuring completely different goals, parameters like lifetime and safety, as well as construction. In this work, we present an outline on the major security challenges faced by cyber-physical production systems. While many of these challenges harken back to issues also present in traditional web based IT, we will thoroughly analyze the differences. Still, many new attack vectors appeared in the past, either in practical attacks like Stuxnet, or in theoretical work. These attack vectors use specific features or design elements of cyber-physical systems to their advantage and are unparalleled in traditional IT. Furthermore, many mitigation strategies prevalent in traditional IT systems are not applicable in the industrial world, e.g., patching, thus rendering traditional strategies in IT-Security unfeasible. A thorough discussion of the major challenges in CPPS-Security is thus required in order to focus research on the most important targets.
机译:在过去十年中,安全成为传统IT-行业的重点,主要是通过系统互连,特别是通过与互联网的连接。这开辟了一个巨大的新攻击面,导致了合法服务和新形式的犯罪​​和破坏的主要诱因。这导致开发了多种新的防御机制和策略,以及建立了组织和技术水平的安全程序。在这些过去几年中,生产系统在这些过去几年中仍然存在,安全性通常集中在周边上。现在,随着行业4.0这样的新范式的引入,这种隔离与物理生产系统(PPS)大量质疑,现在与IT世界相连,导致网络物理系统共享传统基于Web的接口的攻击面,同时具有完全不同的界面目标,像寿命和安全等参数,以及建筑。在这项工作中,我们概述了网络 - 物理生产系统面临的主要安全挑战。虽然许多这些挑战在其基础上恢复了传统网站中的问题,但我们将彻底分析差异。尽管如此,过去仍然出现了许多新的攻击向量,无论是在实际攻击中,如Stuxnet,还是在理论工作中。这些攻击向量使用网络物理系统的特定功能或设计元素至其优势,并且在传统的方面是无与伦比的。此外,传统IT系统中普遍存在的许多缓解策略不适用于工业世界,例如,修补,从而在IT安全方面取出传统策略不可行。因此,需要彻底讨论CPPS安全中的主要挑战,以便对最重要的目标进行研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号