首页> 外文会议>International Conference on Critical Information Infrastructures Security >Towards Computer-Aided Security Life Cycle Management for Critical Industrial Control Systems
【24h】

Towards Computer-Aided Security Life Cycle Management for Critical Industrial Control Systems

机译:对关键工业控制系统的计算机辅助安全生命周期管理

获取原文

摘要

Critical infrastructure experienced a transformation from isolated towards highly (inter-)connected systems. This development introduced a variety of new cyber threats, causing high financial damage, threatening lives and affecting the society. Known examples are Stuxnet, WannaCry and the attacks on the Ukrainian power grid. To prevent such attacks, it is indispensable to properly design, assess and maintain countermeasures and security strategies throughout the whole life cycle of the critical systems. For this, security has to be considered and assessed for every system design and redesign. However, common assessment tools and methodologies are not executed on a detailed system knowledge and therefore they are enhanced with penetration tests. Unfortunately, performing only abstract assessments is inadequate and penetration tests endanger the availability of the tested systems. Therefore, the latter cannot be performed on live systems executing critical processes. In this paper, we address these issues for Industrial Control Systems and explain how new concepts for continuous security-by-design or model-based system monitoring and automated vulnerability assessments can resolve them by exploiting new Industry 4.0 developments.
机译:关键基础设施经历了从隔离(间)连接系统的转换。这一发展介绍了各种新的网络威胁,造成了高的财务损害,威胁生活和影响社会。已知的例子是Stuxnet,Wannacry和对乌克兰电网的攻击。为防止此类攻击,在关键系统的整个生命周期中正确设计,评估和维持对策和安全策略是必不可少的。为此,必须对每个系统设计和重新设计进行考虑和评估安全性。但是,常见的评估工具和方法没有在详细的系统知识上执行,因此它们的渗透测试增强。不幸的是,只表演抽象评估是不充分的,渗透测试危及测试系统的可用性。因此,后者不能对执行关键过程的实时系统执行。在本文中,我们解决了工业控制系统的这些问题,并解释了持续的逐个设计或基于模型的系统监控和自动漏洞评估的新概念可以通过利用新的行业4.0开发来解决这些问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号