학술논문

Determining Tolerable Attack Surfaces that Preserves Safety of Cyber-Physical Systems
Document Type
Conference
Source
2018 IEEE 23rd Pacific Rim International Symposium on Dependable Computing (PRDC) PRDC Dependable Computing (PRDC), 2018 IEEE 23rd Pacific Rim International Symposium on. :125-134 Dec, 2018
Subject
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Computing and Processing
Safety
Rail transportation
Servers
Automata
Security
Communication system signaling
Tracking
cyber-physical system, safety analysis, formal verification, attacker model, timed automata
Language
ISSN
2473-3105
Abstract
As safety-critical systems become increasingly interconnected, a system's operations depend on the reliability and security of the computing components and the interconnections among them. Therefore, a growing body of research seeks to tie safety analysis to security analysis. Specifically, it is important to analyze system safety under different attacker models. In this paper, we develop generic parameterizable state automaton templates to model the effects of an attack. Then, given an attacker model, we generate a state automaton that represents the system operation under the threat of the attacker model. We use a railway signaling system as our case study and consider threats to the communication protocol and the commands issued to physical devices. Our results show that while less skilled attackers are not able to violate system safety, more dedicated and skilled attackers can affect system safety. We also consider several countermeasures and show how well they can deter attacks.