A Comprehensive and Open Framework for Classifying Incidents Involving Cyber-Physical Systems

نویسندگان

  • William B. Miller
  • Dale C. Rowe
چکیده

In recent years, events such as the Stuxnet nuclear plant cyber-attack have brought the security of industrial control systems under scrutiny. Most of this focus has been on supervisory control and data acquisition (SCADA) systems (more generically known as ICS or industrial control systems). While these systems play a major role in our daily lives, this focus tends to overlook the broader scope of cyber-physical systems (CPS) and the impact they have on human lives (e.g., vehicles, mobile devices, agriculture). There are currently no open databases to record and classify CPS incidents that include systems outside of ICS. While it may be possible to adapt existing databases, we have found that those suitable for adaptation have multiple drawbacks, including proprietary ownership, requirement of a paid subscription and/or limited access, and design scope. In this paper, we propose an open standards framework for classifying a wide variety of CPS incidents. As part of this framework, we introduce a new taxonomy that facilitates the rapid categorization of such incidents by a variety of criteria. An important new parameter of this taxonomy is a hierarchy of market sector classifications, allowing incidents to be evaluated in their application of context. Other factors of the taxonomy include source profile, impact (both direct and indirect), method, and a comprehensive victim profile. We compare our framework to other existing approaches by classifying several incidents occurring over the last twenty years and demonstrate the wide capabilities of our method by including incidents outside of industrial control systems. We further note that the flexibility of the framework caters for multiple CPU types and provides a context rich description of incidents. Finally, we note that the system allows multiple classifications so an incident can be identified in multiple relevant contexts.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Toward Representing and Recognizing Cyber-Physical Autonomous Agents in Competition Using Event Semantics

The Federal Aviation Administration (FAA) is observing an increasing number of incidents involving recreational drones, and imagining a future where every drone will be equipped with an Automatic Dependent Surveillance-Broadcast (ADS-B) transponder that communicates and cooperates with the FAA’s Next Generation (NextGen) Aviation Cyber-Physical System in order to help mitigate aerial collision ...

متن کامل

Toward Representing and Recognizing Cyber-Physical Elements in Competition Using Event Semantics

The Federal Aviation Administration (FAA) is observing an increasing number of incidents involving recreational drones, and imagining a future where every drone will be equipped with an Automatic Dependent Surveillance-Broadcast (ADS-B) transponder that communicates and cooperates with the FAA’s Next Generation (NextGen) Aviation Cyber-Physical System in order to help mitigate aerial collision ...

متن کامل

A Case for Open Network Health Systems: Systems as Networks in Public Mental Health

Increases in incidents involving so-called confused persons have brought attention to the potential costs of recent changes to public mental health (PMH) services in the Netherlands. Decentralized under the (Community) Participation Act (2014), local governments must find resources to compensate for reduced central funding to such services or “innovate.” But innovation, even when pressure for c...

متن کامل

Assuring Industrial Control System (ICS) Cyber Security

Industrial Control Systems (ICS) are an integral part of the industrial infrastructure providing for the national good. These systems include Distributed Control Systems (DCS) Supervisory Control and Data Acquisition systems (SCADA), Programmable Logic Controllers (PLC), and devices such as remote telemetry units (RTU), smart meters, and intelligent field instruments including remotely programm...

متن کامل

Formal Specification and Analysis of Robust Adaptive Distributed Cyber-Physical Systems

We are interested in systems of cyber-physical agents that operate in unpredictable, possibly hostile, environments using locally obtainable information. How can we specify robust agents that are able to operate alone and/or in cooperation with other agents? What properties are important? How can they be verified? In this tutorial we describe a framework called Soft Agents, formalized in the Ma...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014