首页> 外文会议>International Conference on Security for Information Technology and Communications >Formal Security Analysis of Cloud-Connected Industrial Control Systems
【24h】

Formal Security Analysis of Cloud-Connected Industrial Control Systems

机译:云连接工业控制系统的正式安全分析

获取原文

摘要

Industrial control systems are changing from isolated to remotely accessible cloud-connected architectures. Despite their advantages, these architectures introduce extra complexity, which makes it more difficult to ensure the security of these systems prior to deployment. One way to address this is by using formal methods to reason about the security properties of these systems during the early stages of development. Specifically, by analyzing security attacks and verifying that the corresponding mitigation strategies work as intended. In this paper, we present a formal framework for security analysis of cloud-connected industrial control systems. We consider several well-known attack scenarios and formally verify mitigation strategies for each of them. Our framework is mechanized using TLA+ in order to enable formal verification of security properties. Finally we demonstrate the applicability of our work using an industrial case study.
机译:工业控制系统从孤立到远程访问云连接的架构改变。尽管他们的优势,这些架构介绍了额外的复杂性,这使得能够在部署之前确保这些系统的安全性更加困难。解决此方法的一种方法是通过使用正式的方法来推理这些系统的安全性质在开发的早期阶段。具体而言,通过分析安全攻击并验证相应的缓解策略按预期工作。在本文中,我们为云连接的工业控制系统提供了一个正式的安全分析框架。我们考虑了几种众所周知的攻击情景,并正式验证每个人的缓解策略。我们的框架是使用TLA +机械化的,以便能够正式验证安全性质。最后,我们展示了我们使用工业案例研究的工作的适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号