首页> 外文期刊>Energy Informatics >powerLang: a probabilistic attack simulation language for the power domain
【24h】

powerLang: a probabilistic attack simulation language for the power domain

机译:Powerlang:电源域的概率攻击模拟语言

获取原文
           

摘要

Cyber-attacks on power-related IT and OT infrastructures can have disastrous consequences for individuals, regions, as well as whole nations. In order to respond to these threats, the cyber security assessment of IT and OT infrastructures can foster a higher degree of safety and resilience against cyber-attacks. Therefore, the use of attack simulations based on system architecture models is proposed. To reduce the effort of creating new attack graphs for each system under assessment, domain-specific languages (DSLs) can be employed. DSLs codify the common attack logics of the considered domain. Previously, MAL (the Meta Attack Language) was proposed, which serves as a framework to develop DSLs and generate attack graphs for modeled infrastructures. In this article, powerLang as a MAL-based DSL for modeling IT and OT infrastructures in the power domain is proposed. Further, it allows analyzing weaknesses related to known attacks. To comprise powerLang, two existing MAL-based DSL are combined with a new language focusing on industrial control systems (ICS). Finally, this first version of the language was validated against a known cyber-attack.
机译:对电力相关的网络攻击和OT基础设施可能对个人,地区以及整个国家的灾难性后果具有灾难性的后果。为了应对这些威胁,网络安全评估和OT基础设施可以促进更高程度的安全性和抵御网络攻击的恢复力。因此,提出了基于系统架构模型的攻击模拟的使用。为了减少在评估下为每个系统创建新的攻击图的努力,可以使用域的特定语言(DSL)。 DSLS编码COMPED域的常见攻击逻辑。以前,提出了MAL(META攻击语言),它用作开发DSL的框架并为建模基础架构生成攻击图。在本文中,提出了PowerLang作为用于建模的MAL的DSL和电源域中的OT基础设施。此外,它允许分析与已知攻击有关的弱点。为了构成Powerlang,两种现有的基于MAL的DSL与专注于工业控制系统(ICS)的新语言相结合。最后,这种语言的第一个版本是针对已知网络攻击的验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号