Architecture-based attack propagation and variation analysis for identifying confidentiality issues in Industry 4.0

IF 0.7 4区 计算机科学 Q4 AUTOMATION & CONTROL SYSTEMS At-Automatisierungstechnik Pub Date : 2023-06-01 DOI:10.1515/auto-2022-0135
Maximilian Walter, Sebastian Hahner, T. Bures, P. Hnetynka, R. Heinrich, R. Reussner
{"title":"Architecture-based attack propagation and variation analysis for identifying confidentiality issues in Industry 4.0","authors":"Maximilian Walter, Sebastian Hahner, T. Bures, P. Hnetynka, R. Heinrich, R. Reussner","doi":"10.1515/auto-2022-0135","DOIUrl":null,"url":null,"abstract":"Abstract Exchanging data between entities is an essential part of Industry 4.0. However, the data exchange should not affect the confidentiality. Therefore, data should only be shared with the intended entities. In exceptional scenarios, it is unclear whether data should be shared or not and what the impact of the access decision is. Runtime access control systems such as role-based access control often do not consider the impact on the overall confidentiality. Static design-time analyses often provide this information. We use architectural design-time analyses together with an uncertainty variation metamodel mitigating uncertainty to calculate impact properties of attack paths. Runtime access control approaches can then use this information to support the access control decision. We evaluated our approach on four case studies based on real-world examples and research cases.","PeriodicalId":55437,"journal":{"name":"At-Automatisierungstechnik","volume":"71 1","pages":"443 - 452"},"PeriodicalIF":0.7000,"publicationDate":"2023-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"At-Automatisierungstechnik","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.1515/auto-2022-0135","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"AUTOMATION & CONTROL SYSTEMS","Score":null,"Total":0}
引用次数: 2

Abstract

Abstract Exchanging data between entities is an essential part of Industry 4.0. However, the data exchange should not affect the confidentiality. Therefore, data should only be shared with the intended entities. In exceptional scenarios, it is unclear whether data should be shared or not and what the impact of the access decision is. Runtime access control systems such as role-based access control often do not consider the impact on the overall confidentiality. Static design-time analyses often provide this information. We use architectural design-time analyses together with an uncertainty variation metamodel mitigating uncertainty to calculate impact properties of attack paths. Runtime access control approaches can then use this information to support the access control decision. We evaluated our approach on four case studies based on real-world examples and research cases.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于体系结构的攻击传播和变异分析,用于识别工业4.0中的机密性问题
实体之间的数据交换是工业4.0的重要组成部分。但是,数据交换不应影响机密性。因此,数据应该只与预期的实体共享。在特殊情况下,不清楚是否应该共享数据以及访问决策的影响是什么。诸如基于角色的访问控制之类的运行时访问控制系统通常不会考虑对总体机密性的影响。静态设计时分析通常提供这些信息。我们使用架构设计时分析和不确定性变化元模型来计算攻击路径的影响特性。然后,运行时访问控制方法可以使用这些信息来支持访问控制决策。我们基于现实世界的例子和研究案例对我们的方法进行了四个案例研究。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
At-Automatisierungstechnik
At-Automatisierungstechnik 工程技术-自动化与控制系统
CiteScore
2.00
自引率
10.00%
发文量
99
审稿时长
6-12 weeks
期刊介绍: Automatisierungstechnik (AUTO) publishes articles covering the entire range of automation technology: development and application of methods, the operating principles, characteristics, and applications of tools and the interrelationships between automation technology and societal developments. The journal includes a tutorial series on "Theory for Users," and a forum for the exchange of viewpoints concerning past, present, and future developments. Automatisierungstechnik is the official organ of GMA (The VDI/VDE Society for Measurement and Automatic Control) and NAMUR (The Process-Industry Interest Group for Automation Technology). Topics control engineering digital measurement systems cybernetics robotics process automation / process engineering control design modelling information processing man-machine interfaces networked control systems complexity management machine learning ambient assisted living automated driving bio-analysis technology building automation factory automation / smart factories flexible manufacturing systems functional safety mechatronic systems.
期刊最新文献
Investigating the rendering capability of embedded devices for graphical-user-interfaces in mobile machines Methods, approaches, and applications in mobile machines Communication in collaborating construction equipment Aligning process quality and efficiency in agricultural soil tillage OPC UA client-server connection over an ISO 11783 vehicle network
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1