University of Limerick
Browse
Nuseibeh_2018_Seen.pdf (2.76 MB)

I’ve seen this before: sharing cyber-physical incident knowledge

Download (2.76 MB)
conference contribution
posted on 2018-12-18, 16:26 authored by Faeq Alrimawi, Liliana Pasquale, Deepak Mehta, Bashar NuseibehBashar Nuseibeh
An increasing number of security incidents in cyber-physical systems (CPSs) arise from the exploitation of cyber and physical components of such systems. Knowledge about how such incidents arose is rarely captured and used systematically to enhance security and support future incident investigations. In this paper, we propose an approach to represent and share incidents knowledge. Our approach captures incident patterns – common aspects of incidents occurring in different CPSs. Our approach then allows incident patterns to be instantiated for different systems to assess if and how such patterns can manifest again. To support our approach, we provide two meta-models that represent, respectively, incident patterns and the cyber-physical systems themselves. The incident meta-model captures the characteristics of incidents, such as assets and activities. The system meta-model captures cyber and physical components and their interactions, which may be exploited during an incident. We demonstrate the feasibility of our approach in the application domain of smart buildings, by tailoring the system meta-model to represent components and interactions in this domain.

Funding

Study on Aerodynamic Characteristics Control of Slender Body Using Active Flow Control Technique

Japan Society for the Promotion of Science

Find out more...

History

Publication

SEAD '18 Proceedings of the 1st International Workshop on Security Awareness from Design to Deployment;pp. 33-40

Publisher

Association for Computing Machinery

Note

peer-reviewed

Other Funding information

ERC

Rights

© ACM, 2018. This is the author's version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in SEAD '18 Proceedings of the 1st International Workshop on Security Awareness from Design to Deployment, pp. 33-40,

Language

English

Usage metrics

    University of Limerick

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC