论文标题

网络LOPA:一种用于设计可靠和安全的网络物理系统的综合方法

Cyber LOPA: An Integrated Approach for the Design of Dependable and Secure Cyber Physical Systems

论文作者

Tantawy, Ashraf, Abdelwahed, Sherif, Erradi, Abdelkarim

论文摘要

安全风险评估是确保可靠的网络物理系统(CPS)设计的重要过程。传统风险评估仅考虑身体失败。对于现代CP,由网络攻击引起的失败正在上升。最新研究工作的重点是安全 - 安全生命周期的整合以及建模形式主义以进行风险评估以纳入安全故障。安全性和安全生命周期之间的相互作用及其对整个系统设计的影响以及忽略安全故障造成的可靠性损失是一些被忽视的研究问题。本文通过提出一种名为网络保护分析(Clopa)的新安全设计方法来解决这些研究问题,该方法将现有的LOPA框架扩展到包括由网络攻击引起的故障。所提出的方法提供了一种严格的数学公式,该公式在设计高度可靠性的CPS与高度安全的CP之间进行了定量的折衷。我们进一步提出了一个共同设计的生命周期流程,以整合安全和保障风险评估流程。我们在对由工业控制测试台控制的过程反应器进行的实际案例研究中评估了提出的clopa方法和综合生命周期,并提供了拟议中的clopa和当前LOPA风险评估实践之间的比较。

Safety risk assessment is an essential process to ensure a dependable Cyber-Physical System (CPS) design. Traditional risk assessment considers only physical failures. For modern CPS, failures caused by cyber attacks are on the rise. The focus of latest research effort is on safety-security lifecycle integration and the expansion of modeling formalisms for risk assessment to incorporate security failures. The interaction between safety and security lifecycles and its impact on the overall system design, as well as the reliability loss resulting from ignoring security failures are some of the overlooked research questions. This paper addresses these research questions by presenting a new safety design method named Cyber Layer Of Protection Analysis (CLOPA) that extends existing LOPA framework to include failures caused by cyber attacks. The proposed method provides a rigorous mathematical formulation that expresses quantitatively the trade-off between designing a highly-reliable versus a highly-secure CPS. We further propose a co-design lifecycle process that integrates the safety and security risk assessment processes. We evaluate the proposed CLOPA approach and the integrated lifecycle on a practical case study of a process reactor controlled by an industrial control testbed, and provide a comparison between the proposed CLOPA and current LOPA risk assessment practice.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源