• DocumentCode
    1778162
  • Title

    A method for modeling and evaluation of the security of cyber-physical systems

  • Author

    Orojloo, Hamed ; Azgomi, Mohammad Abdollahi

  • Author_Institution
    Trustworthy Comput. Lab., Iran Univ. of Sci. & Technol., Tehran, Iran
  • fYear
    2014
  • fDate
    3-4 Sept. 2014
  • Firstpage
    131
  • Lastpage
    136
  • Abstract
    Quantitative evaluation of security has always been one of the challenges in the field of computer security. The integration of computing and communication technologies with physical components, has introduced a variety of new security risks, which threaten cyber-physical components. It is possible that an attacker damage a physical component with cyber attack. In this paper, we propose a new approach for modeling and quantitative evaluation of the security of cyber-physical systems (CPS). The proposed method, considers those cyber attacks that can lead to physical damages. The factors impacting attacker´s decision-making in the process of cyber attack to cyber-physical system are also taken into account. Furthermore, for describing the attacker and the system behaviors over time, the uniform probability distributions are used in a state-based semi-Markov chain (SMC) model. The security analysis is carried out for mean time to security failure (MTTSF), steady-state security, and steady-state physical availability.
  • Keywords
    Markov processes; decision making; security of data; statistical distributions; CPS security; MTTSF; communication technology integration; computer security; computing technology integration; cyber attack; cyber-physical components; cyber-physical system security; decision-making; mean time-to-security failure; quantitative evaluation; security analysis; security risks; state-based SMC model; state-based semi-Markov chain model; steady-state physical availability; steady-state security; uniform probability distributions; Analytical models; Availability; Computational modeling; Mathematical model; Random variables; Security; Steady-state; Cyber-physical systems; physical damage; quantitative ssecurity evaluation; security modelling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security and Cryptology (ISCISC), 2014 11th International ISC Conference on
  • Conference_Location
    Tehran
  • Type

    conf

  • DOI
    10.1109/ISCISC.2014.6994036
  • Filename
    6994036