• DocumentCode
    561143
  • Title

    Defense as a service cloud for Cyber-Physical Systems

  • Author

    Azab, Mohamed ; Eltoweissy, Mohamed

  • Author_Institution
    Bradley Dept. of Electr. & Comput. Eng, Virginia Tech, Blacksburg, VA, USA
  • fYear
    2011
  • fDate
    15-18 Oct. 2011
  • Firstpage
    392
  • Lastpage
    401
  • Abstract
    Modernizing our critical infrastructure often involves upgrades with Cyber-Physical Systems (CPS) to enhance efficiency, safety and reliability. New security and resilience requirements and challenges arise given the mission- and time-critical nature of CPS applications. These applications are always targeted by sophisticated persistent attacks exploiting potential cyber-physical integration vulnerabilities. In this paper, we present CyPhyCARD (Cooperative Autonomous Resilient Defense “CARD” platform for Cyber Physical Systems) as a resilient and secure defense cloud. The foundation of CyPhyCARD is our Cell-Oriented Architecture (COA) that enables distributed, dynamically configurable, and runtime-programmable platforms. COA comprises composable intrinsically resilient, active components termed “Cells” that dynamically manage heterogeneous resources and executable software code variants to execute CyPhyCARD defense missions. CyPhyCARD uses our generic Evolutionary Sensory system (EvoSense) to circulate context-driven, functionally customizable sensors and effectors through the target of defense. EvoSense provides cooperative autonomous control and sharing amongst interconnected defense service providers (CyPhyCARD) and/or their target of defense to enhance attack detection and deterrence. Further, CyPhyCARD uses our ChameleonSoft system to secure its infrastructure of cells. ChameleonSoft is a multidimensional software diversity system that autonomously induces runtime confusion and diffusion thereby, in effect, encrypting the spatiotemporal software behavior and realizing a moving target defense. Both EvoSense and ChameleonSoft are built using the COA. CyPhyCARD is designed to increase the cost for the attacker at all times through persistently asymmetric operations achieved, in part, using a moving target defense construction and automated recovery provided by ChameleonSoft; rabid global attack detection and mitigation through EvoS- nse; and Operation resilience in presence of attacks using attack containment and honeypots defense missions. We demonstrate, using an attack scenario, how our proposed solution reacts to threats targeting CyPhyCARD and/or its target of defense systems.
  • Keywords
    cloud computing; evolutionary computation; security of data; COA; CPS; ChameleonSoft; CyPhyCARD; EvoSense; attack containment; cell oriented architecture; cloud service; cooperative autonomous resilient defense; critical infrastructure; cyber physical systems; cyber-physical integration; evolutionary sensory system; operation resilience; resilience requirements; software code; software diversity system; spatiotemporal software behavior; Organisms; Reliability; Runtime; Autonomic Management; Cloud Computing; Cyber Physical Systems; Resilience; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2011 7th International Conference on
  • Conference_Location
    Orlando, FL
  • Print_ISBN
    978-1-4673-0683-6
  • Electronic_ISBN
    978-1-936968-32-9
  • Type

    conf

  • Filename
    6144825