论文标题
用于评估网络物理系统安全的攻击者建模框架
An Attacker Modeling Framework for the Assessment of Cyber-Physical Systems Security
论文作者
论文摘要
表征攻击者在网络物理系统方面的行为对于确保这些系统的安全姿势和弹性很重要。经典的网络脆弱性评估方法取决于网络安全专家的知识和经验来进行安全分析,并且在缺乏专家的知识和经验的情况下可能不一致。本文提出了一个灵活的攻击者建模框架,该框架通过模拟各种攻击者行为来预测攻击进展并提供一致的系统脆弱性分析,从而有助于安全分析过程。该模型提出了扩展的漏洞数据库体系结构,以最大程度地提高其在检测CPS漏洞的同时与现有漏洞数据库兼容的效果和一致性。该模型具有针对实际或虚拟CP的实现和模拟的能力。针对模拟的工业控制系统架构证明了攻击者模型的执行,从而对攻击者行为进行了概率预测。
Characterizing attacker behavior with respect to Cyber-Physical Systems is important to assuring the security posture and resilience of these systems. Classical cyber vulnerability assessment approaches rely on the knowledge and experience of cyber-security experts to conduct security analyses and can be inconsistent where the experts' knowledge and experience are lacking. This paper proposes a flexible attacker modeling framework that aids in the security analysis process by simulating a diverse set of attacker behaviors to predict attack progression and provide consistent system vulnerability analysis. The model proposes an expanded architecture of vulnerability databases to maximize its effectiveness and consistency in detecting CPS vulnerabilities while being compatible with existing vulnerability databases. The model has the power to be implemented and simulated against an actual or virtual CPS. Execution of the attacker model is demonstrated against a simulated industrial control system architecture, resulting in a probabilistic prediction of attacker behavior.