A Formal Approach to Physics-Based Attacks in Cyber-Physical Systems (Extended Version)

02/12/2019
by   Ruggero Lanotte, et al.
0

We apply formal methods to lay and streamline theoretical foundations to reason about Cyber-Physical Systems (CPSs) and physics-based attacks, i.e., attacks targeting physical devices. We focus on a formal treatment of both integrity and denial of service attacks to sensors and actuators of CPSs, and on the timing aspects of these attacks. Our contributions are fourfold. (1) We define a hybrid process calculus to model both CPSs and physics-based attacks. (2) We formalise a threat model that specifies MITM attacks that can manipulate sensor readings or control commands in order to drive a CPS into an undesired state, and we provide the means to assess attack tolerance/vulnerability with respect to a given attack. (3) We formalise how to estimate the impact of a successful attack on a CPS and investigate possible quantifications of the success chances of an attack. (4) We illustrate our definitions and results by formalising a non-trivial running example in Uppaal SMC, the statistical extension of the Uppaal model checker; we use Uppaal SMC as an automatic tool for carrying out a static security analysis of our running example in isolation and when exposed to three different physics-based attacks with different impacts.

READ FULL TEXT
research
06/27/2018

Towards a formal notion of impact metric for cyber-physical attacks (full version)

Industrial facilities and critical infrastructures are transforming into...
research
03/22/2019

Limitations on Observability of Effects in Cyber-Physical Systems

Increased interconnectivity of Cyber-Physical Systems, by design or othe...
research
01/22/2018

SecSens: Secure State Estimation with Application to Localization and Time Synchronization

Research evidence in Cyber-Physical Systems (CPS) shows that the introdu...
research
02/26/2021

Yoneda Hacking: The Algebra of Attacker Actions

Our work focuses on modeling security of systems from their component-le...
research
11/08/2018

Integrating Security in Resource-Constrained Cyber-Physical Systems

Defense mechanisms against network-level attacks are commonly based on t...
research
05/28/2021

The Unpatchable Silicon: A Full Break of the Bitstream Encryption of Xilinx 7-Series FPGAs

The security of FPGAs is a crucial topic, as any vulnerability within th...
research
11/28/2019

Modelling Load-Changing Attacks in Cyber-Physical Systems

Cyber-Physical Systems (CPS) are present in many settings addressing a m...

Please sign up or login with your details

Forgot password? Click here to reset