Incidents Are Meant for Learning, Not Repeating: Sharing Knowledge About Security Incidents in Cyber-Physical Systems

06/29/2019
by   Faeq Alrimawi, et al.
0

Cyber-physical systems (CPSs) are part of most critical infrastructures such as industrial automation and transportation systems. Thus, security incidents targeting CPSs can have disruptive consequences to assets and people. As prior incidents tend to re-occur, sharing knowledge about these incidents can help organizations be more prepared to prevent, mitigate or investigate future incidents. This paper proposes a novel approach to enable representation and sharing of knowledge about CPS incidents across different organizations. To support sharing, we represent incident knowledge (incident patterns) capturing incident characteristics that can manifest again, such as incident activities or vulnerabilities exploited by offenders. Incident patterns are a more abstract representation of specific incident instances and, thus, are general enough to be applicable to various systems - different than the one in which the incident occurred. They can also avoid disclosing potentially sensitive information about an organization's assets and resources. We provide an automated technique to extract an incident pattern from a specific incident instance. To understand how an incident pattern can manifest again in other cyber-physical systems, we also provide an automated technique to instantiate incident patterns to specific systems. We demonstrate the feasibility of our approach in the application domain of smart buildings. We evaluate correctness, scalability, and performance using two substantive scenarios inspired by real-world systems and incidents.

READ FULL TEXT
research
11/17/2019

Guiding the Self-organization of Cyber-Physical Systems

Self-organization offers a promising approach for designing adaptive sys...
research
06/16/2021

A Revised Taxonomy of Steganography Embedding Patterns

Steganography embraces several hiding techniques which spawn across mult...
research
10/14/2022

Let's Talk Through Physics! Covert Cyber-Physical Data Exfiltration on Air-Gapped Edge Devices

Although organizations are continuously making concerted efforts to hard...
research
04/02/2021

Bayesian Structural Learning for an Improved Diagnosis of Cyber-Physical Systems

The diagnosis of cyber-physical systems (CPS) is based on a representati...
research
05/08/2015

How Resilient Are Our Societies? Analyses, Models, and Preliminary Results

Traditional social organizations such as those for the management of hea...
research
08/01/2023

CONSTRUCT: A Program Synthesis Approach for Reconstructing Control Algorithms from Embedded System Binaries in Cyber-Physical Systems

We introduce a novel approach to automatically synthesize a mathematical...
research
06/15/2018

IPSME- Idempotent Publish/Subscribe Messaging Environment

The integration of disparate systems is required in the domain of Cyber ...

Please sign up or login with your details

Forgot password? Click here to reset