A new safety and security risk analysis framework for industrial control systems

被引:12
|
作者
Kriaa, Siwar [1 ,2 ]
Bouissou, Marc [1 ]
Laarouchi, Youssef [1 ]
机构
[1] EDF, 7 Blvd Gaspard Monge, F-91120 Palaiseau, France
[2] CentraleSupelec, Chatenay Malabry, France
关键词
Industrial control system; safety; security; modeling; risk assessment; cyber-physical system; COMPROMISE; MODEL;
D O I
10.1177/1748006X18765885
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The migration of modern industrial control systems toward information and communication technologies exposes them to cyber-attacks that can alter the way they function, thereby causing adverse consequences on the system and its environment. It has consequently become crucial to consider security risks in traditional safety risk analyses for industrial systems controlled by modern industrial control system. We propose in this article a new framework for safety and security joint risk analysis for industrial control systems. S-cube (for supervisory control and data acquisition safety and security joint modeling) is a new model-based approach that enables, thanks to a knowledge base, formal modeling of the physical and functional architecture of cyber-physical systems and automatic generation of a qualitative and quantitative analysis encompassing safety risks (accidental) and security risks (malicious). We first give the principle and rationale of S-cube and then we illustrate its inputs and outputs on a case study.
引用
收藏
页码:151 / 174
页数:24
相关论文
共 50 条
  • [21] Safety of railway control systems: a new preliminary risk analysis approach
    Guenab, F.
    Boulanger, J-L.
    Schoen, W.
    SAFETY AND SECURITY ENGINEERING III, 2009, 108 : 627 - 636
  • [22] Safety of railway control systems: A new preliminary risk analysis approach
    Guenab, F.
    Boulanger, J.-L.
    Schön, W.
    International Journal of Safety and Security Engineering, 2013, 3 (01) : 59 - 68
  • [23] Safety of railway control systems: A new Preliminary Risk Analysis approach
    Guenab, F.
    Boulanger, J. L.
    Schoen, W.
    IEEM: 2008 INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT, VOLS 1-3, 2008, : 1309 - 1313
  • [24] Towards a Modular Security Testing Framework for Industrial Automation and Control Systems: ISuTest
    Pfrang, Steffen
    Meier, David
    Kautz, Valentin
    2017 22ND IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2017,
  • [25] Co-engineering Safety and Security in Industrial Control Systems: A Formal Outlook
    Vistbakka, Inna
    Troubitsyna, Elena
    Kuismin, Tuomas
    Latvala, Timo
    SOFTWARE ENGINEERING FOR RESILIENT SYSTEMS, SERENE 2017, 2017, 10479 : 96 - 114
  • [26] A unified framework for risk and vulnerability analysis covering both safety and security
    Aven, Terje
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2007, 92 (06) : 745 - 754
  • [27] A unified framework for risk and vulnerability analysis covering both safety and security
    Aven T.
    IEEE Engineering Management Review, 2011, 39 (04): : 123 - 134
  • [28] Industrial Control System Security Framework for Ethiopia
    Berhe, Abraham Belay
    Tizazu, Gebere Akele
    Kim, Ki-Hyung
    2017 NINTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2017), 2017, : 814 - 817
  • [29] Safety, reliability and security of industrial computer systems
    Anderson, S
    Felici, M
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2005, 89 (01) : 1 - 5
  • [30] Safety, reliability and security of industrial computer systems
    Anderson, S
    Felici, M
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2003, 81 (03) : 235 - 238