Synergistic Security for the Industrial Internet of Things: Integrating Redundancy, Diversity, and Hardening

08/28/2018
by   Aron Laszka, et al.
0

As the Industrial Internet of Things (IIot) becomes more prevalent in critical application domains, ensuring security and resilience in the face of cyber-attacks is becoming an issue of paramount importance. Cyber-attacks against critical infrastructures, for example, against smart water-distribution and transportation systems, pose serious threats to public health and safety. Owing to the severity of these threats, a variety of security techniques are available. However, no single technique can address the whole spectrum of cyber-attacks that may be launched by a determined and resourceful attacker. In light of this, we consider a multi-pronged approach for designing secure and resilient IIoT systems, which integrates redundancy, diversity, and hardening techniques. We introduce a framework for quantifying cyber-security risks and optimizing IIoT design by determining security investments in redundancy, diversity, and hardening. To demonstrate the applicability of our framework, we present two case studies in water distribution and transportation a case study in water-distribution systems. Our numerical evaluation shows that integrating redundancy, diversity, and hardening can lead to reduced security risk at the same cost.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/25/2020

A Review of Cybersecurity Incidents in the Water Sector

This study presents a critical review of disclosed, documented, and mali...
research
08/26/2019

Airport Cyber Security and Cyber Resilience Controls

Cyber Security scares are the main areas of demerits associated with the...
research
11/21/2019

Assessing Cyber-Physical Security in Industrial Control Systems

Over the last years, Industrial Control Systems (ICS) have become increa...
research
08/06/2021

When Googling it doesn't work: The challenge of finding security advice for smart home devices

As users increasingly introduce Internet-connected devices into their ho...
research
06/19/2022

Cybersecurity Law: Legal Jurisdiction and Authority

Cybersecurity threats affect all aspects of society; critical infrastruc...
research
12/15/2021

IoT Security and Safety Testing Toolkits for Water Distribution Systems

Due to the critical importance of Industrial Control Systems (ICS) to th...
research
01/09/2019

Risk analysis beyond vulnerability and resilience - characterizing the defensibility of critical systems

A common problem in risk analysis is to characterize the overall securit...

Please sign up or login with your details

Forgot password? Click here to reset