Employing Digital Twins for Security-by-Design System Testing

Marietheres Dietz, Leon Hageman, Constantin von Hornung, G. Pernul
{"title":"Employing Digital Twins for Security-by-Design System Testing","authors":"Marietheres Dietz, Leon Hageman, Constantin von Hornung, G. Pernul","doi":"10.1145/3510547.3517929","DOIUrl":null,"url":null,"abstract":"Ever since cyber attacks focused on industrial and critical infrastructure settings, the awareness of the security issues of these systems has increased. These industrial control systems (ICS) mainly focus on operation and availability -- instead of providing general security features. Moreover, the current Industry 4.0 movement aggravates this security gap by connecting the ICS to the enterprise network, which facilitates targeting these systems. Proper system testing can reveal the system's vulnerabilities and provide remedies. However, security measures are usually neglected or addressed after an emerging incident only, which results in high costs. To maximize the benefit of system testing, we argue that it should be carried out as early as possible, especially to render systems secure-by-design. In this work, we propose an approach for introducing security-by-design system testing by the application of a digital twin. A digital twin is able to represent a system virtually along its lifecycle. To enable security-by-design, the simulation capability of digital twin is harnessed to create a prospective environment of a planned system. This allows detecting vulnerabilities before they can emerge in the real-world and providing a adequate risk strategy. Our work shows how security-by-design system testing is anchored in the security applications along a system's lifecycle. Next to proposing a security-by-design system testing approach with digital twins, we implement a digital twin representing a pressure vessel, and demonstrate how to carry out each step of our proposed approach. During this proof-of-concept, we identify vulnerabilities and show how an attacker can compromise the system by manipulating values of the pressure vessel with the potential to cause over-pressure, which, in turn, can result in an explosion of the vessel.","PeriodicalId":316402,"journal":{"name":"Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-04-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3510547.3517929","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Ever since cyber attacks focused on industrial and critical infrastructure settings, the awareness of the security issues of these systems has increased. These industrial control systems (ICS) mainly focus on operation and availability -- instead of providing general security features. Moreover, the current Industry 4.0 movement aggravates this security gap by connecting the ICS to the enterprise network, which facilitates targeting these systems. Proper system testing can reveal the system's vulnerabilities and provide remedies. However, security measures are usually neglected or addressed after an emerging incident only, which results in high costs. To maximize the benefit of system testing, we argue that it should be carried out as early as possible, especially to render systems secure-by-design. In this work, we propose an approach for introducing security-by-design system testing by the application of a digital twin. A digital twin is able to represent a system virtually along its lifecycle. To enable security-by-design, the simulation capability of digital twin is harnessed to create a prospective environment of a planned system. This allows detecting vulnerabilities before they can emerge in the real-world and providing a adequate risk strategy. Our work shows how security-by-design system testing is anchored in the security applications along a system's lifecycle. Next to proposing a security-by-design system testing approach with digital twins, we implement a digital twin representing a pressure vessel, and demonstrate how to carry out each step of our proposed approach. During this proof-of-concept, we identify vulnerabilities and show how an attacker can compromise the system by manipulating values of the pressure vessel with the potential to cause over-pressure, which, in turn, can result in an explosion of the vessel.
采用数字孪生进行设计安全系统测试
自从网络攻击集中于工业和关键基础设施设置以来,人们对这些系统的安全问题的认识不断提高。这些工业控制系统(ICS)主要关注操作和可用性,而不是提供一般的安全功能。此外,当前的工业4.0运动通过将ICS连接到企业网络,从而加剧了这种安全差距,这有助于针对这些系统。适当的系统测试可以揭示系统的漏洞并提供补救措施。然而,安全措施通常被忽视或只在事件发生后才得到解决,这导致了高昂的成本。为了使系统测试的好处最大化,我们认为应该尽可能早地进行测试,特别是为了使系统在设计上是安全的。在这项工作中,我们提出了一种通过应用数字孪生来引入设计安全系统测试的方法。数字孪生能够在系统的整个生命周期中虚拟地表示系统。为了实现设计安全,利用数字孪生的仿真能力来创建计划系统的预期环境。这允许在漏洞在现实世界中出现之前检测漏洞,并提供适当的风险策略。我们的工作显示了设计安全性系统测试是如何在系统生命周期中的安全性应用程序中进行锚定的。接下来,我们提出了一种使用数字双胞胎的设计安全系统测试方法,我们实现了一个代表压力容器的数字双胞胎,并演示了如何执行我们提出的方法的每个步骤。在这个概念验证过程中,我们识别了漏洞,并展示了攻击者如何通过操纵压力容器的值来破坏系统,从而可能导致压力容器的超压,进而导致容器的爆炸。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信