{"title":"Facing Cyber-Physical Security Threats by PSIM-SIEM Integration","authors":"Flavio Frattini, Ugo Giordano, V. Conti","doi":"10.1109/EDCC.2019.00026","DOIUrl":null,"url":null,"abstract":"Physical Protection Systems are Physical Systems that evolved towards the cyber world. Sensors, cameras, barriers and control panels are now networked, making up a monitoring system subject to cyber attacks. Physical Security Information Management (PSIM) software systems are used for managing physical security information; Security Information and Event Management (SIEM) systems are used for cyber security information and events. Considering cyber-physical risks, they can not remain separated. In this paper, we describe our experience in merging PCMS, a PSIM system widely used by Banks in Italy, with QRadar, the well known IBM SIEM. Their integration helps physical security personnel in figuring out hidden threats, as well as the cyber security team for understanding risks related to the Physical Protection System.","PeriodicalId":334498,"journal":{"name":"2019 15th European Dependable Computing Conference (EDCC)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 15th European Dependable Computing Conference (EDCC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EDCC.2019.00026","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
Physical Protection Systems are Physical Systems that evolved towards the cyber world. Sensors, cameras, barriers and control panels are now networked, making up a monitoring system subject to cyber attacks. Physical Security Information Management (PSIM) software systems are used for managing physical security information; Security Information and Event Management (SIEM) systems are used for cyber security information and events. Considering cyber-physical risks, they can not remain separated. In this paper, we describe our experience in merging PCMS, a PSIM system widely used by Banks in Italy, with QRadar, the well known IBM SIEM. Their integration helps physical security personnel in figuring out hidden threats, as well as the cyber security team for understanding risks related to the Physical Protection System.
物理保护系统是向网络世界发展的物理系统。传感器、摄像头、屏障和控制面板现在联网,构成了一个容易受到网络攻击的监控系统。物理安全信息管理(PSIM)软件系统用于管理物理安全信息;SIEM (Security Information and Event Management)系统用于管理网络安全信息和事件。考虑到网络物理风险,它们不能保持分离。在本文中,我们描述了我们将意大利银行广泛使用的PSIM系统PCMS与著名的IBM SIEM QRadar合并的经验。他们的融合有助于物理安全人员发现隐藏的威胁,也有助于网络安全团队了解与物理防护系统相关的风险。