{"title":"工业自动化与控制系统中软件漏洞的系统特定风险评级","authors":"Monika Maidl, Dirk Kröselberg, Tiange Zhao, Tobias Limmer","doi":"10.1109/ISSREW53611.2021.00097","DOIUrl":null,"url":null,"abstract":"Security vulnerabilities are constantly detected in software, and with CVE a world wide infrastructure exists to inform about such vulnerabilities. Typically, the software vendor issues a patch for the vulnerability. The system owners have to install patches timely in order protect against attacks that exploit vulnerabilities. In industrial automation & control systems, there is often a lot of overhead for installing patches, as availability must be ensured. Hence it makes sense to patch immediately only if the vulnerability poses a high risk to the operation of the plant. We propose an algorithm for calculating the system-specific risk of a vulnerability, based on a system model and a system risk image for system-specific exposure and impact. The system-specific exposure depends on the deployment, while the level of impact depends on the purpose of the system, e.g. in critical infrastructure.","PeriodicalId":385392,"journal":{"name":"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)","volume":"10 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"System-specific risk rating of software vulnerabilities in industrial automation & control systems\",\"authors\":\"Monika Maidl, Dirk Kröselberg, Tiange Zhao, Tobias Limmer\",\"doi\":\"10.1109/ISSREW53611.2021.00097\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Security vulnerabilities are constantly detected in software, and with CVE a world wide infrastructure exists to inform about such vulnerabilities. Typically, the software vendor issues a patch for the vulnerability. The system owners have to install patches timely in order protect against attacks that exploit vulnerabilities. In industrial automation & control systems, there is often a lot of overhead for installing patches, as availability must be ensured. Hence it makes sense to patch immediately only if the vulnerability poses a high risk to the operation of the plant. We propose an algorithm for calculating the system-specific risk of a vulnerability, based on a system model and a system risk image for system-specific exposure and impact. The system-specific exposure depends on the deployment, while the level of impact depends on the purpose of the system, e.g. in critical infrastructure.\",\"PeriodicalId\":385392,\"journal\":{\"name\":\"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)\",\"volume\":\"10 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ISSREW53611.2021.00097\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISSREW53611.2021.00097","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
System-specific risk rating of software vulnerabilities in industrial automation & control systems
Security vulnerabilities are constantly detected in software, and with CVE a world wide infrastructure exists to inform about such vulnerabilities. Typically, the software vendor issues a patch for the vulnerability. The system owners have to install patches timely in order protect against attacks that exploit vulnerabilities. In industrial automation & control systems, there is often a lot of overhead for installing patches, as availability must be ensured. Hence it makes sense to patch immediately only if the vulnerability poses a high risk to the operation of the plant. We propose an algorithm for calculating the system-specific risk of a vulnerability, based on a system model and a system risk image for system-specific exposure and impact. The system-specific exposure depends on the deployment, while the level of impact depends on the purpose of the system, e.g. in critical infrastructure.