{"title":"面向工业信息物理系统的信息物理零信任架构","authors":"Xiaomeng Feng;Shiyan Hu","doi":"10.1109/TICPS.2023.3333850","DOIUrl":null,"url":null,"abstract":"In recent years, zero trust architecture (ZTA) has become an emerging security architecture. When deploying to industrial systems, an important consideration of the ZTA is the effective modeling of the cross-layer penetration between cyber and physical layers. An ineffective model of cross-layer penetration can lead to inferior performance in mitigating cross-layer failures. To tackle this issue, this paper develops a subset of the ZTA dedicated to industrial cyber-physical systems (ICPS), called the Cyber-Physical-ZTA, to model cross-layer penetration. Its uniqueness mainly consists of two innovative techniques, namely, a multi-layer access control engine and an integrated physical model-based and data-driven policy optimizer. The multi-layer access control engine can evaluate the trust scores for each component considering their cross-layer impact, while the integration of data-driven and model-based approaches can improve efficiency in optimizing access policies. Our simulations are conducted to demonstrate the effectiveness of Cyber-Physical-ZTA. In comparison to the standard ZTA, with no rules added to detect cross-layer penetration, the multi-access policy engine of the Cyber-Physical-ZTA increases the detection probability against false data injection (FDI) attacks by more than 31%.","PeriodicalId":100640,"journal":{"name":"IEEE Transactions on Industrial Cyber-Physical Systems","volume":"1 ","pages":"394-405"},"PeriodicalIF":0.0000,"publicationDate":"2023-11-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Cyber-Physical Zero Trust Architecture for Industrial Cyber-Physical Systems\",\"authors\":\"Xiaomeng Feng;Shiyan Hu\",\"doi\":\"10.1109/TICPS.2023.3333850\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In recent years, zero trust architecture (ZTA) has become an emerging security architecture. When deploying to industrial systems, an important consideration of the ZTA is the effective modeling of the cross-layer penetration between cyber and physical layers. An ineffective model of cross-layer penetration can lead to inferior performance in mitigating cross-layer failures. To tackle this issue, this paper develops a subset of the ZTA dedicated to industrial cyber-physical systems (ICPS), called the Cyber-Physical-ZTA, to model cross-layer penetration. Its uniqueness mainly consists of two innovative techniques, namely, a multi-layer access control engine and an integrated physical model-based and data-driven policy optimizer. The multi-layer access control engine can evaluate the trust scores for each component considering their cross-layer impact, while the integration of data-driven and model-based approaches can improve efficiency in optimizing access policies. Our simulations are conducted to demonstrate the effectiveness of Cyber-Physical-ZTA. In comparison to the standard ZTA, with no rules added to detect cross-layer penetration, the multi-access policy engine of the Cyber-Physical-ZTA increases the detection probability against false data injection (FDI) attacks by more than 31%.\",\"PeriodicalId\":100640,\"journal\":{\"name\":\"IEEE Transactions on Industrial Cyber-Physical Systems\",\"volume\":\"1 \",\"pages\":\"394-405\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-11-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Transactions on Industrial Cyber-Physical Systems\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10330693/\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Industrial Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://ieeexplore.ieee.org/document/10330693/","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
摘要
近年来,零信任体系结构(zero trust architecture, ZTA)成为一种新兴的安全体系结构。当部署到工业系统时,ZTA的一个重要考虑因素是对网络层和物理层之间的跨层渗透进行有效建模。一个无效的跨层穿透模型会导致降低跨层失效的性能。为了解决这个问题,本文开发了一个专用于工业网络物理系统(ICPS)的ZTA子集,称为网络物理ZTA,以模拟跨层渗透。其独特性主要在于两项创新技术,即多层访问控制引擎和基于物理模型和数据驱动的集成策略优化器。多层访问控制引擎可以考虑每个组件的跨层影响来评估信任得分,而数据驱动和基于模型的方法的集成可以提高访问策略优化的效率。通过仿真验证了网络物理- zta的有效性。与标准的ZTA相比,在没有添加检测跨层渗透的规则的情况下,Cyber-Physical-ZTA的多访问策略引擎对FDI (false data injection)攻击的检测概率提高了31%以上。
Cyber-Physical Zero Trust Architecture for Industrial Cyber-Physical Systems
In recent years, zero trust architecture (ZTA) has become an emerging security architecture. When deploying to industrial systems, an important consideration of the ZTA is the effective modeling of the cross-layer penetration between cyber and physical layers. An ineffective model of cross-layer penetration can lead to inferior performance in mitigating cross-layer failures. To tackle this issue, this paper develops a subset of the ZTA dedicated to industrial cyber-physical systems (ICPS), called the Cyber-Physical-ZTA, to model cross-layer penetration. Its uniqueness mainly consists of two innovative techniques, namely, a multi-layer access control engine and an integrated physical model-based and data-driven policy optimizer. The multi-layer access control engine can evaluate the trust scores for each component considering their cross-layer impact, while the integration of data-driven and model-based approaches can improve efficiency in optimizing access policies. Our simulations are conducted to demonstrate the effectiveness of Cyber-Physical-ZTA. In comparison to the standard ZTA, with no rules added to detect cross-layer penetration, the multi-access policy engine of the Cyber-Physical-ZTA increases the detection probability against false data injection (FDI) attacks by more than 31%.