{"title":"货物港口的安全参考体系结构","authors":"Eduardo B. Fernandez, Virginia M. Romero","doi":"10.1016/j.iotcps.2022.07.001","DOIUrl":null,"url":null,"abstract":"<div><p>Secure systems must be built in a systematic and holistic way, where security is an integral part of the development lifecycle and cuts across all architectural layers. This need is more evident in Cyber Physical Systems (CPSs), where attacks may target not only the information model of the system but also its physical entities. CPS systems are heterogeneous and often highly complex. Their possibly numerous components and cross-domain complexity make attacks easy to propagate and security difficult to implement. Moreover, this complexity results in a considerable variety of vulnerabilities and a large attack surface. To design secure CPS systems a good approach is to abstract their complexity and develop a common framework, namely a Reference Architecture (RA), to which we add security mechanisms in appropriate places to stop its threats to define a Security Reference Architecture (SRA). An SRA is an abstract architecture describing a conceptual model of security that provides a way to specify security requirements for a wide range of derived concrete architectures. An important type of CPS is a maritime container terminal, a facility where cargo containers are transported between ships and land vehicles for onward transportation, and vice versa. We present here an SRA for cargo ports built out of patterns, which goes beyond existing models in providing a global view and a more precise description than just block diagrams. Starting from an RA, we analyze security issues in each activity of the processes of the system and enumerate its threats. We describe threats using misuse patterns, and from them we select security patterns that realize defensive solutions.</p></div>","PeriodicalId":100724,"journal":{"name":"Internet of Things and Cyber-Physical Systems","volume":"2 ","pages":"Pages 120-137"},"PeriodicalIF":0.0000,"publicationDate":"2022-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.sciencedirect.com/science/article/pii/S2667345222000207/pdfft?md5=87eb6db102f5744874c7aa529dd9d898&pid=1-s2.0-S2667345222000207-main.pdf","citationCount":"2","resultStr":"{\"title\":\"A security reference architecture for cargo ports\",\"authors\":\"Eduardo B. Fernandez, Virginia M. Romero\",\"doi\":\"10.1016/j.iotcps.2022.07.001\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Secure systems must be built in a systematic and holistic way, where security is an integral part of the development lifecycle and cuts across all architectural layers. This need is more evident in Cyber Physical Systems (CPSs), where attacks may target not only the information model of the system but also its physical entities. CPS systems are heterogeneous and often highly complex. Their possibly numerous components and cross-domain complexity make attacks easy to propagate and security difficult to implement. Moreover, this complexity results in a considerable variety of vulnerabilities and a large attack surface. To design secure CPS systems a good approach is to abstract their complexity and develop a common framework, namely a Reference Architecture (RA), to which we add security mechanisms in appropriate places to stop its threats to define a Security Reference Architecture (SRA). An SRA is an abstract architecture describing a conceptual model of security that provides a way to specify security requirements for a wide range of derived concrete architectures. An important type of CPS is a maritime container terminal, a facility where cargo containers are transported between ships and land vehicles for onward transportation, and vice versa. We present here an SRA for cargo ports built out of patterns, which goes beyond existing models in providing a global view and a more precise description than just block diagrams. Starting from an RA, we analyze security issues in each activity of the processes of the system and enumerate its threats. We describe threats using misuse patterns, and from them we select security patterns that realize defensive solutions.</p></div>\",\"PeriodicalId\":100724,\"journal\":{\"name\":\"Internet of Things and Cyber-Physical Systems\",\"volume\":\"2 \",\"pages\":\"Pages 120-137\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.sciencedirect.com/science/article/pii/S2667345222000207/pdfft?md5=87eb6db102f5744874c7aa529dd9d898&pid=1-s2.0-S2667345222000207-main.pdf\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Internet of Things and Cyber-Physical Systems\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2667345222000207\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Internet of Things and Cyber-Physical Systems","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2667345222000207","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Secure systems must be built in a systematic and holistic way, where security is an integral part of the development lifecycle and cuts across all architectural layers. This need is more evident in Cyber Physical Systems (CPSs), where attacks may target not only the information model of the system but also its physical entities. CPS systems are heterogeneous and often highly complex. Their possibly numerous components and cross-domain complexity make attacks easy to propagate and security difficult to implement. Moreover, this complexity results in a considerable variety of vulnerabilities and a large attack surface. To design secure CPS systems a good approach is to abstract their complexity and develop a common framework, namely a Reference Architecture (RA), to which we add security mechanisms in appropriate places to stop its threats to define a Security Reference Architecture (SRA). An SRA is an abstract architecture describing a conceptual model of security that provides a way to specify security requirements for a wide range of derived concrete architectures. An important type of CPS is a maritime container terminal, a facility where cargo containers are transported between ships and land vehicles for onward transportation, and vice versa. We present here an SRA for cargo ports built out of patterns, which goes beyond existing models in providing a global view and a more precise description than just block diagrams. Starting from an RA, we analyze security issues in each activity of the processes of the system and enumerate its threats. We describe threats using misuse patterns, and from them we select security patterns that realize defensive solutions.