Deprecated: Function curl_close() is deprecated since 8.5, as it has no effect since PHP 8.0 in /home/u483256323/domains/poorvam.com/public_html/subdomains/pore/includes/api.php on line 184
Back to Search View Original Cite This Article

Abstract

<jats:p>Hybrid cyber–physical systems (CPS) integrate cloud services used in enterprise environments with operational technology (OT), which controls physical processes. However, most threat models applied to such systems implicitly assume that an adversary necessarily causes any loss of process availability. This perspective is reflected in both the STRIDE model and the MITRE ATT&amp;CK for ICS knowledge base, which primarily focus on adversarial activities. As a result, they do not explicitly account for a scenario that is becoming increasingly relevant in hybrid architectures: the intentional shutdown of a physical process by the organization defending the system. The loss of availability resulting from the activation of protective mechanisms is not, in itself, a new problem. The concept of a spurious trip has been recognized in safety engineering for decades and is addressed in standards such as IEC 61511. Related dependencies are also considered within the STPA-Sec methodology. Therefore, the objective of this work is not to introduce a new type of threat, but rather to demonstrate that this phenomenon is not adequately represented in widely used threat-modeling taxonomies that are primarily attacker-centric. In addition, a specific trust boundary within the hybrid architecture at which this problem manifests itself is identified. This makes it possible to incorporate the phenomenon into the risk analysis of systems in which a compromise of the IT layer alone can ultimately lead to the shutdown of physical processes. The proposed threat model is based on trust-boundary analysis. The reference hybrid architecture was divided into seven trust boundaries, and each STRIDE category was subsequently mapped to the corresponding MITRE ATT&amp;CK techniques for ICS, based on the trust boundary crossed by a given attack scenario. The resulting threat vectors were then ranked using the fundamental metrics defined in CVSS v4.0. The attack vector was derived from the trust boundary crossed by each scenario and, where applicable, was correlated with published CVE vulnerability assessments. The model was validated against four widely documented industrial cybersecurity incidents: Stuxnet, Triton, Industroyer, and Colonial Pipeline.</jats:p>

Show More

Keywords

hybrid which threat trust systems

Related Articles


Deprecated: Function curl_close() is deprecated since 8.5, as it has no effect since PHP 8.0 in /home/u483256323/domains/poorvam.com/public_html/subdomains/pore/includes/api.php on line 76
PORE

About

Connect