GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • INFORMATIK - Jahrestagung der Gesellschaft für Informatik e.V.
  • P295 - INFORMATIK 2019 - 50 Jahre Gesellschaft für Informatik – Informatik für Gesellschaft (Workshop-Beiträge)
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • INFORMATIK - Jahrestagung der Gesellschaft für Informatik e.V.
  • P295 - INFORMATIK 2019 - 50 Jahre Gesellschaft für Informatik – Informatik für Gesellschaft (Workshop-Beiträge)
  • Dokumentanzeige

Operational Security Modeling and Analysis for IACS

Autor(en):
Gao, Yuan [DBLP] ;
Ben Zid, Ines [DBLP] ;
Lou, Xinxin [DBLP] ;
Parekh, Mithil [DBLP]
Zusammenfassung
Security Certifications based on international standards, like ISO 27000 and IEC 62443 series, are strongly favored by industrial manufactures and (critical) facility owners. However, comparing to mature safety certification procedures, there is only a small portion of security certifications available on the market for the booming Industry 4.0 solutions and IoT/IIoT products. The major challenge is how to define a practical working scope, which is compatible with frequent system updates as well as creations of new systems by coupling supplier services. Meanwhile, the potential security impacts should be quantitatively predictable since some of them are tolerable, which are different from most of safety constraints. Thus, in this paper, we proposed an operational security model, which intends to support monitoring and analysis on a dynamically running system. It was extended from the 3-domains security model we proposed in previous work by introducing run-time perspectives and procedures. In addition, cooperating with the security in design concept, the proposed operational procedures were developed following the guidance of the security standard series IEC 62443. For addressing the external threats, Open Source Intelligence (OSINT) were involved to query whether some confidential information, like user-credentials and system vulnerabilities are already collected and publicly known to adversaries. The introduction of OSINT can support more transparent risk assessment approaches. As the conclusion, with the operational security model, we proposed a hybrid approach which consists of security certifications and continuous monitoring/consulting to solve the current challenge.
  • Vollständige Referenz
  • BibTeX
Gao, Y., Ben Zid, I., Lou, X. & Parekh, M., (2019). Operational Security Modeling and Analysis for IACS. In: Draude, C., Lange, M. & Sick, B. (Hrsg.), INFORMATIK 2019: 50 Jahre Gesellschaft für Informatik – Informatik für Gesellschaft (Workshop-Beiträge). Bonn: Gesellschaft für Informatik e.V.. (S. 271-281). DOI: 10.18420/inf2019_ws31
@inproceedings{mci/Gao2019,
author = {Gao, Yuan AND Ben Zid, Ines AND Lou, Xinxin AND Parekh, Mithil},
title = {Operational Security Modeling and Analysis for IACS},
booktitle = {INFORMATIK 2019: 50 Jahre Gesellschaft für Informatik – Informatik für Gesellschaft (Workshop-Beiträge)},
year = {2019},
editor = {Draude, Claude AND Lange, Martin AND Sick, Bernhard} ,
pages = { 271-281 } ,
doi = { 10.18420/inf2019_ws31 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
paper05_04.pdf252.4Kb PDF Öffnen

Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.18420/inf2019_ws31

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

DOI: 10.18420/inf2019_ws31
ISBN: 978-3-88579-689-3
ISSN: 1617-5468
Datum: 2019
Sprache: en (en)
Typ: Text/Conference Paper

Keywords

  • Security Model
  • Operational Security Model
  • Security Operation
  • Continuous Monitoring
  • OSINT
  • Functional Safety
  • IEC 62443
  • Industry 4.0
  • IoT
  • IIoT
Sammlungen
  • P295 - INFORMATIK 2019 - 50 Jahre Gesellschaft für Informatik – Informatik für Gesellschaft (Workshop-Beiträge) [62]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.