Imperial College London

Dr Martin Barrere Cambrun

Faculty of EngineeringInstitute for Security Science & Technology

Honorary Research Fellow
 
 
 
//

Contact

 

+44 (0)20 7594 8864m.barrere Website

 
 
//

Location

 

Institute for Security Science and TechnologyAbdus Salam LibrarySouth Kensington Campus

//

Summary

 

Publications

Citation

BibTex format

@unpublished{Barrère:2019,
author = {Barrère, M and Hankin, C and Nicolau, N and Eliades, DG and Parisini, T},
publisher = {arxiv},
title = {Identifying security-critical cyber-physical components in industrial control systems},
url = {http://arxiv.org/abs/1905.04796v1},
year = {2019}
}

RIS format (EndNote, RefMan)

TY  - UNPB
AB - In recent years, Industrial Control Systems (ICS) have become an appealingtarget for cyber attacks, having massive destructive consequences. Securitymetrics are therefore essential to assess their security posture. In thispaper, we present a novel ICS security metric based on AND/OR graphs thatrepresent cyber-physical dependencies among network components. Our metric isable to efficiently identify sets of critical cyber-physical components, withminimal cost for an attacker, such that if compromised, the system would enterinto a non-operational state. We address this problem by efficientlytransforming the input AND/OR graph-based model into a weighted logical formulathat is then used to build and solve a Weighted Partial MAX-SAT problem. Ourtool, META4ICS, leverages state-of-the-art techniques from the field of logicalsatisfiability optimisation in order to achieve efficient computation times.Our experimental results indicate that the proposed security metric canefficiently scale to networks with thousands of nodes and be computed inseconds. In addition, we present a case study where we have used our system toanalyse the security posture of a realistic water transport network. We discussour findings on the plant as well as further security applications of ourmetric.
AU - Barrère,M
AU - Hankin,C
AU - Nicolau,N
AU - Eliades,DG
AU - Parisini,T
PB - arxiv
PY - 2019///
TI - Identifying security-critical cyber-physical components in industrial control systems
UR - http://arxiv.org/abs/1905.04796v1
UR - http://hdl.handle.net/10044/1/73782
ER -