- Research Article
5
- 10.1016/s1361-3723(11)70112-9
The role of user-driven security in data loss prevention
- Nov 01, 2011
- Computer Fraud & Security
- Stephane Charbonneau
The role of user-driven security in data loss prevention
Optimizing security and quality of service in a real-time operating system using multi-objective Bat algorithm
The role of user-driven security in data loss prevention
The role of user-driven security in data loss prevention
Leveraging digital twins for advanced threat modeling in cyber-physical systems cybersecurity
Threat modeling is a critical proactive security technique for identifying threats and determining mitigations. However, traditional approaches often fall short for Industrial Control Systems (ICS), which automate operations in domains like manufacturing and energy and are a subset of Cyber-Physical Systems (CPS). CPS integrates computation, networking, and physical processes, with ICS requiring specialized cybersecurity approaches due to its operational and safety-critical nature. This study explores the use of digital twin technology as a promising cybersecurity tool for ICS, enabling testing and analysis without disrupting operations. By examining the capabilities of digital twins in analysis, simulation, and replication, the research evaluates their potential to enhance threat modeling across the CPS life-cycle. Insights from the European Cyber Security Organisation (ECSO) Technical Paper on Cybersecurity Scenarios and Digital Twins guide the exploration of their role in threat modeling. The study addresses four research questions: 1. What purposes do digital twins serve in cybersecurity? 2. What benefits do digital twins offer in cybersecurity? 3. How can digital twin technology be leveraged for threat modeling? 4. What advantages can the use of digital twins bring to threat modeling? Our findings reveal that digital twins enhance ICS threat modeling by enabling continuous, dynamic, and autonomous assessment, offering valuable insights for advancing cybersecurity strategies in ICS, CPS, and related domains.
Read moreReflecting RTOS Model During WCET Timing Analysis: MSP430/Freertos Case Study
The determination of the execution time upper bound, commonly called Worst-Case Execution Time (WCET), is a necessary step in the development and validation process for real-time systems.The WCET analysis techniques can be classified as static or dynamic.While a high-level language code suffices for the static techniques, for a precise WCET analysis a target architecture or its authentic simulator able to run the final machine-level code of an analyzed application is needed by the dynamic techniques.In the paper, we have decided not only to present a novel hybrid timing analysis technique, but also to show its practical applicability in the area of WCET analysis over particular embedded architecture (MSP430) and real-time operating system (FreeRTOS).Novelty of the presented method can be seen in the fact the operating system model is reflected during the analysis in order to facilitate the process of derivating schedulability test formulas, create detail task/stack analysis etc. Applicability of the method was tested using the MSPsim simulator of the MSP430 architecture.
Read moreCoordination Method of Functional Safety and Cyber Security for Industrial Control Systems
In order to ensure the reliable execution of the functional safety of industrial control systems and effectively resist more and more serious cyber attacks, it is necessary to explore a technical solution suitable for industrial control systems to effectively ensure the compatibility of cyber security and functional security measures. Taking typical SIL3 and SL3 industrial control systems as examples, based on functional safety measures, cyber security measures are analyzed one by one, and potential contradictions between them are identified. Coordination solutions of functional safety and cyber security are given by combining event tree and risk analysis. Finally, integrated protective measures of functional safety and cyber security of industrial control systems are obtained.The results show that the cyber security measures determined by the coordination method are compatible with the original functional safety measures, and the coordination method can be used to guide the cyber security design of industrial control systems.
Read moreIssues in Securing Critical Infrastructure Networks for Smart Grid Based on SCADA, Other Industrial Control and Communication Systems
Computer facilities and microprocessor-based technology have been successfully used in the energy industry. For protection and equipment control, this technology has been used in SCADA, remote control and monitoring applications. Particular attention is paid to the cyber security sector for automation and control systems. Protective application of the equipment and control, SCADA, monitoring and remote control, uses the technology with microprocessor. Due to the great importance of the power supply process, there is no question of being left in a state of vulnerability and neglect. Security is not perfect and will never be. For this reason, there will always be security breaches and incidents. Also, for this reason, not only protection mechanisms are in place, but also mechanisms for rapid detection of incidents and which are able to react effectively to the isolation of problems and to ensuring security. Processes security for systems will continue to evolve in the future. By definition, there are no communication systems that are 100% safe. Attacks against critical industrial infrastructures marked an increase not only in terms of number but also of the level of complexity. The destruction of the industrial control system (ICS) and critical processes were interrupted. For many organizations, the security improvement in ICS systems is great. The extreme sensitivity to ensure the availability and performance of industrial processes has led to a more conservative and rigorous approach to how security measures are implemented. Cyber-attacks that could compromise the availability, integrity, and confidentiality of ICS systems may come from within systems or from outside ICS systems. Among the ICS system infection vectors from the perspective of the SANS Institute (2014) include: external threats (state attacks, hacking etc.), malware, exploiting tools, phishing, internal attacks, cyber security protocols, and industrial espionage. This chapter addresses the cyber security issues required for the protection, automation, control and communications systems of transformation stations as well as methods that could be used to prevent computer attacks that can have a significant impact on the availability of the system Electro-energetic effect with serious consequences on extended area interruptions.
Read moreProposals from the ERNCIP Thematic Group, “Case Studies for the Cyber-security of Industrial Automation and Control Systems”, for a European IACS Components Cyber-security Compliance and Certification Scheme. Thematic Area Industrial Control Systems and Smart Grids
All studies recently published agree. Industrial Automation and Control Systems (IACS) increasingly constitutes a target for cyber-attacks aiming at disturbing Member States’ economies, at disabling our critical infrastructures or at taking advantage from our people. Such hostile acts take place in a context of geostrategic tensions, for the satisfaction of organised crime’s purposes, or else in support of possible activist causes. In this context, the ERNCIP Thematic Group (TG) “Case studies for the cybersecurity of Industrial Automation & Control Systems” was started in January 2014 to answer the question: “Do European critical infrastructure operators need to get IACS’ components or subsystems tested and “certified” (T&C) with regards to their cybersecurity?” And should the answer have been yes, it had to answer a corollary question: “What are (roughly) the conditions of feasibility for implementing successfully a European IACS components cybersecurity Compliance & Certification Scheme?” This TG’s undertaking was a research project, not a task force seeking to deliver an immediately applicable standard. It mobilised representatives of IACS vendors, industrial operators, European Istitutions and national cybersecurity authorities.
Read moreNew Optimal Solutions for Real-Time Reconfigurable Periodic Asynchronous OS Tasks with Minimizations of Response Times
This chapter deals with Reconfigurable Uniprocessor embedded Real-Time Systems to be classically implemented by different OS tasks that we suppose independent, asynchronous, and periodic in order to meet functional and temporal properties described in user requirements. The authors define a schedulability algorithm for preemptable, asynchronous, and periodic reconfigurable task systems with arbitrary relative deadlines, scheduled on a uniprocessor by an optimal scheduling algorithm based on the EDF principles and on the dynamic reconfiguration. Two forms of automatic reconfigurations are assumed to be applied at run-time: Addition-Remove of tasks and just modifications of their temporal parameters: WCET and/or Periods. Nevertheless, when such a scenario is applied to save the system at the occurrence of hardware-software faults, or to improve its performance, some real-time properties can be violated. The authors define a new semantic of the reconfiguration where a crucial criterion to consider is the automatic improvement of the system’s feasibility at run-time by using an Intelligent Agent that automatically checks the system’s feasibility after any reconfiguration scenario to verify if all tasks meet the required deadlines. Indeed, if a reconfiguration scenario is applied at run-time, then the Intelligent Agent dynamically provides otherwise precious technical solutions for users to remove some tasks according to predefined heuristic (based on soft or hard task), or by modifying the Worst Case Execution Times (WCETs), periods, and/or deadlines of tasks that violate corresponding constraints by new ones, in order to meet deadlines and to minimize their response time. To handle all possible reconfiguration solutions, they propose an agent-based architecture that applies automatic reconfigurations in order to re-obtain the system’s feasibility and to satisfy user requirements. Therefore, the authors developed the tool RT-Reconfiguration to support these contributions that they apply to a Blackberry Bold 9700 and to a Volvo system as running example systems and we apply the Real-Time Simulator Cheddar to check the whole system behavior and to evaluate the performance of the algorithm (detailed descriptions are available at the Website: http://beru.univ-brest.fr/~singhoff/cheddar). The authors present simulations of this architecture where they evaluate the agent that they implemented. In addition, the authors present and discuss the results of experiments that compare the accuracy and the performance of their algorithm with others.
Read moreInadequacy of IT Approaches to Manage Cyber Security in ICS Context
The paper “Inadequacy of IT approaches to manage cyber security in ICS context” gives an overview of the application of different IT solutions to deal with cyber security for industrial control systems (ICSs). The real time aspect is important for ICSs to monitor and control effectively different processes. On the other hand, some traditional IT solutions for cyber security do not comply with it. After a careful analysis, it is concluded that there is no ISO 27001 requirement to meet the “non interference” cyber security goal, used by the working group PCSRF in the System Protection Profile for ICSs to ensure that the security functions are implemented in a non-interfering way and do not affect the performance constraints of ICSs. Therefore, a new component, called “Cyber Safety”, is proposed to be added to the existing ones (confidentiality, integrity and availability). Its role would be to check the safety requirements (controls or measures) before their implementations. It is proposed a new model for the management of the cyber security risks that reuses existing results issued from the safety risk analysis and may add safety requirements.
Read moreRisk-based task scheduling approach for integrated control of system safety and cyber security in industrial control systems
System safety and cyber security have a great effect on system reliability which is the foundation of keeping system running-normally. Although safety and security controls can reinforce each other mutually, contradictions between them also exist, such as resource competition that may cause serious damage. This paper puts forward a risk-based task scheduling approach for the integrated control of system safety and cyber security in industrial control systems (ICSs). In this approach, an integrated task model covering both safety task and security task is proposed, which describes the relationship between task and risk in detail. And the change of real-time risk during the enforcement of these tasks is analysed. These tasks are scheduled through an optimal scheduling scheme which means the risk decrease as soon as possible and is always acceptable based on genetic algorithm. Further, simulation results show that the proposed approach is effective for task scheduling and real-time risk control.
Read moreResearch on the Effectiveness of Cyber Security Awareness in ICS Risk Assessment Frameworks
Assessing security awareness among users is essential for protecting industrial control systems (ICSs) from social engineering attacks. This research aimed to determine the effect of cyber security awareness on the emergency response to cyber security incidents in the ICS. Additionally, this study has adopted a variety of cyber security emergency response process measures and frameworks and comprehensively proposes a new organizational model of cyber security incident response. The corresponding measures are evaluated based on the MP2DR2 risk control matrix model to assess their practical value in the evaluation stage. This study found that after adding security awareness measures to response control measures, the influential value ranking of other control measures changed. The practical value of security awareness control measures was given a higher priority than that of other control measures. The research results highlight the importance of cyber security awareness and aim to inspire ICSs to place a higher priority on staff cyber security awareness in relation to cyber security incidents, which can effectively prevent the occurrence of cyber security incidents and make the field of industrial control application agency respond to incidents faster to restore the regular progress of all works.
Read moreRTOS Support for Parallel Execution of Hard Real-Time Applications on the MERASA Multi-core Processor
Multi-cores are the contemporary solution to satisfy high performance and low energy demands in general and embedded computing domains. However, currently available multi-cores are not feasible to be used in safety-critical environments with hard real-time constraints. Hard real-time tasks running on different cores must be executed in isolation or their interferences must be time-bounded. Thus, new requirements also arise for a real-time operating system (RTOS), in particular if the parallel execution of hard real-time applications should be supported. In this paper we focus on the MERASA system software as an RTOS developed on top of the MERASA multi-core processor. The MERASA system software fulfils the requirements for time-bounded execution of parallel hard real-time tasks. In particular we focus on thread control with synchronisation mechanisms, memory management and resource management requirements. Our evaluations show that all system software functions are time-bounded by a worst-case execution time (WCET) analysis.
Read moreDigital Forensic Analysis of Ransomware Attacks on Industrial Control Systems: A Case Study in Factories
In the era of Industry 4.0, the Industrial Control Systems (ICS) are generally connected via a variety of network interfaces for real-time monitoring. As a result, ICS has become one of the main targets to be attacked by several threat actors by discovering the vulnerability in the system encrypting the data, and demanding ransom. Thus, protecting the network has become a major task for many organizations. Although several cybersecurity frameworks and best practices for ransomware are published, a research article case study on the ICS ransomware protection is rarely proposed. Thus, there is a need for actual case studies to increase cyber security experiences. Thus, this paper introduces three case studies based on qualitative research and a real case study. For the actual case study, the network diagram, event log, digital evidence, and digital forensic timeline are presented. For attack analysis, Microsoft ransomware attack framework and MITRE code are used since computer-controlling machines are Windows 10. Case analyses are compared for the understanding of cyber security vulnerabilities.
Read moreOptimisation of optical burst switched networks using multi-objective BAT algorithm
There is a growing demand for OBS (optical burst switching) networks, which is based on the concept of providing switching of data bursts without any intermediate switching and O/E/O conversions. The OBS technology is very economical and flexible to create new definitions for networking processes. OBS networks can also help in creating several types of new services which involve more bandwidth usage. The present research paper focuses on the OBS network and its benefits. The major problems of burst contention and congestion control using OBS networks are addressed in this research. In this paper, a possible solution to burst contention and congestion control is presented by the use of an algorithm, called BAT algorithm. The multi-objective optimisation problem is solved using a multi-objective BAT algorithm (MOBA). The proposed algorithm presented effective results to maximise the traffic demand, burst loss ratio minimisation, and reduction in overall burst block probability.
Read moreHuman factor security: evaluating the cybersecurity capacity of the industrial workforce
As cyber-attacks continue to grow, organisations adopting the internet-of-things (IoT) have continued to react to security concerns that threaten their businesses within the current highly competitive environment. Many recorded industrial cyber-attacks have successfully beaten technical security solutions by exploiting human-factor vulnerabilities related to security knowledge and skills and manipulating human elements into inadvertently conveying access to critical industrial assets. Knowledge and skill capabilities contribute to human analytical proficiencies for enhanced cybersecurity readiness. Thus, a human-factored security endeavour is required to investigate the capabilities of the human constituents (workforce) to appropriately recognise and respond to cyber intrusion events within the industrial control system (ICS) environment.,A quantitative approach (statistical analysis) is adopted to provide an approach to quantify the potential cybersecurity capability aptitudes of industrial human actors, identify the least security-capable workforce in the operational domain with the greatest susceptibility likelihood to cyber-attacks (i.e. weakest link) and guide the enhancement of security assurance. To support these objectives, a Human-factored Cyber Security Capability Evaluation approach is presented using conceptual analysis techniques.,Using a test scenario, the approach demonstrates the capacity to proffer an efficient evaluation of workforce security knowledge and skills capabilities and the identification of weakest link in the workforce.,The approach can enable organisations to gain better workforce security perspectives like security-consciousness, alertness and response aptitudes, thus guiding organisations into adopting strategic means of appropriating security remediation outlines, scopes and resources without undue wastes or redundancies.,This paper demonstrates originality by providing a framework and computational approach for characterising and quantify human-factor security capabilities based on security knowledge and security skills. It also supports the identification of potential security weakest links amongst an evaluated industrial workforce (human agents), some key security susceptibility areas and relevant control interventions. The model and validation results demonstrate the application of action research. This paper demonstrates originality by illustrating how action research can be applied within socio-technical dimensions to solve recurrent and dynamic problems related to industrial environment cyber security improvement. It provides value by demonstrating how theoretical security knowledge (awareness) and practical security skills can help resolve cyber security response and control uncertainties within industrial organisations.
Read moreNew Optimal Solutions for Real-Time Reconfigurable Periodic Asynchronous Operating System Tasks with Minimizations of Response Time
Scheduling tasks is an essential requirement in most real-time and embedded systems, but leads to unwanted central processing unit (CPU) overheads. The authors present a real-time schedulability algorithm for preemptable, asynchronous and periodic reconfigurable task systems with arbitrary relative deadlines, scheduled on a uniprocessor by an optimal scheduling algorithm based on the earliest deadline first (EDF) principles and on the dynamic reconfiguration. A reconfiguration scenario is assumed to be a dynamic automatic operation allowing addition, removal or update of operating system’s (OS) functional asynchronous tasks. When such a scenario is applied to save the system at the occurrence of hardware-software faults, or to improve its performance, some real-time properties can be violated. The authors propose an intelligent agent-based architecture where a software agent is used to satisfy the user requirements and to respect time constraints. The agent dynamically provides precious technical solutions for users when these constraints are not verified, by removing tasks according to predefined heuristic, or by modifying the worst case execution times (WCETs), periods, and deadlines of tasks in order to meet deadlines and to minimize their response time. They implement the agent to support these services which are applied to a Blackberry Bold 9700 and to a Volvo system and present and discuss the results of experiments.
Read more