- Research Article
1
- 10.1049/iet-gtd.2016.1054
Guest Editorial
- Aug 01, 2016
- IET Generation, Transmission & Distribution
- Deepa Kundur + 2 more +2
Guest Editorial
This book constitutes the refereed proceedings of the 18th Nordic Conference on Secure IT Systems, NordSec 2013, held in Ilulissat, Greenland, in October 2013. The 18 revised regular papers together with 3 short papers and one invited talk were carefully reviewed and selected from 35 submissions. The papers are organized in topical sections on formal analysis of security protocols, cyber-physical systems, security policies, information flow, security experiences, Web security, and network security
Guest Editorial
Guest Editorial
A Process-Oriented Framework for Security Assessment of Cyber-Physical Systems
Due to digitalization and technological advancement, systems and their requirements are changing, and there is an increasing use of Cyber-Physical Systems (CPS) with a direct connection between the physical and the digital world. These systems process data and have integrated functions and a real-time requirement. There is a great need for security, protection of data, and reliability. The use of digital systems in the energy sector is increasing and changing, as are consumers and generators. This requires a secure IT, communications infrastructure, and highly performing data platforms. The new systems being created are called CPS, which are highly scalable, dynamic, and volatile and process many data of various kinds. One significant aspect of a CPS is security. Personal data and business-sensitive data may be processed, or mission-critical processes may be mapped. Risk analysis and security assessments based on conventional methods and guidelines (for example, BSI IT Basic Protection) have revealed drawbacks. Present security assessment methods focus on analyzing corporate information systems or are applied for software development life cycles. CPS criteria and their impact on security have not yet been accounted for in today’s security assessments and their corresponding frameworks. This thesis concentrates on modeling CPS security and deriving a framework for CPS security assessments. The considered criteria are data security as conventional, expanded by scalability, and real-time. The underlying framework is process-oriented. CPS use cases will be broken down into (atomic) processes and the security assessed based on each process’ data security, scalability and real-time model. Eventually, this will mean security measures can be mapped at the process level. Conducting this research, the focus was on smart grid systems as one example of CPS. For the discussion of mapping security measures, authentication was selected. The result analysis shows an added value in the security assessment of CPS based on the criteria of data security, scalability, real-time, and the breakdown at the process level. The underlying model allows to cope with the complexity of CPS and more precisely assess the security of CPS. The overall approach of CPS security modeling and provision by using a process-oriented framework is highly innovative and provides a concept for developing future CPS security assessment tools.
Read moreData and IT Systems Security in Contemporary Organizations
Data and IT systems security is a critical aspect and plays a significant role in protecting an organization’s business. Organizations must safeguard their information and assets to sustain their value and reputation. Security is essential to information systems because it concerns personal and confidential data belonging to users or companies. The study aims to indicate how enterprises in Poland guarantee the security of data and IT systems, as well as to estimate the complexity of this phenomenon. We have confirmed that small and medium enterprises (SMEs) organizations with a lower level of computerization generally invest fewer resources and possess less expertise in establishing and maintaining IT security policies and strategies.
Read moreSecurity and Privacy Aspect of Cyber Physical Systems
Security and Privacy Aspect of Cyber Physical Systems
Cyberattack Detection for Cyber Physical Systems Security – A Preliminary Study
Cyber-physical systems (CPS) security has become an increasingly important research topic in recent years. Geared towards more advanced cyberattack detection techniques as part of strategies for enhancing the security of CPS, in this paper we propose a machine learning based cyber-attack detection scheme. The proposed scheme is a physical-domain technique; specifically, it assumes the physical measurements of the system carry sufficient information for capturing the system behavior, thus can be used for differentiating normal operation and attacks. CPS are complex in nature and the number of physical measurements available for CPS is often overwhelmingly high. Thus, accurately modeling CPS’ dynamic behavior, more importantly, distinguishing normal and adversary activities based on the large number of physical measurements, can be challenging. To address the challenge, we have focused our research effort on feature engineering, that is, to intelligently derive a set of salient signatures or features from the noisy measurements. We make sure the derived features are more compact and, more importantly, have more discriminant power than the original physical measurements, thus enabling us to achieve more accurate and robust detection performance. To demonstrate the effectiveness of the proposed scheme, in our experimental study we consider gas turbines of combined cycle power plants as the cyber-physical system. Using the data from the high-fidelity simulation we show that our proposed cyberattack detection scheme is able to achieve high detection performance.
Read moreThe use of the command line interface in the verification and management of the security of IT systems and the analysis of the potential of integrating biometric data in cryptographic mechanisms
Purpose: The rapid advancement of digital technologies has necessitated robust security measures to protect information systems against escalating cyber threats. The objective is to study the effectiveness of the command line interface (CLI) in IT system security management. Design/methodology/approach: This paper explores the efficacy of the command line interface (CLI) in managing IT system security and examines the potential of integrating biometric data into cryptographic mechanisms. We delve into the CLI's precision and flexibility, which enable the execution of complex security tasks and its seamless integration with advanced security tools. Furthermore, we investigate the incorporation of biometrics, such as fingerprints and facial recognition, into encryption processes, offering enhanced security by binding access to individual biometric identifiers. Findings: Our findings suggest that while CLI remains a vital tool for security specialists, the convergence of CLI with biometric authentication can significantly fortify the security of information systems. Practical implications: The paper addresses the challenges and opportunities presented by this integration, including privacy concerns and the need for secure handling of biometric data. We also discuss the implications of such technologies in the context of the European Union's legal framework on cybersecurity. Originality/value: The article is aimed at those involved in cyber security management. The article presents the possibility of using biometric attestations to support the security of IT systems. Keywords: cybersecurity, European Union cybersecurity legislation, cryptographic mechanisms, data encryption, multi-factor authentication. Category of the paper: research paper.
Read moreResilient Machine Learning for Networked Cyber Physical Systems: A Survey for Machine Learning Security to Securing Machine Learning for CPS
Cyber Physical Systems (CPS) are characterized by their ability to integrate\nthe physical and information or cyber worlds. Their deployment in critical\ninfrastructure have demonstrated a potential to transform the world. However,\nharnessing this potential is limited by their critical nature and the far\nreaching effects of cyber attacks on human, infrastructure and the environment.\nAn attraction for cyber concerns in CPS rises from the process of sending\ninformation from sensors to actuators over the wireless communication medium,\nthereby widening the attack surface. Traditionally, CPS security has been\ninvestigated from the perspective of preventing intruders from gaining access\nto the system using cryptography and other access control techniques. Most\nresearch work have therefore focused on the detection of attacks in CPS.\nHowever, in a world of increasing adversaries, it is becoming more difficult to\ntotally prevent CPS from adversarial attacks, hence the need to focus on making\nCPS resilient. Resilient CPS are designed to withstand disruptions and remain\nfunctional despite the operation of adversaries. One of the dominant\nmethodologies explored for building resilient CPS is dependent on machine\nlearning (ML) algorithms. However, rising from recent research in adversarial\nML, we posit that ML algorithms for securing CPS must themselves be resilient.\nThis paper is therefore aimed at comprehensively surveying the interactions\nbetween resilient CPS using ML and resilient ML when applied in CPS. The paper\nconcludes with a number of research trends and promising future research\ndirections. Furthermore, with this paper, readers can have a thorough\nunderstanding of recent advances on ML-based security and securing ML for CPS\nand countermeasures, as well as research trends in this active research area.\n
Read moreA Study on the Development of IT System Emergency Recovery - Focused on IT System Security
The purpose of this paper is to study on the development of IT sys- tem emergency recovery focused on IT system security. There are some devel- opment efforts in terms of trial about prompt recovery solutions from securities incidents. In this paper, the main objective is to study about IT system emer- gency recovery solution during system down and security incident happening to react rapidly and correctly for normal condition recovery. This study is fo- cused on quick time back up confronting about security incidents from hacking attacks which cause system down, with a view to prompt recovery of IT system to normal operation conditions.
Read moreTowards a Security Reinforcement Mechanism for Social Cyber-Physical Systems
Cyber-physical systems (CPS) are heterogeneous inter-operating parts of different aspects that can be physical, technical, networking, and even social like agent operators in smart grids. The main concerns of CPS are ensuring security and well-functioning against attacks that can either be technical or socio-technical based threats. To detail how well security policies are expressed, integrated, and reinforced within a CPS, we rely on formal methods to develop a sound approach that models CPS entities, especially their demeanor and interactions. Further, the approach proposes to specify formally security requirements and policies in CPS. For security analysis, we propose an algorithm that reinforces the specified security policies and also quantifies the validity of requirements for CPS. Finally, we validate the approach on a real case scenario of CPS in the presence of social and technical treats.
Read moreThe British National Security Strategy: Security after Representation
Research Highlights and Abstract This article Contributes to the debate on British Foreign and Security Policy; Contributes to the literature on the British National Security Strategy; Links international relations literature with domestic policy formation literature; Introduces the concept of ‘legitimacy’ to foreign and security policy analysis. The publication of the Britain's first National Security Strategy (NSS) in 2008 marked a formal shift away from the secret state of the Cold War to the highly public protective state of today. This article is interested in the question of why the NSS and related framework have taken this particular public and explicit form. Both mainstream and critically minded academics have argued that contemporary security discourses and policies are techniques of power and governance and that the public nature of the policies is vital to this function. In this article, I argue that there has been a transformation in the nature of the British state from a representative state in which the state's authority was legitimated through a number of political mechanisms of representation, to one in which state elites and institutions need to forge new kinds of relationships with the governed. This is a key development that has been noticed in political, sociological and legal theoretical literature but as yet hardly addressed in international relations and security studies. This transformation of the state, I will argue, is intimately linked to the form and content of contemporary security policies. The contemporary state is undergoing a process of an erosion of legitimacy, which has a direct impact upon the capacity of the state to govern. In this context, policies take on the role of trying to bridge the legitimacy gap. I will argue that this shift in the state leads to a different understanding of contemporary security policies as representative of a decreasing ability to govern security, a state that is losing legitimacy and authority; that is in effect, losing its sovereignty. This article argues that British national security strategies and policies are representative of this.
Read moreITL technical accomplishments, 1998
ITL achieved major impact in the areas of measurement and standards for a number of its programs. Measurement technology for the Next Generation Internet (NGI) and the introduction of secure protocols for the Internet are creating a seamless, secure environment for millions of Internet users worldwide. In cooperation with NSA through the NIAP, we are ensuring the security of IT systems and networks through cost-effective testing, evaluation, and certification programs. Also noteworthy is our leadership in defining requirements for embedded Java, as well as numerical extensions to this language.
Read moreThe Cyber Physical Systems and Industrial Internet of Things (IIoT):
The growing requirement for the rise of production, quality, and efficiency of industrial products drives humans to jointly develop novel technologies capable of following up with the exponential technology growth they are facing today in production processes. In the 21st century, industrial internet of things (IIoT) is dedicated to endorsing the internet of things (IoT) to allow the interconnection of anywhere, any time, and anything to enhance efficiency, productivity, intelligence, and safety in the manufacturing system. Consequently, the combined IoT and cyber physical system (CPS) in IIoT will have an influence on industrial techniques through the industrial 4.0 confluence to encourage connected factories. CPS effectively combines physical and cyber components employing modern components such as sensors, network, and computing technologies. But various securities challenges rising in the CPS, like increasing cyberattacks due to the increase in IoT devices, modelling of security threads, CPS vulnerabilities assessment development techniques, and designing of fault-tolerant architectures, motivate new technologies to meet CPS requirements in order to offer security, confidentiality, and reliability of users’ data. Thus, this chapter presents the classification of various existing studies based on CPS security in terms of IIoT applications. Also, it provides the limitations, shortcomings, CPS architectures, and future potential applications to help researchers in the context of practical work.
Read moreA Through Analysis on Protecting Cyber Threats and Attacks on Cps Embedded Subsystems
A Through Analysis on Protecting Cyber Threats and Attacks on Cps Embedded Subsystems
On Distributed System Security
Authorization plays an essential role to ensure the security of a wide variety of computing and IT systems such as data management systems, e-trading systems, database transaction systems, etc. This paper aims to propose a high level formal language for specifying and evaluating distributed authorizations with delegation, develop a new method for credential chain discovery, and implement a system prototype for representing and reasoning about access control policies in distributed environments. By applying the new methodology and technology developed from this work, we will be able to design highly secure computing and IT systems in many different complex problem domains.
Read moreA language for describing attacks on cyber-physical systems
A language for describing attacks on cyber-physical systems