Cyber-Physical System Security Analysis via Attack Hook Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber-physical systems (CPS) face increased vulnerability to cyberattacks due to their reliance on digital controls, making it challenging to model and analyze the impact of such attacks on both cyber and physical components effectively, which is crucial for assessing robustness and performance.

Innovation Solution

A model-based security diagnosis and analysis system is developed, featuring a frontend web-based workbench for creating cyber-attack effects libraries and importing simulation models, with a backend platform that generates attack hooks to emulate cyberattacks within the simulation models, allowing for comprehensive analysis of CPS performance under various attack conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If digital control systems are used to operate physical systems, then operational efficiency and control precision are improved, but vulnerability to cyberattacks increases

Engineering Contradiction:
Improvecontrol precisionVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by creating virtual copies of the cyber-physical system before actual attacks occur. These digital twins allow simulation of attack scenarios and preparation of defense strategies in advance, enabling the system to anticipate and prepare responses to potential cyber threats without affecting the actual physical system operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention creates a virtual copy or digital twin of the cyber-physical system that replicates its behavior, components, and operations. This copy can be subjected to various attack scenarios and stress tests independently, allowing analysis of vulnerability and impact without risking the actual physical system while maintaining the precision benefits of digital control.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive simulation of cyberattack impacts is performed, then understanding of vulnerability and impact is improved, but system complexity and computational resources required increase

Engineering Contradiction:
Improveunderstanding of vulnerabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The simulation system is segmented into modular components that can independently model different aspects of the cyber-physical system and attack scenarios. This segmentation allows comprehensive vulnerability analysis to be performed through combination of simpler, manageable modules rather than requiring a single complex monolithic system, reducing overall system complexity while maintaining thoroughness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial simulations focusing on specific attack vectors, system components, or scenario types rather than attempting to simulate every possible attack simultaneously. This selective approach provides comprehensive understanding of vulnerability across multiple dimensions while managing computational resources and system complexity by concentrating on the most critical and likely attack scenarios.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10262143B2System and method for modeling and analyzing the impact of cyber-security events on cyber-physical systems
Publication Date: 2019.04.16 THE MITRE CORPORATION
  • US10262143B2 patent drawing
  • US10262143B2 patent drawing
  • US10262143B2 patent drawing

AI summary

A system and method for systematically undertaking model-based security analysis of a cyber physical system (CPS) is provided. In one example, a cyber model simulation and a control system simulation are mapped using various methods to determine which portions of the cyber-model simulation and the control system simulation are correlated with one another. Using the determined correlation, when a cyber-attack is generated on the cyber model simulation, a corresponding attack hook can be generated for the control system model. The attack hook is configured to be integrated into the control system model so as to mimic the effect on the control system that a cyber-attack can engender. Once one or more attack hooks are generated, the user can place the hooks into the control system simulation schemas and run a series of simulations to determine the effects of a cyber event on the control system in a CPS.