Integrated Cyber-Physical Security Evaluation Model
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security evaluation methods fail to comprehensively assess and address the interconnected security risks in both physical and cyber domains of infrastructure facilities, allowing adversaries to exploit vulnerabilities in one domain to compromise the other.
Innovation Solution
A computer-implemented security evaluation system that models and analyzes both physical and cyber domains of a facility, using a computing system with processing, storage, and user interface components to simulate attacks, assess vulnerabilities, and provide risk information through Monte Carlo discrete event simulations and timely detection methodologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security evaluation methods focus on only one domain (physical or cyber), then the evaluation process is simpler, but the security risk assessment is incomplete and fails to identify interconnected vulnerabilities
Solution Approach 1:
The patent combines physical security evaluation and cyber security evaluation into a single integrated system. The system models both physical facilities (buildings, security personnel, physical barriers) and cyber infrastructure (networks, software, hardware) within one unified framework, allowing simultaneous assessment of both domains and their interconnections without requiring separate evaluation processes
Solution Approach 2:
The evaluation system is designed to perform multiple functions: it can evaluate physical security measures, cyber security measures, and the interactions between them. The same system framework handles diverse evaluation tasks including assessing physical barriers, cyber vulnerabilities, and hybrid attack scenarios, making it a universal security evaluation platform
2Reliability
If the security evaluation system models both physical and cyber domains comprehensively, then the security risk identification improves, but the computational resources and time required increase significantly
Solution Approach 1:
The system performs preliminary actions by pre-modeling the facility's physical and cyber infrastructure, establishing baseline security configurations and potential attack vectors before actual evaluation begins. This preparatory modeling allows the system to quickly execute scenario-based assessments without rebuilding the entire model each time, reducing evaluation time while maintaining comprehensive coverage
Solution Approach 2:
The system implements partial action by allowing users to select specific evaluation scenarios and focus on particular domains or attack vectors of interest. Rather than requiring complete evaluation of all possible physical and cyber interactions in every case, the system enables targeted assessments that reduce computational overhead while maintaining reliability for the specific evaluation objectives
3Loss of information
If the system integrates both physical and cyber security evaluations, then the identification of interconnected vulnerabilities improves, but the device and method complexity increases
Solution Approach 1:
The system segments the complex integrated evaluation into distinct modules: physical security modeling components, cyber security modeling components, and interaction analysis components. Each segment handles specific aspects of the evaluation independently, then integrates results to identify interconnected vulnerabilities, making the overall complex system manageable and maintainable
Data Source
AI summary
Computer-implemented security evaluation methods, security evaluation systems, and articles of manufacture are described. According to one aspect, a computer-implemented security evaluation method includes accessing information regarding a physical architecture and a cyber architecture of a facility, building a model of the facility comprising a plurality of physical areas of the physical architecture, a plurality of cyber areas of the cyber architecture, and a plurality of pathways between the physical areas and the cyber areas, identifying a target within the facility, executing the model a plurality of times to simulate a plurality of attacks against the target by an adversary traversing at least one of the areas in the physical domain and at least one of the areas in the cyber domain, and using results of the executing, providing information regarding a security risk of the facility with respect to the target.


