• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

通过工作域分析检查关键基础设施的网络物理系统的网络安全。

Examining Cybersecurity of Cyberphysical Systems for Critical Infrastructures Through Work Domain Analysis.

机构信息

Virginia Polytechnic Institute and State University, Blacksburg.

出版信息

Hum Factors. 2018 Aug;60(5):699-718. doi: 10.1177/0018720818769250. Epub 2018 Apr 17.

DOI:10.1177/0018720818769250
PMID:29664683
Abstract

OBJECTIVE

The aim of this study was to apply work domain analysis for cybersecurity assessment and design of supervisory control and data acquisition (SCADA) systems.

BACKGROUND

Adoption of information and communication technology in cyberphysical systems (CPSs) for critical infrastructures enables automated and distributed control but introduces cybersecurity risk. Many CPSs employ SCADA industrial control systems that have become the target of cyberattacks, which inflict physical damage without use of force. Given that absolute security is not feasible for complex systems, cyberintrusions that introduce unanticipated events will occur; a proper response will in turn require human adaptive ability. Therefore, analysis techniques that can support security assessment and human factors engineering are invaluable for defending CPSs.

METHOD

We conducted work domain analysis using the abstraction hierarchy (AH) to model a generic SCADA implementation to identify the functional structures and means-ends relations. We then adopted a case study approach examining the Stuxnet cyberattack by developing and integrating AHs for the uranium enrichment process, SCADA implementation, and malware to investigate the interactions between the three aspects of cybersecurity in CPSs.

RESULTS

The AHs for modeling a generic SCADA implementation and studying the Stuxnet cyberattack are useful for mapping attack vectors, identifying deficiencies in security processes and features, and evaluating proposed security solutions with respect to system objectives.

CONCLUSION

Work domain analysis is an effective analytical method for studying cybersecurity of CPSs for critical infrastructures in a psychologically relevant manner.

APPLICATION

Work domain analysis should be applied to assess cybersecurity risk and inform engineering and user interface design.

摘要

目的

本研究旨在将工作域分析应用于网络安全评估和监控与数据采集(SCADA)系统的设计。

背景

在关键基础设施的网络物理系统(CPS)中采用信息和通信技术可实现自动化和分布式控制,但也引入了网络安全风险。许多 CPS 采用 SCADA 工业控制系统,这些系统已成为网络攻击的目标,这些攻击无需使用武力即可造成物理损坏。鉴于复杂系统不可能实现绝对安全,引入意外事件的网络入侵将会发生;适当的响应反过来又需要人类的适应能力。因此,能够支持安全评估和人为因素工程的分析技术对于防御 CPS 是非常宝贵的。

方法

我们使用抽象层次(AH)进行工作域分析,对通用 SCADA 实现进行建模,以识别功能结构和手段-目的关系。然后,我们通过开发和集成铀浓缩过程、SCADA 实现和恶意软件的 AH,对 Stuxnet 网络攻击进行案例研究,研究 CPS 中网络安全的三个方面之间的相互作用。

结果

用于对通用 SCADA 实现进行建模和研究 Stuxnet 网络攻击的 AH 可用于映射攻击向量、识别安全过程和功能的缺陷,并评估针对系统目标的拟议安全解决方案。

结论

工作域分析是一种有效的分析方法,可用于以心理相关的方式研究关键基础设施的 CPS 的网络安全。

应用

应将工作域分析应用于网络安全风险评估,并为工程和用户界面设计提供信息。

相似文献

1
Examining Cybersecurity of Cyberphysical Systems for Critical Infrastructures Through Work Domain Analysis.通过工作域分析检查关键基础设施的网络物理系统的网络安全。
Hum Factors. 2018 Aug;60(5):699-718. doi: 10.1177/0018720818769250. Epub 2018 Apr 17.
2
Predicting Cybersecurity Threats in Critical Infrastructure for Industry 4.0: A Proactive Approach Based on Attacker Motivations.预测工业 4.0 关键基础设施中的网络安全威胁:基于攻击者动机的主动方法。
Sensors (Basel). 2023 May 6;23(9):4539. doi: 10.3390/s23094539.
3
Toward an Applied Cyber Security Solution in IoT-Based Smart Grids: An Intrusion Detection System Approach.迈向基于物联网的智能电网中的应用网络安全解决方案:入侵检测系统方法。
Sensors (Basel). 2019 Nov 14;19(22):4952. doi: 10.3390/s19224952.
4
Cyber Risk Propagation and Optimal Selection of Cybersecurity Controls for Complex Cyberphysical Systems.网络风险传播与复杂网络物理系统的网络安全控制的最优选择
Sensors (Basel). 2021 Mar 1;21(5):1691. doi: 10.3390/s21051691.
5
Influence of Human Factors on Cyber Security within Healthcare Organisations: A Systematic Review.人为因素对医疗机构网络安全的影响:系统综述。
Sensors (Basel). 2021 Jul 28;21(15):5119. doi: 10.3390/s21155119.
6
Hacking the Human: The Prevalence Paradox in Cybersecurity.《人体黑客:网络安全中的流行悖论》
Hum Factors. 2018 Aug;60(5):597-609. doi: 10.1177/0018720818780472.
7
Design and Development of Layered Security: Future Enhancements and Directions in Transmission.分层安全的设计与开发:传输方面的未来增强与方向
Sensors (Basel). 2016 Jan 6;16(1):37. doi: 10.3390/s16010037.
8
Cyberattack Models for Ship Equipment Based on the MITRE ATT&CK Framework.基于 MITRE ATT&CK 框架的船舶设备网络攻击模型。
Sensors (Basel). 2022 Feb 26;22(5):1860. doi: 10.3390/s22051860.
9
Trustworthy and Reliable Deep Learning-based Cyberattack Detection in Industrial IoT.工业物联网中基于深度学习的可信可靠网络攻击检测
IEEE Trans Industr Inform. 2023 Jan;19(1):1030-1038. doi: 10.1109/tii.2022.3190352. Epub 2022 Jul 13.
10
Cybersecurity in Hospitals: A Systematic, Organizational Perspective.医院中的网络安全:系统的组织视角
J Med Internet Res. 2018 May 28;20(5):e10059. doi: 10.2196/10059.