Cyber-physical systems (CPS) are a cornerstone of modern industry, combining Operational Technology (OT) with Information Technology (IT) to enhance the monitoring and control of systems. While this improves efficiency, it also exposes critical OT systems to new threats, as seen by incidents like Stuxnet and the attack on Ukraine’s energy grid. In both cases, attackers exploited vulnerabilities within the cyber layer to gain unauthorized access, allowing them to affect the physical operations and compromise the safety and dependability of the broader system. This highlights the growing need to better understand how failures might cascade across several dependability domains. Conventional security metrics, such as the Common Vulnerability Scoring System (CVSS) overlook aspects like operational context, limiting their relevance to CPS. While CVSS provides valuable insights into technical vulnerability severity, system operators must also evaluate operational risk across dependability dimensions, including availability, reliability, safety, integrity, and maintainability. This misalignment calls for a priority shift in CPS risk analysis, moving from data-driven approaches to consequence-driven models.By utilizing a Cyber Digital Twin (CDT), we can measure the impact of failures on operational risk. The CDT provides a high-fidelity replica of both the OT and IT domains within the CPS. In this environment, failures are generated and injected probabilistically, and their impact is analyzed across the dependability dimensions of the model. Through comprehensive sampling of failure scenarios, we develop quantifiable metrics that enable a consequence-driven risk assessment.This position paper advocates for a unified CPS risk assessment framework that prioritizes operational consequences and probabilistic failure modeling, which is achieved using high-fidelity cyber-physical digital twins. We explore the implications and future research directions of our method, highlighting its potential to identify critical dependability weaknesses and assist security analysts in prioritizing threats according to operational risk.
更多
查看译文
关键词
Industrial Control Systems (ICS),Cyber Physical Systems (CPS),Security-Enhancing Digital Twins (SEDT),Cyber Digital Twins (CDT)