Building on Part 1 of this article (see atp magazin 09/2024), which introduced a specific object of analysis for modular plants to adapt established security concepts, this second part evaluates the suitability of various reference architectures for modular automation. The goal is to develop a reference architecture into which the object of analysis is embedded, and which serves as the basis for a structured risk assessment in accordance with the VDI/VDE 2182 Part 1 process model.
The general development of Industry 4.0 and the highly dynamic threat landscape extend the need for continuous security engineering of industrial components, especially during the development phase. Security risk assessments play an important role to ensure the secure and safe development of Industrial Automation and Control Systems (IACSs), but they are based on sophisticated manual and typically time-consuming tasks for human experts. Therefore, this publication identifies and analyzes the information required to document the results of the security risk assessment throughout the development phase. Furthermore, the currently present concepts for documentation are integrated and aligned towards the initially automated and tool-based results by the utilization of Large Language Models (LLMs).
As the global cybersecurity threat landscape continues to evolve, the importance of implementing robust cybersecurity risk management increases for organizations of all sectors and industries, including component manufacturing. Cybersecurity risk assessments form a fundamental basis for the mitigation of such risks and need to be integrated early and throughout the component development life cycle. However, these assessments are currently performed manually and require substantial financial and human resources. Assessment results may also vary in quality due to a reliance on the individual expertise of human security experts. To increase efficiency and consistency, this work presents an approach to support cybersecurity risk assessments during the development of industrial components by leveraging large language models and retrieval augmented generation. Two main application cases are identified for the integration of such models within established industry workflows. Additionally, a prototypical software implementation is presented that can be integrated seamlessly into existing risk assessment activities.
In view of the dynamic cybersecurity threat land-scape and the increasingly interconnected information technol-ogy (IT) and operational technology (OT) environments, the management of security risks to both IT and OT systems becomes paramount, including efficient and comprehensive risk assessment. Such risk assessments, however, require extensive manual work, the availability of trained security personnel as well as considerable time and financial resources. Additionally, a consistent quality of results often cannot be guaranteed due to a dependency on individual expert knowledge and experience. A promising approach to alleviate these challenges is to use software-based support to automate risk assessment processes and increase efficiency and consistency. This work proposes a con-cept for software-supported automated security risk assessments with a focus on industrial components and the manufacturing industry. It presents key challenges, solution approaches, and further research directions that need to be considered in order to practically implement the concept. Additionally, current research that is already in process towards a practical implementation and a preliminary software prototype are presented.
Veränderte Märkte, steigende Gefährdungslagen für OT-Systeme und immer weitreichendere gesetzliche Regulierung beeinflussen die Randbedingungen für den sicheren Betrieb von Prozessanlagen. Gleichzeitig ist die Beurteilung von Security-Aspekten für modulare Anlagen bisher ein weitgehend offen gelassenes Thema. In diesem ersten Beitragsteil werden daher zunächst die generellen Anforderungen zur Umsetzung von Security-Maßnahmen in modularen Anlagen analysiert. In einem zweiten Beitragsteil bewertet das Autoren-Team zunächst die Eignung verschiedener Referenzarchitekturen für die Anwendung auf modulare Anlagen. Anschließend leiten wir anhand ausgewählter Use-Cases Anforderungen auf Modul- sowie Anlagenebene her, die sich auf einen exemplarischen Betrachtungsgegenstand (gemäß VDI/VDE 2182) beziehen. Unser Ziel ist es damit die Basis für eine Referenzarchitektur für sichere modulare Anlagen zu etablieren.
Changing markets, increasing threats to OT systems, and expanding regulatory requirements are influencing the conditions for the secure operation of process plants. At the same time, the assessment of security aspects for modular plants has been largely left unattended. Therefore, in this first part of the article, we will analyze the general requirements for implementing security measures in modular plants. In the second part of the article, we first evaluate the suitability of various reference architectures. Using selected use cases, we derive both intra-modular and plant-wide requirements that relate to an exemplary object of consideration (in accordance with VDI/VDE 2182) within a modular process plant. Our aim is to establish the basis for a reference architecture for secure modular plants.
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are mostly neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. Therefore, a method for information and process modelling regarding the automation of security risk assessments has been previously designed, but not yet evaluated. This work in progress begins the evaluation of the automated security risk assessment concept by investigating the related work and identifying the main deficits. The results include a requirements analysis for the verification and an outlook towards future evaluation aspects.
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are often neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. To relieve this situation and to increase the degree of automation of security risk assessments, a method for information and process modelling was developed in a previous work. The approach was also implemented prototypically as an expert system but has not been validated, yet. This work therefore presents the validation as an integral part of the overall evaluation of the automated security risk assessment concept. For a systematic validation, a reference security risk assessment is manually defined as a set of data for the comparison with the results of the automated expert system. In addition, the two main hypotheses with regard to the result quality and the process automation evaluated.
Manufacturing systems based on Industry 4.0 concepts provide a greater availability of data and have modular characteristics enabling frequent changes. This raises the need for new security engineering concepts that cover the increasing complexity and frequency of mandatory security risk assessments. In contrast, the current standardization landscape used for the assessment of these systems only offers abstract, static, manual, and resource-intensive procedures. Therefore, this work proposes a method that further specifies the IEC 62443 aiming to automate the security risk assessments in such a way that manual efforts can be reduced and a consistent quality can be achieved. The methodology is presented using network segmentation as a guiding example and consists of four main steps: Information collection based on a process analysis, information formalisation with a semi-formal model, information usage applying first order logic to extract expert knowledge, and information access using the concept of the digital twin. In addition, the applicability of the IEC 62443 standard to the risk assessment of modular manufacturing systems is evaluated.
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of systems necessitate continuous security engineering. Therefore, this work in progress presents the specification and prototypical implementation for automated security risk assessments. In addition, an outlook towards the associated validation, verification, evaluation, and hypothesis testing is given.
Abstract Manufacturing systems based on Industry 4.0 concepts provide a greater availability of data and have modular characteristics enabling frequent changes. This raises the need for new security engineering concepts that cover the increasing complexity and frequency of mandatory security risk assessments. In contrast, the current standardization landscape used for the assessment of these systems only offers abstract, static, manual, and resource-intensive procedures. Therefore, this work proposes a method that further specifies the IEC 62443 aiming to automate the security risk assessments in such a way that manual efforts can be reduced and a consistent quality can be achieved. The methodology is presented using network segmentation as a guiding example and consists of four main steps: Information collection based on a process analysis, information formalisation with a semi-formal model, information usage applying first order logic to extract expert knowledge, and information access using the concept of the digital twin. In addition, the applicability of the IEC 62443 standard to the risk assessment of modular manufacturing systems is evaluated.
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of system structures necessitate a continuous and automated security engineering, especially by application of the mandatory security risk assessments. Collecting the required information for these assessments and formalising expert knowledge shall improve the security of modular manufacturing systems in the future. In order to automate the security risk assessment process, this work proposes a method to determine the Target Security Level (SL-T) in conformance to the IEC 62443 standard based on the MITRE ATT&CK framework and the Intel Threat Agent Library (TAL).
Integrity as one property of trustworthiness is an important aspect for the adoption of the Asset Administration Shell (AAS) as a data exchange format and source for data driven services. Until now, the AAS offers an access control solution as a preventive integrity measure. Nevertheless, preventive methods lack in detecting integrity violations due to accidental or malicious modifications from access permitted endpoints. This work in progress paper proposes a concept to complement the access control with a detective integrity measure. By signing submodels of the AAS, business partners along the life cycle can verify the integrity of the data inside the AAS. Therefore, a Certificates Submodel and a Signature Submodel are proposed in the concept to enable a flexible and interoperable integrity verification. In future work, the concept will be implemented and evaluated.
The current static risk assessment processes and concepts do not match the increasing requirements with regard to flexibility within the industrial automation domain. The amount of manual tasks and needed efforts for risk assessments are too high in order to adequately cover the rising rate of system reconfigurations. Analysing the typical risk assessment processes from the IEC 62443 will show resource constraints with regard to time, bottlenecks, and the main cost drivers. If the most rewarding process steps can be identified and automated, the overall performance of risk assessments can be enhanced to keep up with the demanded flexibility.
The Asset Administration Shell (AAS) is a core element for Industrie 4.0. In addition, the security of industrial systems is a permanent topic that could be improved by the AAS and should have a high priority for future developments and implementations of the AAS. This paper evaluates the current threat landscape for Industrial Control Systems (ICS) communicating to the AAS, as well as for IT systems hosting the AAS. The relevance of these threats is evaluated for the AAS and the threats with the highest relevance, namely Basic Web Application Attacks and Malware Infections, are analysed in detail. The recommended countermeasures for these threats are compared with the state of the art of AAS security concepts and result in missing countermeasures and research gaps for an overall security of the AAS.
In order to ensure the safety and security of industrial systems with regard to all life cycle phases from development through operation to disposal, specific regulatory and normative requirements are imposed. Due to the digitalization, interconnection, and constantly increasing complexity of manufacturing systems in the context of Industrie 4.0, the manual effort necessary to achieve the required safety and security is becoming ever greater and almost impossible to manage, especially for small and medium-sized enterprises. Therefore, this paper examines the existing challenges in this area in more detail and gives an outlook on the possible solutions to ensure safety and security much quicker and with less manual effort. The overall vision is a (partially) automated risk assessment of modular systems with respect to safety and security, including the alignment of the corresponding processes from both domains and the formalization of the information models needed.
Due to the dynamic nature of the Industrial Internet and Industry 4.0, future production systems will be reconfigured frequently and as a part of the engineering process, new system configurations will be deployed automatically. In order to keep pace with this development, it will be required to achieve the needed security level in an automated way and to reduce the current static procedures and manual efforts as much as possible. Therefore, the development and modeling of requirements and capability profiles for all cyber security related aspects is needed. The paper describes an approach for such a modeling based on security requirements and levels of the international standard IEC-62443-3-3 and a system description based on OASIS TOSCA. The approach is applied to a real industrial use-case scenario and an evaluation is performed to demonstrate its feasibility.
The advent of Industry 4.0 brings the Internet of Things (IoT) and Cyber-Physical Systems (CPSs) inside the factory premise and made the boundaries between the information and operational technologies (IT & OT) obsolete. This, in turn, introduces the problem of interoperability due to the integration of multiple industrial protocols and technologies from various automation networks. The aim of this paper is to investigate this interoperability problem of heterogeneous network management and propose a semantic network knowledge base as a solution to it. It also describes a set of generic interface functions for data acquisition.
Increasing heterogeneity of industrial network systems is a fact and the chances that in the future one communication standard will be able to fulfill the requirements of all possible applications are utopian. With the increasing number of communication systems, their management, configuration, and maintenance become a significant issue. Additionally, due to the increasing amount of network services and traffic, the management of available network resources and the possibility of delivering certain levels of communication quality of service, especially across different network solutions becomes a big challenge. Therefore, in this paper a Controller of Controllers (CoC) concept for management of heterogeneous industrial networks is proposed. The concept is designed to support still widely spread legacy fieldbus systems, different Ethernetbased industrial solutions, and potentially upcoming network technologies. The goal is achieved by leveraging state-of-theart architectural concepts such as software-defined networks, which allows for integration of abstract models in network management. The concept is described and discussed by way of a demonstrator concept for a heterogeneous system of fieldbus and Ethernet-based time-sensitive networks.