<div class="csl-bib-body">
<div class="csl-entry">Eckhart, M., Ekelhart, A., Biffl, S., Lüder, A., & Weippl, E. R. (2022). QualSec: An Automated Quality-Driven Approach for Security Risk Identification in Cyber-Physical Production Systems. <i>IEEE Transactions on Industrial Informatics</i>. https://doi.org/10.1109/TII.2022.3193119</div>
</div>
-
dc.identifier.issn
1551-3203
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/142503
-
dc.description.abstract
As the threat landscape in the industrial domain continually advances, security-by-design is an evergrowing concern in the engineering of cyber-physical production systems (CPPSs). Often, quality aspects are not
considered when securing CPPSs, which creates attack
vectors that could lead to malicious activity affecting the
products’ quality. Since quality control systems generally provide inadequate protection against intentionally
introduced defects, and can be susceptible to attacks,
quality considerations must be integrated into securityaware CPPS engineering. For this purpose, we propose
the QualSec method that automatically identifies security
risks pertaining to CPPSs, building on the quality characteristics associated with manufacturing operations to
determine cascading effects. QualSec is based on a semantic representation of engineering knowledge, allowing
to efficiently reuse engineering models from AutomationML
artifacts. Moreover, QualSec utilizes Petri nets to facilitate
the analysis of security risks and cascading effects. In this
way, QualSec informs users about possible attack paths
for compromising quality characteristics, how attackers
may disguise their malicious actions, and the possible
consequences of attacks with respect to product quality.
We demonstrate the benefits of QualSec in a case study
and analyze its scalability through a rigorous performance
evaluation
en
dc.description.sponsorship
CDG Christian Doppler Forschungsgesellschaft; CDG Christian Doppler Forschungsgesellschaft
-
dc.language.iso
en
-
dc.publisher
IEEE-INST ELECTRICAL ELECTRONICS ENGINEERS INC
-
dc.relation.ispartof
IEEE Transactions on Industrial Informatics
-
dc.subject
Cyber-physical production systems, information security, industrial control systems, AutomationML, Petri net, production systems engineering.
en
dc.title
QualSec: An Automated Quality-Driven Approach for Security Risk Identification in Cyber-Physical Production Systems
-
dc.type
Article
en
dc.type
Artikel
de
dc.contributor.affiliation
University of Vienna, Austria
-
dc.contributor.affiliation
University of Vienna, Austria
-
dc.contributor.affiliation
Otto-von-Guericke University Magdeburg, Germany
-
dc.contributor.affiliation
SBA Research, Austria
-
dc.relation.grantno
CDL SQI
-
dc.type.category
Original Research Article
-
tuw.journal.peerreviewed
true
-
tuw.peerreviewed
true
-
wb.publication.intCoWork
International Co-publication
-
tuw.project.title
Verbesserung der Sicherheit von Informationsprozessen in Produktionssystemen
-
tuw.researchTopic.id
I2
-
tuw.researchTopic.id
I4a
-
tuw.researchTopic.name
Computer Engineering and Software-Intensive Systems
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
50
-
tuw.researchTopic.value
50
-
dcterms.isPartOf.title
IEEE Transactions on Industrial Informatics
-
tuw.publication.orgunit
E194-01 - Forschungsbereich Software Engineering
-
tuw.publisher.doi
10.1109/TII.2022.3193119
-
dc.identifier.eissn
1941-0050
-
dc.description.numberOfPages
12
-
tuw.author.orcid
0000-0002-3413-7780
-
wb.sci
true
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Wirtschaftswissenschaften
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
5020
-
wb.sciencebranch.value
90
-
wb.sciencebranch.value
10
-
item.openairetype
research article
-
item.languageiso639-1
en
-
item.cerifentitytype
Publications
-
item.fulltext
no Fulltext
-
item.grantfulltext
restricted
-
item.openairecristype
http://purl.org/coar/resource_type/c_2df8fbb1
-
crisitem.project.funder
Christian Doppler Forschungsgesells
-
crisitem.project.grantno
CDL SQI
-
crisitem.author.dept
E194-01 - Forschungsbereich Software Engineering
-
crisitem.author.dept
E194-01 - Forschungsbereich Software Engineering
-
crisitem.author.dept
E194-01 - Forschungsbereich Software Engineering
-
crisitem.author.dept
E194-01 - Forschungsbereich Software Engineering
-
crisitem.author.orcid
0000-0002-3413-7780
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering
-
crisitem.author.parentorg
E194 - Institut für Information Systems Engineering