
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 160-170 |
| Abstrak | : | The rapid advances in technology can be witnessed in the emergence of cyber-physical systems that pertain to several domains of our society. In transportation, we see the emergence of self-driving vehicles that utilize a multitude of sensors and intelligent learning techniques to navigate autonomously. Such vehicles are complex cyber-physical systems that are mobile and due to their sensor and intrinsic intelligence are able to collect, analyze, and capitalize upon an unprecedented amount of fine-grained data, as well as collaborate in real time with multiple stakeholders. Although such rich data can play a key role in data-driven economies of scale, this raises questions with respect to privacy- and integrity-dependent scenarios. In this work, the feasibility of ensuring integrity, and hence safety, while preserving privacy in the emerging hyperconnected vehicle scenarios is discussed. An exemplary case study on real-time vehicle interactions pertaining to map updates exemplifies the combination of privacy-enhancing technologies with integrity-protecting mechanisms. |
| Pengarang | : | Muhammad Umer Tariq |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 144-159 |
| Abstrak | : | This paper presents a service-oriented development methodology for wide-area cyber-physical systems (CPS) such as smart grid and vehicular networks. Unlike the traditional task-based development approach from the domains of automotive and avionics, the proposed service-oriented development methodology inherently enables disruption-free incremental system deployment and reconfiguration that are fundamental requirements for handling the “always-online” nature of emerging wide-area CPS application domains such as smart grid and vehicular networks. The proposed service-oriented CPS development methodology extends the traditional service-oriented computing (SOC) paradigm for handling hard real-time CPS aspects by introducing resource-aware service deployment and quality-of-service (QoS)-aware service operation phases. The proposed CPS development methodology also supports a streamlined formal interface between the traditional computer-aided feedback controller design environments and SOC paradigm. The paper utilizes a simulation-based smart grid case study to illustrate the advantages of the proposed methodology for developing wide-area cyber-physical systems with improved safety and security characteristics. The paper also identifies a set of technological requirements for the proposed service-oriented CPS development methodology that should guide future research in this area. |
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 129-143 |
| Abstrak | : | In this paper, we introduce a design methodology to develop reliable and secure industrial control systems (ICSs) based on the behavior of their computational resources (i.e., process/application) and underlying physical resources (e.g., the controlled plant). The methodology has three independent, but complementary, components that employ novel approaches and techniques in the design of reliable and secure ICSs. First, we introduce reliable-and-secure-by-design development of secure industrial control applications through stepwise sound refinement of an executable specification, employing deductive synthesis to enforce functional and nonfunctional (e.g., security and safety) properties of ICS applications. Second, we present a runtime security monitor at the middleware level of ICSs that protects ICS operation in the field through comparison of the application execution and the application specification execution in real time; the runtime security monitor can be synthesized from the executable specification. Finally, based on the specification, we perform a vulnerability analysis for false data injection (FDI) attacks, which leads to ICS application designs that are resilient to this type of attacks. We demonstrate the methodology through its application to a basic and typical ICS example application, describing all the tools used and ARMET, the middleware monitor that constitutes the core component of the methodology. |
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 113-128 |
| Abstrak | : | Most existing industrial control systems (ICSs), such as building energy management systems (EMSs), were installed when potential security threats were only physical. With advances in connectivity, ICSs are now, typically, connected to communications networks and, as a result, can be accessed remotely. This extends the attack surface to include the potential for sophisticated cyber attacks, which can adversely impact ICS operation, resulting in service interruption, equipment damage, safety concerns, and associated financial implications. In this work, a novel cyber-physical security framework for ICSs is proposed, which incorporates an analytics tool for attack detection and executes a reliable estimation-based attack-resilient control policy, whenever an attack is detected. The proposed framework is adaptable to already implemented ICS and the stability and optimal performance of the controlled system under attack has been proved. The performance of the proposed framework is evaluated using a reduced order model of a real EMS site and simulated attacks. |
| Pengarang | : | Xenofon Koutsoukos |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 93-112 |
| Abstrak | : | The exponential growth of information and communication technologies have caused a profound shift in the way humans engineer systems leading to the emergence of closed-loop systems involving strong integration and coordination of physical and cyber components, often referred to as cyber-physical systems (CPSs). Because of these disruptive changes, physical systems can now be attacked through cyberspace and cyberspace can be attacked through physical means. The paper considers security and resilience as system properties emerging from the intersection of system dynamics and the computing architecture. A modeling and simulation integration platform for experimentation and evaluation of resilient CPSs is presented using smart transportation systems as the application domain. Evaluation of resilience is based on attacker-defender games using simulations of sufficient fidelity. The platform integrates 1) realistic models of cyber and physical components and their interactions; 2) cyber attack models that focus on the impact of attacks to CPS behavior and operation; and 3) operational scenarios that can be used for evaluation of cybersecurity risks. Three case studies are presented to demonstrate the advantages of the platform: 1) vulnerability analysis of transportation networks to traffic signal tampering; 2) resilient sensor selection for forecasting traffic flow; and 3) resilient traffic signal control in the presence of denial-of-service attacks. |
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 71-92 |
| Abstrak | : | The tight interaction between information technology and the physical world inherent in cyber-physical systems (CPS) can challenge traditional approaches for monitoring safety and security. Data collected for robust CPS monitoring is often sparse and may lack rich training data describing critical events/attacks. Moreover, CPS often operate in diverse environments that can have significant inter/intra-system variability. Furthermore, CPS monitors that are not robust to data sparsity and inter/intra-system variability may result in inconsistent performance and may not be trusted for monitoring safety and security. Towards overcoming these challenges, this paper presents recent work on the design of parameter-invariant (PAIN) monitors for CPS. PAIN monitors are designed such that unknown events and system variability minimally affect the monitor performance. This work describes how PAIN designs can achieve a constant false alarm rate (CFAR) in the presence of data sparsity and intra/inter system variance in real-world CPS. To demonstrate the design of PAIN monitors for safety monitoring in CPS with different types of dynamics, we consider systems with networked dynamics, linear-time invariant dynamics, and hybrid dynamics that are discussed through case studies for building actuator fault detection, meal detection in type I diabetes, and detecting hypoxia caused by pulmonary shunts in infants. In all applications, the PAIN monitor is shown to have (significantly) less variance in monitoring performance and (often) outperforms other competing approaches in the literature. Finally, an initial application of PAIN monitoring for CPS security is presented along with challenges and research directions for future security monitoring deployments. |
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 61-70 |
| Abstrak | : | Historically, robotics systems have not been built with an emphasis on security. Their main purpose has been to complete a specific objective, such as to deliver the correct dosage of a drug to a patient, perform a swarm algorithm, or safely and autonomously drive humans from point A to point B. As more and more robotic systems become remotely accessible through networks, such as the Internet, they are more vulnerable to various attackers than ever before. To investigate remote attacks on networked robotic systems we have leveraged HoneyPhy, a physics-aware honeypot framework, to create the HoneyBot. The HoneyBot is the first software hybrid interaction honeypot specifically designed for networked robotic systems. By simulating unsafe actions and physically performing safe actions on the HoneyBot we seek to fool attackers into believing their exploits are successful, while logging all the communication to be used for attacker attribution and threat model creation. In this paper, we present the HoneyBot and discuss our proof of concept implementation. Our HoneyBot prototype swaps between physical actuation and using prebuilt models of sensor behavior for simulation at runtime given user input commands. |
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 107 (No. 2) |
| Halaman | : | 488-498 |
| Abstrak | : | This article explores how the 1931 Frankenstein film drew on many causes and contexts related to the electrification of western societies for its remarkable success. |
| Pengarang | : | Silaen Victor |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 106 (No. 1) |
| Halaman | : | 38-60 |
| Abstrak | : | Wireless sensors and actuators connected by the Internet-of-Things (IoT) are central to the design of advanced cyber-physical systems (CPSs). In such complex, heterogeneous systems, communication links must meet stringent requirements on throughput, latency, and range, while adhering to tight energy budget and providing high levels of security. In this paper, we first summarize wireless communication principles from the perspective of the connectivity needs of IoT and CPS. Based on these principles, we then review the most relevant wireless communication standards before focusing on the key security issues and features of such systems. In particular, the gap between the security features in the communication standards used in CPSs and IoT and their actual vulnerabilities are pointed out with practical examples and recent attacks. We emphasize the need for a more in-depth study of the security issues across all the protocol layers, including both logical layer security and physical layer security. |
| Pengarang | : | - |
| Nama Majalah/Jurnal | : | Proceedings of the IEEE |
| Volume / Edisi | : | 107 (No. 2) |
| Halaman | : | 471-487 |
| Abstrak | : | In this paper, we discuss and speculate about the concept of the Tactile Robot connected with human operators via smart wearables as an essential multimodal embodiment of the coming Tactile Internet. The Tactile Robot, succeeding the recently introduced kinesthetic soft robot, is the upcoming next step in the evolution of rapidly developing robotic platforms that are capable of sensitive physical interaction with their environment. From the combination of rich tactile feedback with state-of-the-art robotics, technology, and algorithms emerge the potential of a meaningful and immersive connection to human operators via the vastly progressing smart wearables and virtual reality/augmented reality devices, effectively creating real-world avatars. Moreover, the Tactile Internet is believed to make it possible to create avatar collectives spanning different application domains and, therefore, cover heterogeneous robotic platforms. We hypothesize that this development will enable us to seamlessly interact with heterogeneous systems such as industrial assembly lines, service robots, automated medical units, or even deep sea and space exploration units. This new paradigm of an immersive coexistence between humans and robots builds on numerous technological advances in robotics, multimodal teleoperation, wearable technology, distributed computing, or network technology, for example. However, such a vision obviously poses major challenges in multiple areas that are still to be overcome. In this paper, we discuss the potentials and enabling technologies together with foreseeable application domains in the framework of the Tactile Internet. Furthermore, we address major challenges and hypothesize about potential solutions. |