TY - JOUR
T1 - Integrating redundancy, diversity, and hardening to improve security of industrial internet of things
AU - Laszka, Aron
AU - Abbas, Waseem
AU - Vorobeychik, Yevgeniy
AU - Koutsoukos, Xenofon
N1 - Publisher Copyright:
© 2019, © 2019 Informa UK Limited, trading as Taylor & Francis Group.
PY - 2020/1/2
Y1 - 2020/1/2
N2 - As the Industrial Internet of Things (IIoT) becomes more ubiquitous in critical application domains, such as smart water-distribution and transportation systems, providing security and resilience against cyber-attacks grows into an issue of utmost importance. Cyber-attacks against critical infrastructure pose significant threats to public health and safety. To alleviate the severity of these threats, various security techniques are available, including redundancy, diversity, and hardening. However, no single technique can address the whole spectrum of cyber-attacks that may be launched by a determined and resourceful attacker. In light of this, we consider a multi-pronged approach that integrates redundancy (deploying additional components and devices), diversity (using multiple implementation variants), and hardening (reinforcing individual components) techniques for designing secure and resilient IIoT systems. We introduce a framework for quantifying cyber-security risks and optimizing IIoT design. We show that finding optimal designs is an NP-hard problem, and then present an efficient meta-heuristic algorithm that finds near optimal designs in practice. To demonstrate the applicability of our framework, we present two case studies in water-distribution and transportation systems. Our numerical evaluation shows that integrating redundancy, diversity, and hardening can lead to reduced security risks at the same cost.
AB - As the Industrial Internet of Things (IIoT) becomes more ubiquitous in critical application domains, such as smart water-distribution and transportation systems, providing security and resilience against cyber-attacks grows into an issue of utmost importance. Cyber-attacks against critical infrastructure pose significant threats to public health and safety. To alleviate the severity of these threats, various security techniques are available, including redundancy, diversity, and hardening. However, no single technique can address the whole spectrum of cyber-attacks that may be launched by a determined and resourceful attacker. In light of this, we consider a multi-pronged approach that integrates redundancy (deploying additional components and devices), diversity (using multiple implementation variants), and hardening (reinforcing individual components) techniques for designing secure and resilient IIoT systems. We introduce a framework for quantifying cyber-security risks and optimizing IIoT design. We show that finding optimal designs is an NP-hard problem, and then present an efficient meta-heuristic algorithm that finds near optimal designs in practice. To demonstrate the applicability of our framework, we present two case studies in water-distribution and transportation systems. Our numerical evaluation shows that integrating redundancy, diversity, and hardening can lead to reduced security risks at the same cost.
UR - http://www.scopus.com/inward/record.url?scp=85079787773&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85079787773&partnerID=8YFLogxK
U2 - 10.1080/23335777.2019.1624620
DO - 10.1080/23335777.2019.1624620
M3 - Article
AN - SCOPUS:85079787773
SN - 2333-5785
VL - 6
SP - 1
EP - 32
JO - Cyber-Physical Systems
JF - Cyber-Physical Systems
IS - 1
ER -