Technical Report: Towards a Systematic Threat Modeling Approach for Cyber-physical Systems

Proc 2015 Resil Week RSW (2015). 2015:2015:10.1109/RWEEK.2015.7287428. doi: 10.1109/RWEEK.2015.7287428.

Abstract

Cyber-Physical Systems (CPS) are systems that integrate physical, computational, and networking components. These systems have an impact on the physical components; it is critical to safeguard them against a range of attacks. In this paper, it is argued that an effective approach to achieve this goal is to systematically identify the potential threats at the design phase of building such systems, commonly achieved via threat modeling. In this context, a tool to perform systematic analysis of threat modeling for CPS is proposed. A real-world wireless railway temperature monitoring system is used as a case study to validate the proposed approach. The threats identified in the system are subsequently mitigated using the National Institute of Standards and Technology (NIST) SP 800-82 guidelines.

Keywords: Case Study; Cyber-Physical Systems; Systematic Analysis; Threat Modeling.