Synergistic Security for the Industrial Internet of Things: Integrating Redundancy, Diversity, and Hardening
Aron Laszka, Waseem Abbas, Yevgeniy Vorobeychik, Xenofon Koutsoukos

TL;DR
This paper proposes a multi-pronged security framework for the Industrial Internet of Things, combining redundancy, diversity, and hardening to enhance resilience against cyber-attacks in critical infrastructure systems.
Contribution
It introduces a framework for quantifying cyber-security risks and optimizing security investments in redundancy, diversity, and hardening for IIoT systems.
Findings
Integrated approach reduces security risk at constant cost
Framework applicable to water distribution and transportation systems
Numerical evaluation confirms effectiveness of combined security techniques
Abstract
As the Industrial Internet of Things (IIot) becomes more prevalent in critical application domains, ensuring security and resilience in the face of cyber-attacks is becoming an issue of paramount importance. Cyber-attacks against critical infrastructures, for example, against smart water-distribution and transportation systems, pose serious threats to public health and safety. Owing to the severity of these threats, a variety of security techniques are available. However, no single technique can address the whole spectrum of cyber-attacks that may be launched by a determined and resourceful attacker. In light of this, we consider a multi-pronged approach for designing secure and resilient IIoT systems, which integrates redundancy, diversity, and hardening techniques. We introduce a framework for quantifying cyber-security risks and optimizing IIoT design by determining security…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Network Security and Intrusion Detection · Information and Cyber Security
