Model-Based Risk Assessment for Cyber Physical Systems Security
Ashraf Tantawy, Abdelkarim Erradi, Sherif Abdelwahed, and Khaled, Shaban

TL;DR
This paper presents an integrated model-based approach for assessing cybersecurity risks in cyber-physical systems, using a real-world industrial testbed to identify hazards, develop attack scenarios, and evaluate mitigation strategies.
Contribution
It introduces a hybrid automaton-based physical model combined with network analysis for cyber threat assessment in CPS, validated on a real industrial control system.
Findings
Hybrid automaton effectively models hazardous states in CPS.
Hazard development time influences cybersecurity design.
Physical and cyber systems are tightly coupled, requiring integrated security approaches.
Abstract
Traditional techniques for Cyber-Physical Systems (CPS) security design either treat the cyber and physical systems independently, or do not address the specific vulnerabilities of real time embedded controllers and networks used to monitor and control physical processes. In this work, we develop and test an integrated model-based approach for CPS security risk assessment utilizing a CPS testbed with real-world industrial controllers and communication protocols. The testbed monitors and controls an exothermic Continuous Stirred Tank Reactor (CSTR) simulated in real-time. CSTR is a fundamental process unit in many industries, including Oil \& Gas, Petrochemicals, Water treatment, and nuclear industry. In addition, the process is rich in terms of hazardous scenarios that could be triggered by cyber attacks due to the lack of possible mechanical protection. The paper presents an integrated…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
