Threat Modeling of Cyber-Physical Systems in Practice
Ameerah-Muhsinah Jamil, Lotfi ben Othmane, Altaz Valani

TL;DR
This paper investigates how security experts perform threat modeling on cyber-physical systems, highlighting challenges and calling for improved methods for continuous and quality-assured threat analysis.
Contribution
It provides empirical insights into current threat modeling practices for CPSs and identifies key challenges faced by practitioners, emphasizing the need for new research in this area.
Findings
Practitioners use a combination of threat modeling methods and standards.
Challenges include knowledge transfer, model updates, and quality assurance.
Reliance on peer evaluation and checklists for model quality.
Abstract
Traditional Cyber-physical Systems(CPSs) were not built with cybersecurity in mind. They operated on separate Operational Technology (OT) networks. As these systems now become more integrated with Information Technology (IT) networks based on IP, they expose vulnerabilities that can be exploited by the attackers through these IT networks. The attackers can control such systems and cause behavior that jeopardizes the performance and safety measures that were originally designed into the system. In this paper, we explore the approaches to identify threats to CPSs and ensure the quality of the created threat models. The study involves interviews with eleven security experts working in security consultation companies, software engineering companies, an Original Equipment Manufacturer (OEM),and ground and areal vehicles integrators. We found through these interviews that the practitioners…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Cybersecurity and Cyber Warfare Studies
