Industry 4.0 embodies one of the significant technological changes of this decade. Cyber-physical systems and the Internet Of Things are two central technologies in this change that embed or connect with sensors and actuators and interact with the physical environment. However, such systems-of-systems undergo additional restrictions in an endeavor to maintain reliability and security when building and interconnecting components to a heterogeneous, multi-domain \textit{Smart-*} systems architecture. This paper presents an application-specific, layer-based approach to an offline security analysis inspired by design science that merges preceding expertise from relevant domains. With the example of a Smart-lighting system, we create a dedicated unified taxonomy for the use case and analyze its distributed Smart-* architecture by multiple layer-based models. We derive potential attacks from the system specifications in an iterative and incremental process and discuss resulting threats and vulnerabilities. Finally, we suggest immediate countermeasures for the latter potential multiple-domain security concerns.
翻译:4.0 工业4.0 体现了本十年的重大技术变革之一:网络物理系统和“物联网”是这一变革中的两项核心技术,它们嵌入或连接传感器和驱动器,并与物理环境互动;然而,这些系统系统系统在努力维护可靠性和安全方面受到额外的限制,以努力在构筑和连接部件时保持可靠性和安全性,并将部件与多元、多域{Smart- ⁇ {Smart- ⁇ }系统结构联系起来。本文件介绍了在设计科学的启发下对离线安全分析采取的具体应用、基于层次的方法,这种分析将相关领域以前的专门知识融合在一起。我们以智能照明系统为例,为使用案例创建了专门的统一分类法,并以多层模型分析其分布式的智能*结构。我们从系统规格中以迭接和递增的过程获取潜在攻击,并讨论由此产生的威胁和脆弱性。最后,我们建议立即对后一种潜在的多领域安全关切采取对策。