With the emergence of low-cost smart and connected IoT devices, the area of cyber-physical security is becoming increasingly important. Past research has demonstrated new threat vectors targeting the transition process between the cyber and physical domains, where the attacker exploits the sensing system as an attack surface for signal injection or extraction of private information. Recently, there have been attempts to characterize an abstracted model for signal injection, but they primarily focus on the path of signal processing. This paper aims to systematize the existing research on security and privacy problems arising from the interaction of cyber world and physical world, with the context of broad CPS applications. The primary goals of the systematization are to (1) reveal the attack patterns and extract a general attack model of existing work, (2) understand possible new attacks, and (3) motivate development of defenses against the emerging cyber-physical threats.
翻译:由于出现了低成本的智能和连接的IoT装置,网络-物理安全领域变得越来越重要,过去的研究表明,针对网络和物理领域之间转型过程的新威胁矢量,攻击者利用遥感系统作为信号注入或提取私人信息的攻击地,最近有人试图将信号注入的抽象模式定性为信号输入模式,但主要侧重于信号处理途径,本文件旨在将关于网络世界和物理世界相互作用引起的安全和隐私问题的现有研究与广泛的CPS应用结合起来,系统化的主要目标是:(1) 揭示攻击模式,并提取现有工作的一般攻击模式,(2) 了解可能出现的新攻击,(3) 推动防御新出现网络-物理威胁。