Concerns for the resilience of Cyber-Physical Systems (CPS) in critical infrastructure are growing. CPS integrate sensing, computation, control and networking into physical objects and mission-critical services, connecting traditional infrastructure to internet technologies. While this integration increases service efficiency, it has to face the possibility of new threats posed by the new functionalities. This leads to cyber-threats, such as denial-of-service, modification of data, information leakage, spreading of malware, and many others. Cyber-resilience refers to the ability of a CPS to prepare, absorb, recover, and adapt to the adverse effects associated with cyber-threats, e.g., physical degradation of the CPS performance resulting from a cyber-attack. Cyber-resilience aims at ensuring CPS survival, by keeping the core functionalities of the CPS in case of extreme events. The literature on cyber-resilience is rapidly increasing, leading to a broad variety of research works addressing this new topic. In this article, we create a systematization of knowledge about existing scientific efforts of making CPS cyber-resilient. We systematically survey recent literature addressing cyber-resilience with a focus on techniques that may be used on CPS. We first provide preliminaries and background on CPS and threats, and subsequently survey state-of-the-art approaches that have been proposed by recent research work applicable to CPS. In particular, we aim at differentiating research work from traditional risk management approaches, based on the general acceptance that it is unfeasible to prevent and mitigate all possible risks threatening a CPS. We also discuss questions and research challenges, with a focus on the practical aspects of cyber-resilience, such as the use of metrics and evaluation methods, as well as testing and validation environments.
翻译:CPS将遥感、计算、控制和联网纳入物理物体和任务关键服务,将传统基础设施与互联网技术连接起来。这种整合提高了服务效率,但必须面对新功能带来的新威胁的可能性。这导致网络威胁,如拒绝服务、修改数据、信息泄漏、恶意软件传播等。网络复原力是指CPS将遥感、计算、控制和联网纳入物理物体和任务关键服务,将物理物理影响纳入物理物体和任务关键服务,将传统基础设施与互联网技术连接起来。虽然这种整合提高了服务效率,但它必须面对新功能带来的新威胁的可能性。这导致网络威胁,如拒绝服务、数据修改、信息泄漏、恶意软件传播等。网络复原力是指CPS将实际科学努力纳入准备、吸收、恢复和适应与网络威胁相关的不利影响的能力,例如,CPS业绩因网络攻击而实际退化。网络恢复能力旨在通过保持CPS的核心功能。 网络复原力方面的文献正在迅速增长,因此,我们开始系统化现有科学努力,以降低CPS网络抗御御能力。