Security of Additive Manufacturing (AM) gets increased attention due to the growing proliferation and adoption of AM in a variety of applications and business models. However, there is a significant disconnect between AM community focused on manufacturing and AM Security community focused on securing this highly computerized manufacturing technology. To bridge this gap, we surveyed the America Makes AM community, asking in total eleven AM security-related questions aiming to discover the existing concerns, posture, and expectations. The first set of questions aimed to discover how many of these organizations use AM, outsource AM, or provide AM as a service. Then we asked about biggest security concerns as well as about assessment of who the potential adversaries might be and their motivation for attack. We then proceeded with questions on any experienced security incidents, if any security risk assessment was conducted, and if the participants' organizations were partnering with external experts to secure AM. Lastly, we asked whether security measures are implemented at all and, if yes, whether they fall under the general cyber-security category. Out of 69 participants affiliated with commercial industry, agencies, and academia, 53 have completed the entire survey. This paper presents the results of this survey, as well as provides our assessment of the AM Security posture. The answers are a mixture of what we could label as expected, "shocking but not surprising," and completely unexpected. Assuming that the provided answers are somewhat representative to the current state of the AM industry, we conclude that the industry is not ready to prevent or detect AM-specific attacks that have been demonstrated in the research literature.
翻译:Additive Manuary(AM)的安全由于各种应用和商业模式中日益扩散和采用AM而得到越来越多的关注。然而,AM社区以制造和AM安全社区为重点,侧重于确保这一高度计算机化的制造技术。为了缩小这一差距,我们调查了America Make AM社区,共询问了11个AM安全相关问题,以发现现有的关切、态势和期望。第一组问题旨在发现这些组织中有多少组织使用AM、外包AM或提供AM作为服务。然后,我们询问了最大的安全关切,以及评估谁是潜在的对手及其攻击动机。我们接着就任何经历过的安全事件提出了问题,如果进行过任何安全风险评估,而且参与者组织与外部专家合作确保AM的安全。最后,我们问是否完全实施了安全措施,如果是的话,它们是否属于一般网络安全类别。在与商业工业、机构和学术界有联系的69名参与者中,53人已完成了整个调查。本文介绍了这次调查的结果,以及我们如何防止了这次袭击的结果,以及他们攻击的动机。如果进行了任何安全风险评估,那么参与者组织是否与外部专家合作来确保了AM的状态。最后一种令人吃惊的状态。我们得出了一种结论。