论文标题

物联网供应链安全风险的建模和评估:结构和参数不确定性的作用

Modeling and Assessment of IoT Supply Chain Security Risks: The Role of Structural and Parametric Uncertainties

论文作者

Kieras, Timothy, Farooq, Muhammad Junaid, Zhu, Quanyan

论文摘要

供应链安全威胁对复杂ICT系统(例如IoT)的安全风险建模技术构成了新的挑战。通过从攻击树中得出的既定技术和可靠性分析提供所需的参考点,基于图的分析可以为考虑供应商在此类系统中的作用提供一个框架。我们在这里提出这样的框架,同时突出了对组件中心模型的需求。给定资源限制在将此模型应用于现有系统时,我们研究了模型开发中各种不确定性的类别,包括估计事件概率的结构不确定性和不确定性。使用案例研究,我们发现结构不确定性构成了模型效用的更大挑战,因此应特别关注。面对这些不确定性的最佳实践是提出的。

Supply chain security threats pose new challenges to security risk modeling techniques for complex ICT systems such as the IoT. With established techniques drawn from attack trees and reliability analysis providing needed points of reference, graph-based analysis can provide a framework for considering the role of suppliers in such systems. We present such a framework here while highlighting the need for a component-centered model. Given resource limitations when applying this model to existing systems, we study various classes of uncertainties in model development, including structural uncertainties and uncertainties in the magnitude of estimated event probabilities. Using case studies, we find that structural uncertainties constitute a greater challenge to model utility and as such should receive particular attention. Best practices in the face of these uncertainties are proposed.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源