当前位置: X-MOL 学术Energy Inform. › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
powerLang: a probabilistic attack simulation language for the power domain
Energy Informatics Pub Date : 2020-11-25 , DOI: 10.1186/s42162-020-00134-4
Simon Hacks , Sotirios Katsikeas , Engla Ling , Robert Lagerström , Mathias Ekstedt

Cyber-attacks these threats, the cyber security assessment of IT and OT infrastructures can foster a higher degree of safety and resilience against cyber-attacks. Therefore, the use of attack simulations based on system architecture models is proposed. To reduce the effort of creating new attack graphs for each system under assessment, domain-specific languages (DSLs) can be employed. DSLs codify the common attack logics of the considered domain.Previously, MAL (the Meta Attack Language) was proposed, which serves as a framework to develop DSLs and generate attack graphs for modeled infrastructures. In this article, powerLang as a MAL-based DSL for modeling IT and OT infrastructures in the power domain is proposed. Further, it allows analyzing weaknesses related to known attacks. To comprise powerLang, two existing MAL-based DSL are combined with a new language focusing on industrial control systems (ICS). Finally, this first version of the language was validated against a known cyber-attack.

中文翻译:

powerLang:针对电源域的概率攻击模拟语言

对这些威胁进行网络攻击后,IT和OT基础设施的网络安全评估可以提高针对网络攻击的安全性和弹性。因此,提出了使用基于系统架构模型的攻击仿真。为了减少为每个评估中的系统创建新的攻击图的工作,可以使用特定于域的语言(DSL)。DSL编码了所考虑域的常见攻击逻辑。以前,人们提出了MAL(元攻击语言),它可作为开发DSL并为建模基础设施生成攻击图的框架。在本文中,提出了powerLang作为基于MAL的DSL,用于在电源域中对IT和OT基础设施进行建模。此外,它允许分析与已知攻击有关的弱点。要包含powerLang,现有的两种基于MAL的DSL与一种针对工业控制系统(ICS)的新语言相结合。最后,该语言的第一个版本已针对已知的网络攻击进行了验证。
更新日期:2020-11-26
down
wechat
bug