Abstract : Enumerations constitute a pivotal element of Cyber Threat Intelligence (CTI). References to enumerated artifacts support a universal understanding and integrate threat information. While traditional IT systems and vulnerabilities are covered by security enumerations, this does not apply to Cyber-Physical Systems (CPS). In particular, complexity and interdependencies of components within these systems demand for an extension of current enumerations. Taking on a CPS security management perspective this work identifies deficiencies within the Common Platform Enumeration (CPE) and the Common Vulnerabilities and Exposures (CVE) enumeration. Models for CPS are thus proposed to cover comprehensiveness and usability. A prototype is used to evaluate the feasibility by demonstrating key features of security enumerations for CPS.
https://hal.inria.fr/hal-03243630 Contributor : Hal IfipConnect in order to contact the contributor Submitted on : Monday, May 31, 2021 - 5:46:26 PM Last modification on : Tuesday, July 6, 2021 - 5:12:02 PM
File
Restricted access
To satisfy the distribution rights of the publisher, the document is embargoed
until : 2023-01-01
Daniel Schlette, Florian Menges, Thomas Baumer, Günther Pernul. Security Enumerations for Cyber-Physical Systems. 34th IFIP Annual Conference on Data and Applications Security and Privacy (DBSec), Jun 2020, Regensburg, Germany. pp.64-76, ⟨10.1007/978-3-030-49669-2_4⟩. ⟨hal-03243630⟩