On the Cybersecurity of Logistics in the Age of Artificial Intelligence
摘要
Logistics and supply chain management make an enormous market globally, with an overall value measured in trillions of dollars. Logistics is also deeply involved in national critical infrastructures (CI): transportation is directly identified as one of the CI sectors, and many other CI sectors cannot adequately function without properly working logistics. To optimize business processes and automate operational technology, different machine learning (ML) technologies are increasingly taken into use in logistics. It is then paramount that the cybersecurity of these new techniques is sufficient. Today, there is even an understanding, following the MITRE ATT&CK framework, on how typical cyberattacks against ML components are performed, on average. However, the risk profile for logistics applications, especially of those with operational technology components, is not clear: how realistic the threat currently is or how the regulation and standardization are addressing machine learning security in operational technology used in logistics. In this survey, we will look at some of the foundational aspects of information security for ML and operational technology, investigate the known cyberattacks against logistics to profile the threat in typical use cases of ML in logistics, and map what kind of measures can be seen in different guidelines and standards to mitigate the threats in this area.