Cyber-Physical Threat Modeling
摘要
This chapter addresses the challenges faced by traditional threat modeling in the face of cyber-physical threats. It discusses the exploratory studies conducted by researchers on overall system control, joint safety and security (S&S) modeling, and threat impact quantification. The chapter outlines the factors to consider in cyber-physical threat modeling across five key aspects. It focuses on three types of cyber-physical threat models and the method of system control invariant modeling, such as SATMP-SafeSec, formal modeling, and threat modeling, for smart grid business features. The chapter emphasizes the system control invariant modeling approach, which integrates S&S concerns with control issues, treating the former as part of the latter. This method is highlighted for its effectiveness in identifying ICS threats by extracting safety invariants across multiple subsystems.