Abstract
Security and safety emerged as an interconnected concept for Cyber-Physical Systems (CPS). In recent years, CPS witnessed an enormous cyber-attack that endorsed the significance of security over safety of the CPS. Many cyber incidents have been recorded where intruders exploit security vulnerabilities that result in safety hazards. In literature, often times security and safety are discussed as a combined concern. This presses the need to treat security and safety as a mutual apprehension. However, more empirical evidence is required to support this mutuality of security and safety. To close this gap, we conducted an empirical study to identify hazard(s) using several methods including the Systematic Theoretical Accidental Model and Process (STAMP), Systematic Theoretic Process Analysis (STPA), Hazard and Operability Study (HAZOP) of a CPS i.e., case study of a Dam , and to performed the risk management (risk identification, risk analysis and mitigation) for the mentioned case study. Our focus remained on security and safety risks only. As a result, we identified all the possible unsafe control events and their potential hazards along with the severity level. Moreover, we suggested the risk mitigation mechanism against the identified hazards which may contribute to the accidents. This study holds implications for CPS practitioners and researchers exploring risk in CPS.
Original language | English |
---|---|
Title of host publication | Proceedings - 2023 International Conference on Frontiers of Information Technology, FIT 2023 |
Publisher | IEEE |
Pages | 7-12 |
Number of pages | 6 |
ISBN (Electronic) | 9798350395785 |
DOIs | |
Publication status | Published - 5 Feb 2024 |
Event | 20th International Conference on Frontiers of Information Technology, FIT 2023 - Islamabad, Pakistan Duration: 11 Dec 2023 → 12 Dec 2023 Conference number: 20 |
Conference
Conference | 20th International Conference on Frontiers of Information Technology, FIT 2023 |
---|---|
Abbreviated title | FIT 2023 |
Country/Territory | Pakistan |
City | Islamabad |
Period | 11/12/23 → 12/12/23 |
Keywords
- 2024 OA procedure
- HAZOP
- Risk Management
- Safety-Security Hazard Analysis
- STAMP
- STPA
- Cyber-Physical Systems