Risk Assessment for IoT-Enabled Cyber-Physical Systems

TitleRisk Assessment for IoT-Enabled Cyber-Physical Systems
Publication TypeBook Chapter
Year of Publication2021
AuthorsI. Stellios, P. Kotzanikolaou, M. Psarakis, and C. Alcaraz
Book TitleAdvances in Core Computer Science-Based Technologies
PublisherSpringer International Publishing
ISBN Number978-3-030-41196-1
KeywordsCritical Infrastructures, Cyber Physical Systems (CPS), Internet of Things (IoT), Risk assessment Attack paths

Internet of Things (IoT) technologies have enabled Cyber-Physical Systems (CPS) to become fully interconnected. This connectivity however has radically changed their threat landscape. Existing risk assessment methodologies often fail to identify various attack paths that stem from the new connectivity/functionality features of IoT-enabled CPS. Even worse, due to their inherent characteristics, IoT systems are usually the weakest link in the security chain and thus many attacks utilize IoT technologies as their key enabler. In this paper we review risk assessment methodologies for IoT-enabled CPS. In addition, based on our previous work (Stellios et al. in IEEE Commun Surv Tutor 20:3453–3495, 2018, [47]) on modeling IoT-enabled cyberattacks, we present a high-level risk assessment approach, specifically suited for IoT-enabled CPS. The mail goal is to enable an assessor to identify and assess non-obvious(indirect or subliminal) attack paths introduced by IoT technologies, that usually target mission critical components of an CPS.

Citation Key1844