Source-linked AI summary
Cyber-Physical Systems Security -- A Survey
Abdulmalik Humayed, Jingqiang Lin, Fengjun Li, Bo Luo
TL;DR
CPS security lacks a systematic treatment because heterogeneous components and diverse cyber-physical interactions complicate analysis. This survey systematizes existing research through a unified framework spanning security categories, CPS aspects, and representative applications. It uses that framework to organize attacks and controls and identify unresolved challenges, while noting that many medical-device attacks remain demonstrated only experimentally.
Problem
Heterogeneous CPS components and complex cyber-physical interactions make security threats, vulnerabilities, attacks, and controls difficult to study systematically.
Method
The survey organizes CPS security using threats, vulnerabilities, attacks, and controls across cyber, cyber-physical, and physical components and representative CPS applications.
Results
The survey presents a taxonomy and framework connecting CPS aspects with security aspects, including how attacks can cross physical and cyber domains and how controls address them.
Takeaways & Limitations
The framework highlights heterogeneous component interactions as a significant contributor to attacks and directs attention toward controls that account for those interactions.
Abstract
from arXiv · showhide
With the exponential growth of cyber-physical systems (CPS), new security challenges have emerged. Various vulnerabilities, threats, attacks, and controls have been introduced for the new generation of CPS. However, there lack a systematic study of CPS security issues. In particular, the heterogeneity of CPS components and the diversity of CPS systems have made it very difficult to study the problem with one generalized model. In this paper, we capture and systematize existing research on CPS security under a unified framework. The framework consists of three orthogonal coordinates: (1) from the \emph{security} perspective, we follow the well-known taxonomy of threats, vulnerabilities, attacks and controls; (2)from the \emph{CPS components} perspective, we focus on cyber, physical, and cyber-physical components; and (3) from the \emph{CPS systems} perspective, we explore general CPS features as well as representative systems (e.g., smart grids, medical CPS and smart cars). The model can be both abstract to show general interactions of a CPS application and specific to capture any details when needed. By doing so, we aim to build a model that is abstract enough to be applicable to various heterogeneous CPS applications; and to gain a modular view of the tightly coupled CPS components. Such abstract decoupling makes it possible to gain a systematic understanding of CPS security, and to highlight the potential sources of attacks and ways of protection.
I. INTRODUCTION
CPS security is difficult because heterogeneous components and complex cyber-physical interactions create diverse vulnerabilities, attacks, and protection challenges. The survey addresses this gap with a unified framework spanning security concepts, CPS components, and representative applications.
- CPS support critical infrastructure, life-support devices, and essential daily services, but complete immunity from vulnerabilities and attacks is practically impossible.
- Heterogeneous hardware, software, and component integration can each contribute to CPS attacks, complicating security analysis.
- Complex cyber-physical interactions make threats, vulnerabilities, and attacks difficult to assess, identify, trace, and examine across multiple components.
- The survey organizes CPS security around threats, vulnerabilities, attacks, and controls within a unified framework.
- The framework distinguishes cyber, cyber-physical, and physical components while surveying threat sources, vulnerabilities, attacks, controls, and unresolved challenges.
B. CPS Communications
The paper models CPS communications and components across communication, computation-and-control, and monitoring-and-manipulation functions. It applies cyber, cyber-physical, and physical distinctions to ICS, smart grids, and medical-device examples.
- CPS Communications: CPS communication uses wired and wireless technologies, with application-specific protocols for automation, control, control-center links, field devices, and medical devices.
- CPS Models and Aspects: A high-level CPS model contains communication, computation and control, and monitoring and manipulation components.
- CPS Models and Aspects: Sensors monitor physical components and actuators manipulate them, connecting CPS to the physical world.
- CPS Models and Aspects: The framework separates cyber, cyber-physical, and physical aspects, while allowing one component to have different classifications depending on interaction with the physical world.
- Representative Applications: The framework captures application-specific interactions in ICS, smart grids, and medical devices through annotated CPS-aspect views.
D. Security in CPS
CPS security is critical because these systems support critical infrastructure, services, and medical devices, while conventional IT protections alone may be inadequate. The survey organizes CPS security around threats and their sources, targets, motives, attack vectors, and consequences.
- Conventional mechanisms such as cryptography, access control, and intrusion detection may be inadequate without controls that account for cyber-physical aspects.
- CPS security failures can cause catastrophic consequences, including nuclear-plant threats, service loss, utility financial losses, blackouts, and medical-device safety risks.
- The survey examines general and application-specific CPS threats, including threats to ICS, smart grids, medical devices, and smart cars.
- Each threat is characterized by its source, target, motive, attack vector, and potential consequences.
B. CPS Security Threats
The threat model classifies CPS threats by source, target, motive, vector, and consequence, then applies these factors across critical infrastructure and representative CPS applications. Examples span cyberwar, espionage, fraud, privacy violations, physical manipulation, and safety impacts.
- The survey applies five threat factors—source, target, motive, vector, and consequence—to general and application-specific CPS threats.
- Threats against ICS: ICS threats include familiar attackers remotely controlling applications and financially motivated customers tampering with equipment or injecting false data.
- General CPS Threats: CPS threats include cyberwar against critical infrastructure, espionage through malware, and physical attacks that spoof sensors or disrupt operations.
- Threats against Smart Grids: Smart-grid threats include meter tampering for billing fraud, customer profiling from electricity usage, blackouts, and privacy violations.
- Threats against Medical Devices: Medical-device threats include command injection, replay, jamming, privacy breaches, and politically motivated attacks that could harm patients.
- Threats against Smart Cars: Smart-car threats include remote control causing collisions, interception of conversations, GPS tracking, profiling, and politically motivated transportation attacks.
IV. CPS SECURITY VULNERABILITIES
CPS vulnerabilities arise from heterogeneous components, increased connectivity, legacy isolation assumptions, and application-specific weaknesses. The survey classifies vulnerabilities by cyber, cyber-physical, and physical aspects while distinguishing generic from system-specific issues.
- CPS vulnerability analysis distinguishes generic weaknesses from application-specific vulnerabilities so that solutions can match smart grids, medical devices, or other systems.
- The survey classifies vulnerabilities according to whether they appear in cyber, cyber-physical, or physical CPS aspects.
- General CPS Vulnerabilities: Legacy isolation assumptions became problematic as CPS gained connectivity through open networks, wireless technologies, control centers, and Internet-linked business networks.
- General CPS Vulnerabilities: Heterogeneous COTS, third-party, and proprietary components create security problems across products and their integration.
- ICS Vulnerabilities: ICS cyber vulnerabilities include weaknesses in open protocols, Ethernet interception and MITM attacks, and wireless eavesdropping, replay, and unauthorized access.
- Smart Grids and Medical Devices: Smart-grid and medical-device vulnerabilities include exposed network connectivity, proprietary security-by-obscurity designs, wireless weaknesses, and software defects affecting health conditions.
C. Cyber-Physical Vulnerabilities
Cyber-physical vulnerabilities connect communication and software weaknesses to physical devices and consequences. Examples include insecure industrial protocols, exposed field devices, malware targeting control software, medical-device wireless failures, and smart-car sensor manipulation.
- ICS Vulnerabilities: Modbus and DNP3 communication between ICS components lack basic protections such as encryption and integrity checks, enabling eavesdropping and data manipulation.
- ICS Vulnerabilities: Internet-connected or directly accessible field devices, default passwords, and secondary communication channels can expose PLCs and RTUs to attackers.
- ICS Vulnerabilities: Stuxnet exploited Windows and WinCC weaknesses to reach PLCs, while missing digital signatures allowed rogue code to be sent to controllers.
- Medical Devices Vulnerabilities: Wireless failures in medical devices can produce physical health impacts, including excessive glucose levels when an insulin pump misses updates.
- Medical Devices Vulnerabilities: Injection and replay attacks can send unauthorized commands or false readings to implanted devices and insulin pumps.
- Smart Cars Vulnerabilities: Smart-car CAN and LIN protocols lack encryption, authentication, and authorization, while spoofed or noisy ACC sensors can cause unexpected speed changes or collisions.
D. Physical Vulnerabilities
Physical vulnerabilities arise from exposed CPS components, devices, environments, and user mobility, enabling tampering, sabotage, misleading data, or disruption across applications.
- Physical vulnerabilities: Physical tampering of sensors, actuators, and surrounding environments can produce misleading data in cyber-physical components.The survey notes that physical attacks with cyber impact are less studied than cyber attacks with physical impact.
- Industrial control systems: Scattered RTUs and PLCs become vulnerable to tampering or sabotage when insufficiently protected physically.A water-canal example shows stolen solar panels causing control-center data loss.
- Smart grids: Smart-grid field devices and power lines remain exposed to direct physical destruction in unprotected environments.The survey cites malicious, accidental, and natural threats to power-grid components.
- Medical devices: Physical access to medical devices can enable malware installation or configuration changes that produce unadvised treatment.Mobility also exposes devices to attacks in surroundings their designers cannot control.
- Smart cars: Unprotected cars are vulnerable to physical destruction and access attacks, including disabling tire-pressure sensing or reaching internal parts.These attacks do not necessarily require cyber-capabilities.
V. REAL-WORLD CPS ATTACKS
The survey reviews experimentally realized or real-world CPS attacks and classifies them by affected components, while illustrating cyber, privacy, and availability consequences across CPS applications.
- Attack taxonomy: Reported CPS attacks are categorized by whether damage remains cyber, directly reaches physical components, or indirectly affects them through cyber components.Publicly known attacks are rare, so the survey emphasizes attacks realized experimentally or in real life.
- Industrial control systems: Communication-protocol vulnerabilities include demonstrated ARP spoofing attacks against SCADA systems.This example represents a purely cyber attack under the survey’s damage-location classification.
- Industrial control systems: ICS attacks include espionage, phishing and watering-hole delivery, web exploitation, and disruptions caused by unintended software updates or malware.Flame collected private data, while a nuclear-plant reboot erased critical control-system data and contributed to shutdown.
- Smart grids: Smart-grid attacks include overwhelming flooding, false-data injection, customer-information inference, and untargeted malware affecting time-critical networks.The survey also reports that Slammer consumed significant time-critical traffic without causing service outages.
- Medical devices: Medical-device attacks include replay, privacy invasion, and command manipulation that can misinform treatment or expose device and patient information.Replaying an old glucose packet can cause an insulin pump to use a dishonest reading and deliver the wrong insulin amount.
- Smart cars: Smart-car attacks exploit physical or wireless access to internal networks and include denial of service, false-data injection, and other control disruptions.Reviewed work was mostly abstract, theoretical, or simulation-based, with only a few experiments on real cars.
B. Cyber-Physical Attacks
Cyber-physical attacks use cyber access, protocols, malware, or network connections to influence physical operations, safety functions, or infrastructure outcomes.
- Industrial control systems: Legacy dial-up connections can expose field devices to unauthorized access and provide control capabilities even when no physical impact occurs.A water utility’s billing information was accessed through a canal-system dial-up connection.
- Industrial control systems: Insider misuse and Modbus malware can alter industrial operations through unauthorized configuration changes or commands to sensors and actuators.The Modbus worm combines denial-of-service messages with command injection by exploiting missing authentication and integrity protection.
- Industrial control systems: Targeted ICS malware such as Stuxnet exploits software vulnerabilities to identify specific PLC environments and alter PLC configurations.The survey describes Stuxnet as a sophisticated attack that infected many systems but targeted specific Siemens PLCs.
- Industrial control systems: Web interfaces connected to field devices can be abused for denial of service or malicious code execution against controllers.Attackers opened connections until authorized users were blocked and used JavaScript to exploit a TCP/IP-stack bug.
- Smart grids: Smart-grid cyber-physical threats include cyber extortion and attacks capable of causing large-scale blackouts or generator damage.An INL experiment demonstrated the feasibility of damaging a generator through a cyber attack.
- Medical devices: Medical-device attacks can remotely stop or resume insulin delivery, replay packets, or disable ICD therapies.These attacks exploit remote-control or replay-countermeasure vulnerabilities and can create critical health conditions.
- Smart cars: Connected-car pathways enable malware injection and packet or replay attacks that reach safety-critical ECUs and vehicle functions.Bluetooth, cellular, OBD-II, and CAN-network access can support attacks involving brakes, engines, windows, lights, or airbags.
C. Physical Attacks
Physical attacks exploit environmental exposure, direct damage, physical access, or sensor manipulation to disrupt CPS operations or deceive cyber components.
- Unintended and collateral attacks: Untargeted malware can cause collateral ICS damage, including server reboots, arbitrary-code-execution exposure, computer infection, and denial of service.The cited example shows that malware intended for traditional IT systems can affect ICS networks.
- Smart grids: Natural incidents, vehicle collisions, vandalism, and terrorism have disrupted or damaged smart-grid infrastructure and caused large outages.Examples include outages affecting 750,000 and 500,000 people, plus a terrorist attack affecting 24 million people.
- Physical access: Physical access can support attacks such as acquiring device identifiers and unauthorized entry through exposed systems.The survey identifies obtaining serial numbers as an example requiring physical access.
- Smart cars: Relay attacks successfully opened and started ten cars from eight manufacturers by relaying key-fob communications at the physical layer.The attack evaded cryptographic measures because it targeted physical-layer communication.
- Smart cars: Car key cloning can also exploit simple cryptography and inadequate key management to enable unauthorized access.The cited attack is described as a Man-in-the-Middle or two-thief attack.
- Smart cars: ABS spoofing manipulates the magnetic field at a wheel-speed sensor to create inaccurate measurements for the ABS ECU.The demonstrated attack used a malicious actuator to disrupt the original sensor field and inject incorrect speed measures.
VI. SECURITY CONTROLS/SOLUTIONS
CPS controls address application-independent risks through general security mechanisms, connectivity protections, communication-aware intrusion detection, and device attestation. These controls must account for proprietary protocols, time-critical operation, physical-security assumptions, and resource constraints.
- General CPS controls: CPS controls include application-independent solutions and cross-domain mechanisms that can transfer between domains such as cars and medical devices.The survey distinguishes general CPS solutions from application-specific controls and identifies some solutions as cross-domain.
- Connectivity controls: Connectivity controls must secure access points and account for vulnerabilities in proprietary protocols designed under isolation assumptions.The survey identifies Modbus and DNP3 as examples of proprietary protocols with inherited vulnerabilities.
- Communication controls: CPS intrusion detection systems should be time-critical because long communication delays are intolerable in industrial control environments.The survey contrasts CPS communication controls with traditional IT solutions and highlights time-critical IDS design.
- Device attestation: Device attestation can reduce malware, but TPM-based approaches assume physical security and may impose excessive computational overhead on resource-limited CPS.The survey calls for TPM designs adapted to constrained CPS resources.
B. System-specific Controls
System-specific controls adapt security mechanisms to the cyber-physical interactions, protocols, scale, and operational constraints of ICS, smart grids, medical devices, and other CPS applications. The surveyed approaches include protocol extensions, specialized IDS, layered key management, standards, and redesigned cyber-physical controls.
- ICS controls: ICS security solutions should address cyber-physical interactions and heterogeneous components and protocols rather than only non-malicious failures.The survey notes that reliability-oriented solutions do not cover the growing possibility of malicious cyber attacks.
- ICS controls: Secure Modbus integrates authentication, non-repudiation, and replay protection by modifying an existing industrial communication protocol.The framework is an example of add-on security at the ICS communication level.
- ICS controls: ICS intrusion detection monitors controller and sensor-actuator communication access, sensor-setting modifications, and physical actuator tampering.The survey emphasizes that predictable traffic and static topology can simplify ICS IDS design relative to traditional IT security.
- ICS controls: Layered hash-chain protection divides ICS into high- and low-security zones and prevents a compromised low-security device from intercepting higher-zone data.The approach also provides lightweight key management for widespread ICS environments.
- ICS controls: ICS standards should combine technical and operational controls because neglecting either can contribute to serious attacks.The survey reports that standards may focus on technical controls or operational controls while neglecting ICS-specific properties.
- Smart-grid controls: Smart-grid controls include rate limiting, malicious-packet filtering, network reconfiguration, and physical-layer techniques against wireless jamming.The survey notes that network reconfiguration may be difficult because smart-grid topology is relatively static.
- Smart-grid controls: Smart-grid IDS remains immature because grid scale and component heterogeneity complicate detection, while traditional IT IDS may not transfer directly.The survey describes anomaly detection that combines traditional IDS techniques with physical models.
- Smart-grid controls: Shared field-device passwords prevent non-repudiation because malicious employees can make changes without reliable attribution.The survey identifies low-level authentication and authorization as a common smart-grid problem.
C. Cyber-Physical Security Framework
The survey organizes CPS security across four security issues and three CPS aspects for several representative applications. This framework links threats, vulnerabilities, attacks, and controls to cyber, cyber-physical, and physical components.
- Cyber-physical security framework: Table VI maps threats, vulnerabilities, attacks, and controls across cyber, cyber-physical, and physical aspects of ICS, smart grids, medical devices, and smart cars.The survey presents the table as a sample of the aspects covered under its framework, not an exhaustive representation.
VII. CPS SECURITY CHALLENGES
CPS security challenges arise from heterogeneous components, cyber-physical interactions, legacy integration, and application-specific requirements across ICS, smart grids, medical devices, and smart cars.
- General CPS Security Challenges: CPS heterogeneity makes components and their integration potential contributors to attacks, complicating vulnerability and attack assessment.CPS combine diverse hardware, software, and component interactions.
- General CPS Security Challenges: Cyber-physical security requires considering both cyber and physical aspects because cyber-attacks can have physical consequences.The paper also links this perspective to survivability under attack.
- General CPS Security Challenges: Real-time decisions are crucial during attacks, while cryptographic mechanisms may introduce delays that affect real-time deadlines.The passage recommends considering lightweight and hardware-based mechanisms.
- ICS: ICS security is constrained by legacy systems, making secure integration and economically feasible short-term protections necessary.Updates and changes also require careful coordination to avoid unexpected failures.
- Smart Grids: Smart grids require protection for physically accessible smart meters, large-scale access, consumer privacy, false-data detection, lower-level devices, and coordinated changes.These challenges follow from two-way communication, broad geographical coverage, many stakeholders, and limited capabilities at lower levels.
- Medical Devices: Medical devices must balance security with usability, since restrictive access can prevent urgent reconfiguration during critical patient conditions.The example concerns an implantable medical device and another provider lacking credentials or privileges.
- Smart Cars: Smart cars face secure-integration challenges when manufacturers combine COTS and third-party components with incompatible security assumptions.The lack of internal product details contributes to mismatched assumptions at integration boundaries.
VIII. CONCLUSION
The paper surveys CPS security and privacy through a framework spanning representative applications and cyber-physical interactions. It identifies component heterogeneity as a significant contributor to attacks and highlights the need for system-specific solutions and further research.
- Conclusion: The survey covers ICS, smart grids, medical devices, and smart cars, presenting taxonomies of threats, vulnerabilities, attacks, and controls.It also presents a cyber-physical security framework connecting physical-domain attacks with cyber-domain consequences and proposed solutions.
- Conclusion: Heterogeneous component interactions contribute significantly to many attacks, so effective controls should pay special attention to those interactions.This conclusion is drawn using the paper’s framework.
- Conclusion: New and system-specific CPS security solutions remain needed as newly identified threats and vulnerabilities continue to emerge.The paper highlights missing pieces and challenges to stimulate further research.