[论文解读] CPDY: Extending the Dolev-Yao Attacker with Physical-Layer Interactions
本文提出了CPDY(网络物理Dolev-Yao)威胁模型,将经典的Dolev-Yao框架扩展至包含网络物理系统(CPS)中的物理层交互,如机械、化学和电学效应。通过将物理定律和正交交互通道整合到形式化模型中,CPDY能够检测传统仅限网络的模型所忽略的物理层攻击,例如通过过热导致水箱破裂的攻击。该能力在使用ASLan++和AVANTSSAR平台的水处理厂案例研究中得到验证。
We propose extensions to the Dolev-Yao attacker model to make it suitable for arguments about security of Cyber-Physical Systems. The Dolev-Yao attacker model uses a set of rules to define potential actions by an attacker with respect to messages (i.e. information) exchanged between parties during a protocol execution. As the traditional Dolev-Yao model considers only information (exchanged over a channel controlled by the attacker), the model cannot directly be used to argue about the security of cyber-physical systems where physical-layer interactions are possible. Our Dolev-Yao extension, called cyber-physical Dolev-Yao (CPDY) attacker model, allows additional orthogonal interaction channels between the parties. In particular, such orthogonal channels can be used to model physical-layer mechanical, chemical, or electrical interactions between components. In addition, we discuss the inclusion of physical properties such as location or distance in the rule set. We present an example set of additional rules for the Dolev-Yao attacker, using those we are able to formally discover physical attacks that previously could only be found by empirical methods or detailed physical process models.
研究动机与目标
- 为解决传统Dolev-Yao模型在捕捉网络物理系统(CPS)中物理层交互方面的局限性。
- 形式化表达攻击者能力,超越网络层面的操纵,包括加热或机械干扰等物理行为。
- 通过将温度、压力和距离等物理属性纳入攻击者模型,实现CPS安全性的形式化验证。
- 证明此前仅能通过经验或详细物理建模发现的物理层攻击,可借助扩展模型实现形式化检测。
- 在ASLan++中实现CPDY模型,并利用AVANTSSAR平台进行验证。
提出的方法
- 通过引入正交交互通道扩展Dolev-Yao攻击者模型,以建模加热、压力变化和材料特性等物理层效应。
- 引入新规则以编码物理定律,例如含水部件中温度与压力的正比关系。
- 将位置、距离和状态变化(如加热、破裂)等物理属性形式化为攻击者知识和能力的一部分。
- 使用ASLan++形式化语言中的符号约束编码物理交互,实现与现有形式化验证工具(如AVANTSSAR)的集成。
- 定义攻击者行为(如加热组件或操纵物理状态),其逻辑条件基于系统状态和物理定律。
- 结合符号推理与物理规则集,在形式化安全分析框架中模拟和验证物理层攻击。
实验结果
研究问题
- RQ1传统Dolev-Yao模型能否检测网络物理系统中的物理层攻击?
- RQ2如何在符号化攻击者框架中形式化建模物理交互,如加热、压力积聚或材料变化?
- RQ3Dolev-Yao模型需要哪些扩展,才能表示机械或热力操纵等物理层能力?
- RQ4扩展模型能否检测仅能通过物理过程建模或经验测试发现的攻击?
- RQ5如何将物理定律(如热力学关系)编码为形式化安全模型中的逻辑规则?
主要发现
- CPDY模型成功检测到一起水处理厂中因过热导致水箱破裂的物理层攻击,而原始Dolev-Yao模型无法检测该攻击。
- 该攻击通过AVANTSSAR平台进行形式化验证,平台报告违反了‘水箱不应破裂’的安全目标。
- 检测依赖于两条关键规则:一条建模加热引起的温度上升,另一条建模含水部件中的压力增加。
- 该模型表明,即使未发生网络层面的入侵,物理交互(如加热)仍可导致系统失效。
- 将物理定律整合到攻击者模型中,可发现传统仅依赖密码学或网络中心视角的模型所遗漏的攻击。
- CPDY模型扩展了形式化安全模型的表达能力,纳入物理动态,从而实现CPS中更全面的威胁分析。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。