arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.30805cs.CRcs.AI

XPhysICS:面向工业控制系统安全的跨物理域威胁落地

XPhysICS: Cross-Physical-Domain Threat Grounding for Industrial Control Systems Security

Sangshin Park, Jainta Paul, Lawrence Ponce, Md Raihan Ahmed, Mu Zhang, Luis Garcia

首次发表
浏览论文内容

中文总结 AI 辅助

XPhysICS提出一种来源感知、目标条件化的方法,通过五个资格标准将ICS威胁跨域落地到目标系统,实验验证了其有效性并强调了可追溯语义和明确标准的重要性。

中文摘要 AI 辅助

针对一个工厂记录的工业控制系统(ICS)威胁可以表达与另一个工厂相关的网络物理效应,但仅凭语义相似性并不能确定这些效应在目标系统上是否结构上可接受或可评估。我们提出了XPhysICS,一种具有来源感知、目标条件化的方法,将分析师引导的源抽象与确定性的落地分离到目标特定的验证切片中。给定固定的源抽象、词汇表和模式,以及机器验证的目标契约,XPhysICS使用五个资格标准评估候选映射:角色兼容性、实现类型兼容性、阶段一致性、切片可行性和规则表面适用性。落地接受、切片充分性、动态可实现性、消费者适用性和消费者结果仍然是不同的证据层。我们评估了83个结构化源威胁抽象,涵盖水处理、水分配、水电/水能以及化学过程目标。受控的目标侧研究,包括SWaT到水处理和WADI到水分配的落地,产生了干净、名义混淆和接近阈值的消费者结果;九个Hydro/GRFICS案例扩展了有界验证切片的执行。我们还评估了有界预测、状态感知和相位感知的消费者通道,未修改的上游GeCo实现,以及基于论文的物理引导搜索方法在三个冻结落地上的复现。结果表明,跨域ICS威胁重用需要可追溯的源语义、明确的目标条件化落地标准,以及后续目标侧证据的仔细分离。

英文摘要

Industrial control system attacks are usually documented in terms of the plant where they occurred: its sensors, actuators, process stages, and control logic. Yet many attacks express a more general physical pattern--such as suppressing flow, corrupting chemical dosing, or driving a vessel toward overflow--that may also matter in a different plant. The challenge is deciding when such a threat remains meaningful on a new system rather than relying on similar component names or broad semantic labels. We present XPhysICS, a methodology for grounding documented cyber-physical threats onto a specific target system. XPhysICS converts source evidence into a provenance-linked description of what is manipulated, what physical consequence is expected, and what observations the evidence calls for. Once this analyst-guided abstraction, its vocabulary and schema version, and a target contract are fixed, XPhysICS applies deterministic grounding checks. An accepted result can be represented as a validation slice that records the mapped roles, signals, dependencies, and context intended to support later evaluation. We study 83 threat abstractions across continuous-process and manufacturing sources using separate evaluation denominators. The continuous-process study evaluates 78 abstractions against target contracts spanning water treatment, water distribution, hydropower, and chemical processes. Selected cases are exercised through controlled perturbations of simulator-role signals. We also test compatibility with several analysis styles, including the released upstream GeCo implementation, and conduct a three-objective, one-target realizability study using a paper-derived search reproduction. Across these evaluated settings, the results support treating explicit target checks and traceable evidence as separate from semantic similarity alone.

发表机构

  • University of Utah(犹他大学)
  • Kahlert School of Computing, University of Utah(犹他大学卡勒特计算学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑