TY - GEN
T1 - Model-Based Security Analysis in Additive Manufacturing Systems
AU - Durling, Michael R.
AU - Moitra, Abha
AU - Siu, Kit Y.
AU - Meng, Baoluo
AU - Carbone, John W.
AU - Alexander, Christopher C.
AU - Castillo-Villar, Krystel K.
AU - Ciocarlie, Gabriela F.
N1 - Publisher Copyright:
© 2022 ACM.
PY - 2022/11/7
Y1 - 2022/11/7
N2 - Additive manufacturing (AM) is expected to revolutionize industrial manufacturing processes by providing access to readily available, lower cost, high-performance parts, including those with complex designs and diverse materials, not attainable in conventional subtractive machining processes. These benefits are distinctly advantageous for low-volume rapid prototyping. They also reduce the build time of complex, safety-critical components that traditionally require assembly. The advanced product capabilities of AM also make these systems high risk for intellectual property theft, service outage attacks, and sabotage through compromised product quality. Concerns about malicious actors restrict business models and deter industry adoption and investment, especially those requiring secrecy around safety-critical components. In this paper, we analyze the threats to additive manufacturing system security using the Verification Evidence and Resilient Design in Anticipation of Cybersecurity Threats (VERDICT) tool, a model-based system engineering (MBSE) tool. First, we introduce a comprehensive set of attributes to characterize MBSE tools together with a survey of MBSE tools that support cyber analysis. Based on these attributes and the available tools, we select the relevant tool (i.e., VERDICT) and apply it to an example additive manufacturing system. The modeling and analysis are intended to show the functionality of the VERDICT tool in a research context. The signals, properties, and requirements enable the user to experiment with and illustrate the functionality of the tool. Finally, the paper introduces a novel approach for modeling the return on investment (ROI) for additive hardware cybersecurity investments that will lead to a cost-analysis integration with the VERDICT tool.
AB - Additive manufacturing (AM) is expected to revolutionize industrial manufacturing processes by providing access to readily available, lower cost, high-performance parts, including those with complex designs and diverse materials, not attainable in conventional subtractive machining processes. These benefits are distinctly advantageous for low-volume rapid prototyping. They also reduce the build time of complex, safety-critical components that traditionally require assembly. The advanced product capabilities of AM also make these systems high risk for intellectual property theft, service outage attacks, and sabotage through compromised product quality. Concerns about malicious actors restrict business models and deter industry adoption and investment, especially those requiring secrecy around safety-critical components. In this paper, we analyze the threats to additive manufacturing system security using the Verification Evidence and Resilient Design in Anticipation of Cybersecurity Threats (VERDICT) tool, a model-based system engineering (MBSE) tool. First, we introduce a comprehensive set of attributes to characterize MBSE tools together with a survey of MBSE tools that support cyber analysis. Based on these attributes and the available tools, we select the relevant tool (i.e., VERDICT) and apply it to an example additive manufacturing system. The modeling and analysis are intended to show the functionality of the VERDICT tool in a research context. The signals, properties, and requirements enable the user to experiment with and illustrate the functionality of the tool. Finally, the paper introduces a novel approach for modeling the return on investment (ROI) for additive hardware cybersecurity investments that will lead to a cost-analysis integration with the VERDICT tool.
KW - additive manufacturing systems
KW - attack/defense tree
KW - cyber resiliency verification
KW - cybersecurity analysis
KW - model based architecture
UR - https://www.scopus.com/pages/publications/85145550449
UR - https://www.scopus.com/pages/publications/85145550449#tab=citedBy
U2 - 10.1145/3560833.3563566
DO - 10.1145/3560833.3563566
M3 - Conference contribution
AN - SCOPUS:85145550449
T3 - AMSec 2022 - Proceedings of the 2022 ACM CCS Workshop on Additive Manufacturing ,3D Printing Security, co-located with CCS 2022
SP - 3
EP - 13
BT - AMSec 2022 - Proceedings of the 2022 ACM CCS Workshop on Additive Manufacturing ,3D Printing Security, co-located with CCS 2022
T2 - 2022 ACM CCS Workshop on Additive Manufacturing ,3D Printing Security, AMSec 2022 - Co-located with CCS 2022
Y2 - 11 November 2022 through 11 November 2022
ER -