Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Operations security evaluation of IaaS-cloud backend for industry 4.0
University of Applied Sciences Burgenland, Eisenstadt.
University of Applied Sciences Burgenland, Eisenstadt.
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering, Embedded Internet Systems Lab. University of Applied Sciences Burgenland, Eisenstadt.ORCID iD: 0000-0003-2477-3692
Luleå University of Technology, Department of Computer Science, Electrical and Space Engineering, Embedded Internet Systems Lab. University of Applied Sciences Burgenland, Eisenstadt.
Show others and affiliations
2018 (English)In: CLOSER 2018: Proceedings of the 8th International Conference on Cloud Computing and Services Science / [ed] Ferguson D.,Helfert M.,Pahl C.,Munoz V.M., 2018, p. 392-399Conference paper, Published paper (Refereed)
Abstract [en]

The fast growing number of cloud based Infrastructure-as-a-Service instances raises the question, how the operations security depending on the underlying cloud computing infrastructure can be sustained and guaranteed. Security standards provide guidelines for information security controls applicable to the provision and use of the cloud services. The objectives of operations security are to support planning and sustaining of day-to-day processes that are critical with respect to security of information environments. In this work we provide a detailed analysis of ISO 27017 standard regarding security controls and investigate how well popular cloud platforms can cater for them. The resulting gap of support for individual security controls is furthermore compared with outcomes of recent cloud security research projects. Hence the contribution is twofold, first we identify a set of topics that still require research and development and secondly, as a practical output, we provide a comparison of popular industrial and open-source platforms focusing on private cloud environments, which are important for Industry 4.0 use cases.

Place, publisher, year, edition, pages
2018. p. 392-399
National Category
Other Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Industrial Electronics
Identifiers
URN: urn:nbn:se:ltu:diva-70237Scopus ID: 2-s2.0-85048945725ISBN: 9789897582950 (print)OAI: oai:DiVA.org:ltu-70237DiVA, id: diva2:1237004
Conference
8th International Conference on Cloud Computing and Services Science, CLOSER 2018, Funchal, Madeira, Portugal, 19-21 March 2018
Available from: 2018-08-07 Created: 2018-08-07 Last updated: 2021-10-02Bibliographically approved
In thesis
1. Security Standard Compliance in System of Systems
Open this publication in new window or tab >>Security Standard Compliance in System of Systems
2020 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

The world we live in is becoming digitalized by transforming our society and economyin an unpredicted way. Digital technologies are transforming products, manufacturingassets, and entire supply chains. These technologies revolutionize how organisations en-gage with customers, other partners, and society depending on the ability to connectpeople, technology, and processes. Distributed services through different platforms, or-ganisations, and even regions are becoming very common with the digital transformationof industrial processes. More and more systems are being constructed by interconnectingexisting and new independent systems. The transformation from traditional and isolatedsystems to connected components in a System of Systems (SoS), provides many advan-tages such as flexibility, efficiency, interoperability, and competitiveness. While it is clearthat digital technology will transform most industries, there are a number of challengesto be addressed, especially in terms of standards and security.In the past, providing a secure environment meant isolation from external access andproviding physical protection, usually based on proprietary standards. Nowadays, withthe development of state-of-the-art technologies, these systems have to meet and provideproof of fulfilling several requirements and involving many stakeholders. Thus, to assurethat organisations can move towards this multi-stakeholder cooperation, security is one ofthe challenges that need to be addressed. With the increasing number of devices, systems,and services in these complex systems and the number of standards and regulationsthey should fulfill, the need for automated standard compliance verification is of utmostimportance. Such verification will ensure that the components included in their businessprocesses comply with the imposed standards, laws and regulations.The research presented in this thesis targets the automated and continuous standardcompliance verification in SoS. Standard compliance verification provides evidence thatprocesses and their components satisfy the requirements defined by national and interna-tional standards. The thesis proposes an automated and continuous standard complianceverification framework that provides evidence if SoS components fulfill security standards’requirements based on extracted measurable indicator points. Since these systems evolveover time, the standard compliance is verified in design time and continuously monitoredand verified during run time after the SoS has been deployed.

Place, publisher, year, edition, pages
Luleå University of Technology, 2020
Series
Doctoral thesis / Luleå University of Technology 1 jan 1997 → …, ISSN 1402-1544
Keywords
Security, Standard, Security Standards, System of Systems, Industry 4.0, Digitization, Standard Compliance, Security Standards, Standardization Bodies, Internet of Things, Cyber Physical Systems
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Research subject
Electronic systems
Identifiers
urn:nbn:se:ltu:diva-80454 (URN)978-91-7790-632-2 (ISBN)978-91-7790-633-9 (ISBN)
Public defence
2020-11-18, A1543, 13:00 (English)
Opponent
Supervisors
Available from: 2020-08-20 Created: 2020-08-18 Last updated: 2020-10-28Bibliographically approved
2. Autonomic Management of System of Systems Security
Open this publication in new window or tab >>Autonomic Management of System of Systems Security
2021 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

The digitalization of manufacturing industry and the profound reliance on interconnected System of Systems (SoS) is demanding for innovative solutions that can handle production processes, while making use of the new data that is being generated by various connected devices. Innovations based on collecting, evaluating, and using this data can improve existing processes and create new business models. Although this is beneficial to the user, at the same time, it opens the way for adversaries to exploit new vulnerabilities. Since the factories are exposing their internal production processes to the internet, security is one of the challenges that should be addressed in this new digitalization era, referred to as the fourth industrial revolution or Industry 4.0. Furthermore, security cannot be seen as independent from other non-functional requirements of SoS, e.g. performance or safety aspects. Addressing security without risking to negatively affect other aspects and vice versa is a main concern for such interconnected systems.

This thesis outlines the progress made towards security management and mitigation in SoS. It proposes an automated and secure onboarding procedure, which is required to introduce a new device in a SoS environment without compromising the already on-boarded devices and the underlying infrastructure. The proposed procedure establishes a chain of trust from the hardware device to its hosted application systems and their provided services by creating a chain of digital certificates. Thus, it allows to rely on the information on which “smart” decisions are being based, while ensuring a secure and trusted communication between the interacting systems.

Even with security controls in place, e.g. the automated onboarding procedure, maintaining a required security level for the SoS as a whole is difficult due to uncertainties that may occur at runtime. Uncertainties may occur due to internal factors, e.g. malfunction of a system, or external factors, e.g. malicious attacks. One approach that can tackle these uncertainties at run time and manage trade-offs between security and other non-functional requirements is self-adaptation. Self-adaptation enables a system to adapt in the face of such uncertainties without human intervention.

This thesis proposes a generic autonomic management system aimed to support the engineers in building self-adaptive systems that should cope with dynamic changes of the environment and system itself, while considering the expected rapid advances of system attacks. Given its generic property, the system can be reused and extended for a variety of use cases without requiring major modifications. This will reduce the software engineering effort needed to implement the generic control mechanisms. A prototype of the system has been implemented and tested.

Place, publisher, year, edition, pages
Luleå University of Technology, 2021
Series
Doctoral thesis / Luleå University of Technology 1 jan 1997 → …, ISSN 1402-1544
Keywords
System of Systems, Security, Self-Adaptation, Autonomic Management, Eclipse Arrowhead
National Category
Computer Sciences
Research subject
Cyber-Physical Systems
Identifiers
urn:nbn:se:ltu:diva-87316 (URN)978-91-7790-942-2 (ISBN)978-91-7790-943-9 (ISBN)
Public defence
2021-11-17, E632, Luleå, 10:00 (English)
Opponent
Supervisors
Available from: 2021-10-04 Created: 2021-10-02 Last updated: 2022-01-03Bibliographically approved

Open Access in DiVA

No full text in DiVA

Scopus

Authority records

Bicaku, AniMaksuti, Silia

Search in DiVA

By author/editor
Bicaku, AniMaksuti, Silia
By organisation
Embedded Internet Systems Lab
Other Electrical Engineering, Electronic Engineering, Information Engineering

Search outside of DiVA

GoogleGoogle Scholar

isbn
urn-nbn

Altmetric score

isbn
urn-nbn
Total: 163 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf