Skip to main content

31.01.2022

IT Availability Risks in Smart Factory Networks – Analyzing the Effects of IT Threats on Production Processes Using Petri Nets

verfasst von: Stephan Berger, Christopher van Dun, Björn Häckel

Erschienen in: Information Systems Frontiers

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

In manufacturing, concepts like the Internet of Things or Cyber-physical Systems accelerate the development from traditional production facilities towards smart factories. Thereby, emerging digital technologies increasingly connect information networks with production processes, forming complex smart factory networks (SFNs). Due to their reliance on information flows and the high degree of cross-linking, SFNs are, in particular, vulnerable to IT availability risks caused by attacks and errors. Against this backdrop, we present a modelling approach for analyzing the effects of IT threats on production processes. Based on Petri Nets, we provide modular SFN components for modelling SFN architectures and for simulating stochastic attack and error propagation. With this, we support the analysis and comparison of different SFN architectures regarding spreading effects, availability of information and production components, and associated effects on productivity. Our approach enables and serves as a foundation for decision support on SFN layouts from a risk perspective and the derivation of IT security mitigation measures in both research and practice. We evaluate our artefact by implementing and applying a software prototype in artificial and real-life settings.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Anhänge
Nur mit Berechtigung zugänglich
Literatur
Zurück zum Zitat van der Aalst, W.M.P. (1993): Interval timed coloured petri nets and their analysis. In: 1993 Intl Conf on Application and Theory of Petri Nets, S. 453–472. van der Aalst, W.M.P. (1993): Interval timed coloured petri nets and their analysis. In: 1993 Intl Conf on Application and Theory of Petri Nets, S. 453–472.
Zurück zum Zitat Amiri, Amin., Cavusoglu, Hasan., Benbasat, Izak. (2014). When is IT Unavailability a Strategic Risk?: A Study in the Context of Cloud Computing. In: ICIS. Amiri, Amin., Cavusoglu, Hasan., Benbasat, Izak. (2014). When is IT Unavailability a Strategic Risk?: A Study in the Context of Cloud Computing. In: ICIS.
Zurück zum Zitat Atamli, A. W., Martin, A., (2014) Threat-Based Security Analysis for the Internet of Things. In: 2014 Intl Workshop on Secure IoT, S. 35–43. Atamli, A. W., Martin, A., (2014) Threat-Based Security Analysis for the Internet of Things. In: 2014 Intl Workshop on Secure IoT, S. 35–43.
Zurück zum Zitat Brettel, M., Friederichsen, N., Keller, M., & Rosenberg, M. (2014). How virtualization, decentralization and network building change the manufacturing landscape: An industry 4.0 perspective. Intl Journal of Information & Communication Engineering, 8(1), 1–8. https://doi.org/10.5281/zenodo.1336426 Brettel, M., Friederichsen, N., Keller, M., & Rosenberg, M. (2014). How virtualization, decentralization and network building change the manufacturing landscape: An industry 4.0 perspective. Intl Journal of Information & Communication Engineering, 8(1), 1–8. https://​doi.​org/​10.​5281/​zenodo.​1336426
Zurück zum Zitat Broy, M.; Cengarle, M. V.; Geisberger, E. (2012): Cyber-Physical Systems: Imminent Challenges. In: Radu Calinescu and David Garlan (Hg.): Large-scale complex IT systems. Development, operation and management, Bd. 7539. Springer, S. 1–28. Broy, M.; Cengarle, M. V.; Geisberger, E. (2012): Cyber-Physical Systems: Imminent Challenges. In: Radu Calinescu and David Garlan (Hg.): Large-scale complex IT systems. Development, operation and management, Bd. 7539. Springer, S. 1–28.
Zurück zum Zitat Cardenas, A. A.; Amin, S.; Sastry, S. (2008): Secure Control: Towards Survivable Cyber-Physical Systems. In: 2008 Intl Conference on Distributed Computing Systems, S. 495–500. Cardenas, A. A.; Amin, S.; Sastry, S. (2008): Secure Control: Towards Survivable Cyber-Physical Systems. In: 2008 Intl Conference on Distributed Computing Systems, S. 495–500.
Zurück zum Zitat Cardenas, A. A.; Amin, S..; Sinopoli, B..; Giani, A.; Perrig, A.; Sastry, S. (2009): Challenges for Securing Cyber Physical Systems. In: Workshop on Future Directions in Cyber-Physical Systems Securiy, S. 1–4. Cardenas, A. A.; Amin, S..; Sinopoli, B..; Giani, A.; Perrig, A.; Sastry, S. (2009): Challenges for Securing Cyber Physical Systems. In: Workshop on Future Directions in Cyber-Physical Systems Securiy, S. 1–4.
Zurück zum Zitat Christensen, S., & Hansen, N. D. (1993). Coloured Petri nets extended with place capacities, test arcs and inhibitor arcs. In M. A. Marsan (Ed.), Application and theory of Petri. Springer. Christensen, S., & Hansen, N. D. (1993). Coloured Petri nets extended with place capacities, test arcs and inhibitor arcs. In M. A. Marsan (Ed.), Application and theory of Petri. Springer.
Zurück zum Zitat Danziger, M., Shekhtman, L., Bashan, A., Berezin, Y., & Havlin, S. (2016). Vulnerability of interdependent networks and networks of networks. In Garas (Ed.), Interconnected networks (pp. 79–99). Springer.CrossRef Danziger, M., Shekhtman, L., Bashan, A., Berezin, Y., & Havlin, S. (2016). Vulnerability of interdependent networks and networks of networks. In Garas (Ed.), Interconnected networks (pp. 79–99). Springer.CrossRef
Zurück zum Zitat Dempsey, K.; Chawla, N. S.; Johnson, A.; Johnston, R.; Jones, A. C.; Orebaugh, A. et al. (2011): Information Security Continuous Monitoring for Federal information Systems and Organizations. National Institute of Standards and Technology. U.S. Department of Commerce. Dempsey, K.; Chawla, N. S.; Johnson, A.; Johnston, R.; Jones, A. C.; Orebaugh, A. et al. (2011): Information Security Continuous Monitoring for Federal information Systems and Organizations. National Institute of Standards and Technology. U.S. Department of Commerce.
Zurück zum Zitat Desel, J., Esparza, J. (1995). Free choice Petri nets. In: Cambridge tracts in theoretical computer science. Desel, J., Esparza, J. (1995). Free choice Petri nets. In: Cambridge tracts in theoretical computer science.
Zurück zum Zitat Dotoli, M.; Fanti, M. P. (2005) A Generalized Stochastic Petri Net Model for Management of Distributed Manufacturing Systems. In: 2005 44th IEEE Conf on Decision & Control, S. 2125–2130. Dotoli, M.; Fanti, M. P. (2005) A Generalized Stochastic Petri Net Model for Management of Distributed Manufacturing Systems. In: 2005 44th IEEE Conf on Decision & Control, S. 2125–2130.
Zurück zum Zitat Dufourd, C., Finkel, A., & Schnoebelen, P. (1998). Reset nets between decidability and undecidability. In K. G. Larsen, S. Skyum, & G. Winskel (Eds.), Automata, languages and programming (pp. 103–115). Springer.CrossRef Dufourd, C., Finkel, A., & Schnoebelen, P. (1998). Reset nets between decidability and undecidability. In K. G. Larsen, S. Skyum, & G. Winskel (Eds.), Automata, languages and programming (pp. 103–115). Springer.CrossRef
Zurück zum Zitat Erdős, P., & Rényi, A. (1960). On the evolution of random graphs. Publication of the Mathematical Institute of the Hungarian Academy of Sciences, 5(1), 17–60. Erdős, P., & Rényi, A. (1960). On the evolution of random graphs. Publication of the Mathematical Institute of the Hungarian Academy of Sciences, 5(1), 17–60.
Zurück zum Zitat Häckel, B.; Übelhör, J. (2017): Development of Dynamic Key Figures for the Identification of Critical Components in Smart Factory Information Networks. In: ECIS 2017 25, S. 2767–2776. Häckel, B.; Übelhör, J. (2017): Development of Dynamic Key Figures for the Identification of Critical Components in Smart Factory Information Networks. In: ECIS 2017 25, S. 2767–2776.
Zurück zum Zitat Hermann, M.; Pentek, T.; Otto, B. (2016): Design Principles for Industrie 4.0 Scenarios. In: 49th Hawaii International Conference on System Sciences, S. 3928–3937. Hermann, M.; Pentek, T.; Otto, B. (2016): Design Principles for Industrie 4.0 Scenarios. In: 49th Hawaii International Conference on System Sciences, S. 3928–3937.
Zurück zum Zitat Hevner, A. R. (2007). A three-cycle view of design science research. Scandinavian Journal of Information Systems, 19(2), 87–92. Hevner, A. R. (2007). A three-cycle view of design science research. Scandinavian Journal of Information Systems, 19(2), 87–92.
Zurück zum Zitat Iivari, J. (2007). A paradigmatic analysis of information systems as a design science. Scandinavian Journal of Information Systems, 19(2), 39–64. Iivari, J. (2007). A paradigmatic analysis of information systems as a design science. Scandinavian Journal of Information Systems, 19(2), 39–64.
Zurück zum Zitat Jensen, K. (1987). Coloured Petri nets. In G. Rozenberg (Ed.), Advances in Petri nets (254th ed., pp. 248–299). Springer (Lecture Notes in Computer Science). Jensen, K. (1987). Coloured Petri nets. In G. Rozenberg (Ed.), Advances in Petri nets (254th ed., pp. 248–299). Springer (Lecture Notes in Computer Science).
Zurück zum Zitat Jensen, K. (1991): Coloured Petri Nets: A High Level Language for System Design and Analysis. In: Jensen (Hg.): High-level Petri nets, S. 44–119. Jensen, K. (1991): Coloured Petri Nets: A High Level Language for System Design and Analysis. In: Jensen (Hg.): High-level Petri nets, S. 44–119.
Zurück zum Zitat Kämper, S. (1991). On the appropriateness of Petri nets in model building and simulation. Systems Analysis Modelling Simulation, 8(9), 689–714. Kämper, S. (1991). On the appropriateness of Petri nets in model building and simulation. Systems Analysis Modelling Simulation, 8(9), 689–714.
Zurück zum Zitat Krueger, R. A., & Casey, M. A. (2014). Focus groups. A practical guide for applied research (5th ed.). SAGE. Krueger, R. A., & Casey, M. A. (2014). Focus groups. A practical guide for applied research (5th ed.). SAGE.
Zurück zum Zitat de La Mota, Flores, I., Guasch, A., Piera, A. M., & Mujica, M. M. (2017). Robust modelling and simulation. Springer International Publishing.CrossRef de La Mota, Flores, I., Guasch, A., Piera, A. M., & Mujica, M. M. (2017). Robust modelling and simulation. Springer International Publishing.CrossRef
Zurück zum Zitat Lee, E. A., (2008) Cyber Physical Systems: Design Challenges. In: IEEE Intl Symposium on Object Oriented Real-Time Distributed Computing, 363–369. Lee, E. A., (2008) Cyber Physical Systems: Design Challenges. In: IEEE Intl Symposium on Object Oriented Real-Time Distributed Computing, 363–369.
Zurück zum Zitat Lucke, D., Constantinescu, C., & Westkämper, E. (2008). Smart factory - a step towards the next generation of manufacturing. In M. Mitsuishi (Ed.), Manufacturing systems and Technologies for the new Frontier (pp. 115–118). Springer.CrossRef Lucke, D., Constantinescu, C., & Westkämper, E. (2008). Smart factory - a step towards the next generation of manufacturing. In M. Mitsuishi (Ed.), Manufacturing systems and Technologies for the new Frontier (pp. 115–118). Springer.CrossRef
Zurück zum Zitat March, S. T., & Storey, V. C. (2008). Design science in the information systems discipline. An introduction to the special issue on design science research. MIS Quarterly, 32(4), 725–730.CrossRef March, S. T., & Storey, V. C. (2008). Design science in the information systems discipline. An introduction to the special issue on design science research. MIS Quarterly, 32(4), 725–730.CrossRef
Zurück zum Zitat Miehle, D.; Häckel, B.; Pfosser, S.; Übelhör, J. (2019): Modeling IT Availability Risks in Smart Factories: a Stochastic Petri Nets Approach. In: Business & Information Systems Engineering. Miehle, D.; Häckel, B.; Pfosser, S.; Übelhör, J. (2019): Modeling IT Availability Risks in Smart Factories: a Stochastic Petri Nets Approach. In: Business & Information Systems Engineering.
Zurück zum Zitat Nawir, M.Amir, A.; Yaakob, N.; Lynn, O. B. (2016): Internet of Things (IoT): Taxonomy of security attacks. In: 2016 3rd Intl Conference on Electronic Design, S. 321–326. Nawir, M.Amir, A.; Yaakob, N.; Lynn, O. B. (2016): Internet of Things (IoT): Taxonomy of security attacks. In: 2016 3rd Intl Conference on Electronic Design, S. 321–326.
Zurück zum Zitat Petri, C. A. (1966). Communication with automata. Diploma thesis. Technical University of Darmstadt. Petri, C. A. (1966). Communication with automata. Diploma thesis. Technical University of Darmstadt.
Zurück zum Zitat Pries-Heje, J.; Baskerville, R.; Venable, J. R. (2008): Strategies for Design Science Research Evaluation. In: European Conf on Information Systems, S. 255–266. Pries-Heje, J.; Baskerville, R.; Venable, J. R. (2008): Strategies for Design Science Research Evaluation. In: European Conf on Information Systems, S. 255–266.
Zurück zum Zitat Ramchandani, C. (1973): Analysis of Asynchronos Concurrent Systems by Timed Petri Nets. Diss. Massachusetts Institute of Technology. Ramchandani, C. (1973): Analysis of Asynchronos Concurrent Systems by Timed Petri Nets. Diss. Massachusetts Institute of Technology.
Zurück zum Zitat Sadeghi, A-R.; Wachsmann, C.; Waidner, M. (2015): Security and privacy challenges in industrial internet of things. In: 52nd ACM/EDAC/IEEE Design Automation Conference, S. 1–6. Sadeghi, A-R.; Wachsmann, C.; Waidner, M. (2015): Security and privacy challenges in industrial internet of things. In: 52nd ACM/EDAC/IEEE Design Automation Conference, S. 1–6.
Zurück zum Zitat Salfner, F.; Wolter, K. (2009): A Petri net model for service availability in redundant computing systems. In: Manuel D. Rossetti (Hg.): Proceedings of the 2009 Winter Simulation Conference. 2009 Winter Simulation Conference. Austin. IEEE, S. 819–826. Salfner, F.; Wolter, K. (2009): A Petri net model for service availability in redundant computing systems. In: Manuel D. Rossetti (Hg.): Proceedings of the 2009 Winter Simulation Conference. 2009 Winter Simulation Conference. Austin. IEEE, S. 819–826.
Zurück zum Zitat Selic, B., & Gérard, S. (2013). Modeling and analysis of real-time and embedded systems with UML and MARTE. Developing cyber-physical systems. Elsevier Science (The MK / OMG Press). Selic, B., & Gérard, S. (2013). Modeling and analysis of real-time and embedded systems with UML and MARTE. Developing cyber-physical systems. Elsevier Science (The MK / OMG Press).
Zurück zum Zitat Sonnenberg, C.; Vom Brocke, J. (2012): Evaluations in the Science of the Artificial – Reconsidering the Build-Evaluate Pattern in Design Science Research. In: 7th DESRIST Conference, S. 381–397. Sonnenberg, C.; Vom Brocke, J. (2012): Evaluations in the Science of the Artificial – Reconsidering the Build-Evaluate Pattern in Design Science Research. In: 7th DESRIST Conference, S. 381–397.
Zurück zum Zitat Tsinarakis, G. J.; Valavanis, K. P.; Tsourveloudis, N. C.: (2003) Modular Petri net based modeling, analysis and synthesis of dedicated production systems. In: Intl Conference on Robotics S. 3559–3564. Tsinarakis, G. J.; Valavanis, K. P.; Tsourveloudis, N. C.: (2003) Modular Petri net based modeling, analysis and synthesis of dedicated production systems. In: Intl Conference on Robotics S. 3559–3564.
Zurück zum Zitat Valk, Rüdiger (1981): Generalizations of Petri nets. In: Gruska, Chytil (Hg.) Mathematical foundations of computer science, Bd. 118, S. 140–155. Valk, Rüdiger (1981): Generalizations of Petri nets. In: Gruska, Chytil (Hg.) Mathematical foundations of computer science, Bd. 118, S. 140–155.
Zurück zum Zitat Vavra, Jan; Hromada, Martin (2015): An evaluation of cyber threats to industrial control systems. In: 2015 Intl Conference on Model Transformation, S. 1–5. Vavra, Jan; Hromada, Martin (2015): An evaluation of cyber threats to industrial control systems. In: 2015 Intl Conference on Model Transformation, S. 1–5.
Zurück zum Zitat Venable, J., Pries-Heje, J., & Baskerville, R (2012). A comprehensive framework for evaluation in design science research. Design Science Research in Information Systems, 7286, 423–438. Venable, J., Pries-Heje, J., & Baskerville, R (2012). A comprehensive framework for evaluation in design science research. Design Science Research in Information Systems, 7286, 423–438.
Zurück zum Zitat van der Zee, Durk-Jouke (2009): Building Insightful Simulation Models Using Formal Approaches. A Case Study On Petri Nets. In: Manuel D. Rossetti (eds.): Proceedings of the 2009 Winter Simulation Conference. 2009 Winter Simulation Conference. Austin. IEEE, S. 886–898. van der Zee, Durk-Jouke (2009): Building Insightful Simulation Models Using Formal Approaches. A Case Study On Petri Nets. In: Manuel D. Rossetti (eds.): Proceedings of the 2009 Winter Simulation Conference. 2009 Winter Simulation Conference. Austin. IEEE, S. 886–898.
Zurück zum Zitat Zhou, M., & Venkatesh, K. (2000). Modeling, simulation and control of flexible manufacturing systems. In A petri net approach (p. 6). World Scientific (Series in intelligent control and intelligent automation). Zhou, M., & Venkatesh, K. (2000). Modeling, simulation and control of flexible manufacturing systems. In A petri net approach (p. 6). World Scientific (Series in intelligent control and intelligent automation).
Metadaten
Titel
IT Availability Risks in Smart Factory Networks – Analyzing the Effects of IT Threats on Production Processes Using Petri Nets
verfasst von
Stephan Berger
Christopher van Dun
Björn Häckel
Publikationsdatum
31.01.2022
Verlag
Springer US
Erschienen in
Information Systems Frontiers
Print ISSN: 1387-3326
Elektronische ISSN: 1572-9419
DOI
https://doi.org/10.1007/s10796-022-10243-y

Premium Partner