Architectural Pen-Test Generation and Vulnerability Prediction for Cyber-Physical Systems
Tobias M. Walter · 2022
The security of cyber-physical systems (CPSs) gains in significance as they become more open and rely on communication. Penetration testing is a technique to assess the security of such systems. However, existing techniques depend on the experience and domain knowledge of the penetration tester. This paper outlines ideas for supporting penetration testers to reduce the influence of the experience and knowledge on the results of a pen test. Our goal is to generate attack paths and test cases based on a software architecture during design phase. The attack paths and test cases are used to support pen testers in conducting tests on a system under test (SUT) once the system is completely developed. Furthermore, we intend to use the generated test cases to analyze changes made by the software architect during the design phase. Our goal here is to provide feedback in terms of a vulnerability prediction. The prediction supports the software architect in making design decisions towards more secure software architectures.