Security Modelling for Cyber-Physical Systems: A Systematic Literature Review

S.-T. Huang, Christopher M. Poskitt, Lwin Khin Shar · ACM Transactions on Cyber-Physical Systems · 2025

Cyber-physical systems are at the intersection of digital technology and engineering domains, rendering them high-value targets of sophisticated and well-funded cybersecurity threat actors. Prominent cybersecurity attacks on cyber-physical systems have brought attention to the vulnerability of these systems and the inherent weaknesses of critical infrastructure reliant on them. Security modelling for cyber-physical systems is an important mechanism to systematically identify and assess vulnerabilities, threats and risks throughout system lifecycles, and to ultimately ensure system resilience, safety and reliability. This survey delves into state-of-the-art research on security modelling for cyber-physical systems, encompassing both threat and attack modelling. While these terms are sometimes used interchangeably, they are different concepts. This article elaborates on the differences between threat and attack modelling, examining their implications for cyber-physical system security. We conducted a systematic search that yielded 449 papers, from which 32 were selected and categorised into 3 clusters: those focused on threat modelling methods, attack modelling methods and literature reviews. Specifically, we sought to examine what security modelling methods exist today, and how they address real-world cybersecurity threats and attacker capabilities throughout the lifecycle of cyber-physical systems, which typically span longer durations compared to traditional IT systems. This article also highlights several limitations in existing research, wherein security models adopt simplistic approaches that do not adequately consider the dynamic, multi-layer, multi-path and multi-agent characteristics of real-world cyber-physical attacks.

Read the paper · More papers on PaperTik