Evaluation of Visual Notations as a Basis for ICS Security Design Decisions

For making informed security decisions during the design of industrial control systems (ICS), engineers need to process large amounts of security-relevant information outside their area of expertise. This problem moves the presentation of the security-relevant information into focus: security-releva...

Full description

Bibliographic Details
Main Authors: Sarah Fluchs, Rainer Drath, Alexander Fay
Format: Article
Language:English
Published: IEEE 2023-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/10021609/
_version_ 1811172288757760000
author Sarah Fluchs
Rainer Drath
Alexander Fay
author_facet Sarah Fluchs
Rainer Drath
Alexander Fay
author_sort Sarah Fluchs
collection DOAJ
description For making informed security decisions during the design of industrial control systems (ICS), engineers need to process large amounts of security-relevant information outside their area of expertise. This problem moves the presentation of the security-relevant information into focus: security-relevant engineering information must be presented to security decision-makers in a way that enables them to decide upon security measures to build a defensible system. Visual representations have the potential to effectively convey suchlike information, thus saving the engineers’ brain capacity for the security decision-making. However, research shows that this potential is only realized if the visualizations are carefully constructed for cognitive effectiveness. As a prerequisite for constructing a visual language for security engineering in the future, this paper explores two scientific questions: 1) what are the requirements for visualizing security-relevant engineering information in a way that enables engineers to make security decisions during ICS design? and 2) which existing visual languages meet (parts of) these requirements? The evaluation of existing visualizations reveals that there is a need for an improved, specialized visual language for security engineering that builds upon established engineering visualizations like piping and instrumentation diagrams and network maps, represents all security-relevant information as icons to achieve semantic transparency, and includes filtering mechanisms to reduce the complexity of each single diagram. The paper finishes with defining the main pillars of a future visual language that should allow ICS engineers to quickly capture security-relevant information and guide them through the process of selecting the right security measures to design a defensible ICS.
first_indexed 2024-04-10T17:27:26Z
format Article
id doaj.art-cd6ebd202da14b59b084dc288c3b8049
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-04-10T17:27:26Z
publishDate 2023-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-cd6ebd202da14b59b084dc288c3b80492023-02-04T00:00:08ZengIEEEIEEE Access2169-35362023-01-01119967999410.1109/ACCESS.2023.323832610021609Evaluation of Visual Notations as a Basis for ICS Security Design DecisionsSarah Fluchs0https://orcid.org/0000-0003-4730-0126Rainer Drath1https://orcid.org/0000-0003-1238-2571Alexander Fay2https://orcid.org/0000-0002-1922-654XAdmeritia GmbH, Langenfeld, GermanySchool of Engineering, Pforzheim University, Pforzheim, GermanyDepartment of Automation, Helmut Schmidt University, Hamburg, GermanyFor making informed security decisions during the design of industrial control systems (ICS), engineers need to process large amounts of security-relevant information outside their area of expertise. This problem moves the presentation of the security-relevant information into focus: security-relevant engineering information must be presented to security decision-makers in a way that enables them to decide upon security measures to build a defensible system. Visual representations have the potential to effectively convey suchlike information, thus saving the engineers’ brain capacity for the security decision-making. However, research shows that this potential is only realized if the visualizations are carefully constructed for cognitive effectiveness. As a prerequisite for constructing a visual language for security engineering in the future, this paper explores two scientific questions: 1) what are the requirements for visualizing security-relevant engineering information in a way that enables engineers to make security decisions during ICS design? and 2) which existing visual languages meet (parts of) these requirements? The evaluation of existing visualizations reveals that there is a need for an improved, specialized visual language for security engineering that builds upon established engineering visualizations like piping and instrumentation diagrams and network maps, represents all security-relevant information as icons to achieve semantic transparency, and includes filtering mechanisms to reduce the complexity of each single diagram. The paper finishes with defining the main pillars of a future visual language that should allow ICS engineers to quickly capture security-relevant information and guide them through the process of selecting the right security measures to design a defensible ICS.https://ieeexplore.ieee.org/document/10021609/Automation engineeringindustrial control system securitysecurity by designvisual language
spellingShingle Sarah Fluchs
Rainer Drath
Alexander Fay
Evaluation of Visual Notations as a Basis for ICS Security Design Decisions
IEEE Access
Automation engineering
industrial control system security
security by design
visual language
title Evaluation of Visual Notations as a Basis for ICS Security Design Decisions
title_full Evaluation of Visual Notations as a Basis for ICS Security Design Decisions
title_fullStr Evaluation of Visual Notations as a Basis for ICS Security Design Decisions
title_full_unstemmed Evaluation of Visual Notations as a Basis for ICS Security Design Decisions
title_short Evaluation of Visual Notations as a Basis for ICS Security Design Decisions
title_sort evaluation of visual notations as a basis for ics security design decisions
topic Automation engineering
industrial control system security
security by design
visual language
url https://ieeexplore.ieee.org/document/10021609/
work_keys_str_mv AT sarahfluchs evaluationofvisualnotationsasabasisforicssecuritydesigndecisions
AT rainerdrath evaluationofvisualnotationsasabasisforicssecuritydesigndecisions
AT alexanderfay evaluationofvisualnotationsasabasisforicssecuritydesigndecisions