security//cyber-physical security
Cyber-physical security is the study and practice of defending systems whose computers act on the physical world (plants, grids, vehicles, drone fleets) against attacks whose effect is physical damage rather than stolen data, and it exists because in a cyber-physical system an intrusion into the network can end as a burst pipe or a crashed aircraft. In this sense the word *security* means protecting the machine from people, while *safety* means protecting people from the machine (functional safety, IEC 61508). In industrial automation the reference standard for the first is IEC 62443.
Cyber-physical security is the study and practice of defending systems whose computers act on the physical world (plants, grids, vehicles, drone fleets) against attacks whose effect is physical damage rather than stolen data, and it exists because in a cyber-physical system an intrusion into the network can end as a burst pipe or a crashed aircraft. In this sense the word security means protecting the machine from people, while safety means protecting people from the machine (functional safety, IEC 61508). In industrial automation the reference standard for the first is IEC 62443.
An attacker can cut communication, inject false values into measurements or commands (false data injection), or replay data recorded while all was well (replay attack); in a fleet, impersonate a node or many (Sybil attack) or fake the satellite signals everyone navigates by (GNSS spoofing). An attack is a fault with intent, and the intent changes everything. A bearing does not know there is a CUSUM watching it; a competent attacker does, and shapes the attack so that the residual stays in its band while the system is pushed, little by little, where the attacker wants (stealthy attack).
An attacker is a fault that knows your detector.
Stuxnet, discovered in 2010, altered the PLC programs driving uranium centrifuges, forcing speeds that damaged them while showing the operators normal values recorded earlier; the operators' residuals were perfect because the attacker controlled both terms of the subtraction. Diagnosis designed for random faults has to be redesigned for an opponent.
The defences lean on what the attacker does not know or control. Independent physical measurements outside the network; many cross-relations, because faking one value is easy and faking twenty that stay consistent with the physics is hard (analytical redundancy); networks divided into zones joined by controlled conduits, the network segmentation of IEC 62443; and a safety instrumented system wired apart, which trips on physical limits without asking the control software. That Triton, found in 2017, targeted exactly such systems at a petrochemical plant says how much that last layer is worth (defense in depth).
Messages between machines need authentication: I am drone 7 proves nothing unless the message is signed and the keys are managed (MAVLink 2 supports message signing). Most real incidents are stopped earlier, by not exposing a PLC to the internet, removing default passwords and segmenting the network.
Against replayed measurements, physical watermarking checks that a secret signal added to the actuation shows up in the outputs, which no recording can fake. What happens after an attack gets through is the subject of resilient control.