中文

面向 OT 场景下容器部署安全风险识别的本体化方法

软件工程 2026-01-08 v1 密码学与安全

摘要

在 operational technology (OT) 场景中,容器化应用通常需要获得 elevated privileges 才能访问低层网络接口或执行诸如应用监控等管理任务。这些权限降低了容器默认的隔离性,引入显著的安全风险。OT 容器部署的安全风险识别面临着混合 IT/OT 架构、碎片化的利益相关者知识以及持续系统变更等挑战。现有方法缺乏可重复性、跨场景的可解释性以及与部署 artefact 的技术集成。我们提出一种基于模型的方法,实现为 Container Security Risk Ontology (CSRO),集成五个关键领域:对抗行为、情境假设、攻击情景、风险评估规则和容器安全 artefact。我们在案例研究中评估了 CSRO,表明从 artefact 到风险等级的端到端形式化流程实现了自动化和可重复的风险识别。虽然 CSRO 当前仅关注技术层面的容器级防护措施,但其模块化和灵活的设计为将方法扩展到主机级和组织风险因素提供了坚实基础。

关键词

引用

@article{arxiv.2601.04010,
  title  = {An Ontology-Based Approach to Security Risk Identification of Container Deployments in OT Contexts},
  author = {Yannick Landeck and Dian Balta and Martin Wimmer and Christian Knierim},
  journal= {arXiv preprint arXiv:2601.04010},
  year   = {2026}
}

备注

Accepted for publication on the Software Engineering in Practice (SEIP) track of the Internation Conference on Software Engineering (ICSE'26)