论文标题

AM行业的安全意识状况:2020年调查

State of Security Awareness in the AM Industry: 2020 Survey

论文作者

Yampolskiy, Mark, Bates, Paul, Seifi, Mohsen, Shamsaei, Nima

论文摘要

由于在各种应用和业务模型中的增殖和采用日益增长的增殖和采用,增材制造业的安全性(AM)受到了越来越多的关注。但是,专注于制造业的AM社区与AM安全社区之间存在重大脱节,专注于确保这项高度计算机化的制造技术。为了弥合这一差距,我们调查了美国使AM社区的调查,总共提出了11个与安全有关的问题,旨在发现现有的担忧,姿势和期望。第一组问题旨在发现其中有多少组织使用AM,外包AM或提供AM作为服务。然后,我们询问了最大的安全问题,以及评估可能是谁的对手及其攻击动机的评估。然后,如果进行了任何安全风险评估,以及参与者组织与外部专家合作以确保AM,我们就提出了有关任何经验丰富的安全事件的问题。最后,我们询问是否实施了安全措施,如果是,它们是否属于一般的网络安全类别。在隶属于商业行业,机构和学术界的69名参与者中,有53位完成了整个调查。本文介绍了这项调查的结果,并提供了我们对AM安全姿势的评估。答案是我们可以预期的标签的混合物,“令人震惊但并不奇怪”,并且是完全出乎意料的。假设提供的答案在某种程度上代表了AM行业的当前状态,我们得出结论,该行业还没有准备好预防或检测研究文献中已证明的AM特定攻击。

Security of Additive Manufacturing (AM) gets increased attention due to the growing proliferation and adoption of AM in a variety of applications and business models. However, there is a significant disconnect between AM community focused on manufacturing and AM Security community focused on securing this highly computerized manufacturing technology. To bridge this gap, we surveyed the America Makes AM community, asking in total eleven AM security-related questions aiming to discover the existing concerns, posture, and expectations. The first set of questions aimed to discover how many of these organizations use AM, outsource AM, or provide AM as a service. Then we asked about biggest security concerns as well as about assessment of who the potential adversaries might be and their motivation for attack. We then proceeded with questions on any experienced security incidents, if any security risk assessment was conducted, and if the participants' organizations were partnering with external experts to secure AM. Lastly, we asked whether security measures are implemented at all and, if yes, whether they fall under the general cyber-security category. Out of 69 participants affiliated with commercial industry, agencies, and academia, 53 have completed the entire survey. This paper presents the results of this survey, as well as provides our assessment of the AM Security posture. The answers are a mixture of what we could label as expected, "shocking but not surprising," and completely unexpected. Assuming that the provided answers are somewhat representative to the current state of the AM industry, we conclude that the industry is not ready to prevent or detect AM-specific attacks that have been demonstrated in the research literature.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源