Marco Ehrlich

dblp:207/6864 · DBLP profile ↗
← Back
17ranked-venue papers
11as first author
8since 2021 · last 2025
0000-0003-1538-0547ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 17 · 11 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Automated Documentation of Security Risk Assessments with Large Language Models
abstract
The general development of Industry 4.0 and the highly dynamic threat landscape extend the need for continuous security engineering of industrial components, especially during the development phase. Security risk assessments play an important role to ensure the secure and safe development of Industrial Automation and Control Systems (IACSs), but they are based on sophisticated manual and typically time-consuming tasks for human experts. Therefore, this publication identifies and analyzes the information required to document the results of the security risk assessment throughout the development phase. Furthermore, the currently present concepts for documentation are integrated and aligned towards the initially automated and tool-based results by the utilization of Large Language Models (LLMs).
Marco Ehrlich, Lisa Gebauer, Uwe Mönks, Henning Trsek
ETFA1
2024 Evaluation of an Automated Security Risk Assessment Based on a Manual Reference
abstract
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are often neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. To relieve this situation and to increase the degree of automation of security risk assessments, a method for information and process modelling was developed in a previous work. The approach was also implemented prototypically as an expert system but has not been validated, yet. This work therefore presents the validation as an integral part of the overall evaluation of the automated security risk assessment concept. For a systematic validation, a reference security risk assessment is manually defined as a set of data for the comparison with the results of the automated expert system. In addition, the two main hypotheses with regard to the result quality and the process automation evaluated.
Marco Ehrlich, Georg Lukas, Lisa Gebauer, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich
ETFA1
2024 Concept for Software-Supported Automated Security Risk Assessments for Industrial Components
abstract
In view of the dynamic cybersecurity threat land-scape and the increasingly interconnected information technol-ogy (IT) and operational technology (OT) environments, the management of security risks to both IT and OT systems becomes paramount, including efficient and comprehensive risk assessment. Such risk assessments, however, require extensive manual work, the availability of trained security personnel as well as considerable time and financial resources. Additionally, a consistent quality of results often cannot be guaranteed due to a dependency on individual expert knowledge and experience. A promising approach to alleviate these challenges is to use software-based support to automate risk assessment processes and increase efficiency and consistency. This work proposes a con-cept for software-supported automated security risk assessments with a focus on industrial components and the manufacturing industry. It presents key challenges, solution approaches, and further research directions that need to be considered in order to practically implement the concept. Additionally, current research that is already in process towards a practical implementation and a preliminary software prototype are presented.
Lisa Gebauer, Marco Ehrlich, Dimitri Harder, Luca Schäfer, Henning Trsek, Natalia Moriz
ETFA2
2024 Requirements Analysis for the Evaluation of Automated Security Risk Assessments
abstract
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are mostly neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. Therefore, a method for information and process modelling regarding the automation of security risk assessments has been previously designed, but not yet evaluated. This work in progress begins the evaluation of the automated security risk assessment concept by investigating the related work and identifying the main deficits. The results include a requirements analysis for the verification and an outlook towards future evaluation aspects.
Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich
WFCS1
2023 Evaluation Concept for Prototypical Implementation towards Automated Security Risk Assessments
abstract
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of systems necessitate continuous security engineering. Therefore, this work in progress presents the specification and prototypical implementation for automated security risk assessments. In addition, an outlook towards the associated validation, verification, evaluation, and hypothesis testing is given.
Marco Ehrlich, Andre Bröring, Henning Trsek, Jürgen Jasperneite, Christian Diedrich
ETFA1
2023 Determining the Target Security Level for Automated Security Risk Assessments
abstract
Due to Industry 4.0 developments, the demanded modularity of manufacturing systems generates additional manual efforts for security experts to guarantee a secure operation. The rising utilization of information and the frequent changes of system structures necessitate a continuous and automated security engineering, especially by application of the mandatory security risk assessments. Collecting the required information for these assessments and formalising expert knowledge shall improve the security of modular manufacturing systems in the future. In order to automate the security risk assessment process, this work proposes a method to determine the Target Security Level (SL-T) in conformance to the IEC 62443 standard based on the MITRE ATT&CK framework and the Intel Threat Agent Library (TAL).
Marco Ehrlich, Andre Bröring, Christian Diedrich, Jürgen Jasperneite, Wolfgang Kastner, Henning Trsek
INDIN1
2022 Towards an Asset Administration Shell Integrity Verification Scheme
abstract
Integrity as one property of trustworthiness is an important aspect for the adoption of the Asset Administration Shell (AAS) as a data exchange format and source for data driven services. Until now, the AAS offers an access control solution as a preventive integrity measure. Nevertheless, preventive methods lack in detecting integrity violations due to accidental or malicious modifications from access permitted endpoints. This work in progress paper proposes a concept to complement the access control with a detective integrity measure. By signing submodels of the AAS, business partners along the life cycle can verify the integrity of the data inside the AAS. Therefore, a Certificates Submodel and a Signature Submodel are proposed in the concept to enable a flexible and interoperable integrity verification. In future work, the concept will be implemented and evaluated.
Andre Bröring, Marco Ehrlich, Lukasz Wisniewski, Henning Trsek, Stefan Heiss
ETFA2
2022 Investigation of Resource Constraints for the Automation of Industrial Security Risk Assessments
abstract
The current static risk assessment processes and concepts do not match the increasing requirements with regard to flexibility within the industrial automation domain. The amount of manual tasks and needed efforts for risk assessments are too high in order to adequately cover the rising rate of system reconfigurations. Analysing the typical risk assessment processes from the IEC 62443 will show resource constraints with regard to time, bottlenecks, and the main cost drivers. If the most rewarding process steps can be identified and automated, the overall performance of risk assessments can be enhanced to keep up with the demanded flexibility.
Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Christian Diedrich
WFCS1
2020 Towards Automated Security Evaluation within the Industrial Reference Architecture
abstract
The current developments towards the visions of Industrie 4.0 will create open and dynamic architectures being supervised by Industrial Automation and Control Systems. Due to this new connectivity and flexibility, future industrial production systems need to be inspected during all phases of the whole lifecycle from a security point of view as well. Frequent reconfiguration and adaptation based on smart services impose advanced requirements on the audits and certification with regard to security. To facilitate that, this work presents an approach for the modeling of security requirements and capabilities within the Industrial Reference Architecture and evaluates it based on the concrete system architectures of a number of industrial use cases. The result is the Sec4ICS tooling-based concept for the automated assessment of security-related functionalities within industrial systems.
Marco Ehrlich, Martin Gergeleit, Henning Trsek, Georg Lukas
ETFA1
2020 Controller of Controllers Architecture for Management of Heterogeneous Industrial Networks
abstract
Increasing heterogeneity of industrial network systems is a fact and the chances that in the future one communication standard will be able to fulfill the requirements of all possible applications are utopian. With the increasing number of communication systems, their management, configuration, and maintenance become a significant issue. Additionally, due to the increasing amount of network services and traffic, the management of available network resources and the possibility of delivering certain levels of communication quality of service, especially across different network solutions becomes a big challenge. Therefore, in this paper a Controller of Controllers (CoC) concept for management of heterogeneous industrial networks is proposed. The concept is designed to support still widely spread legacy fieldbus systems, different Ethernetbased industrial solutions, and potentially upcoming network technologies. The goal is achieved by leveraging state-of-theart architectural concepts such as software-defined networks, which allows for integration of abstract models in network management. The concept is described and discussed by way of a demonstrator concept for a heterogeneous system of fieldbus and Ethernet-based time-sensitive networks.
Ansah Frimpong, Santiago Soler Perez Olaya, Dennis Krummacker, Christoph Fischer, Alexander Winkel, René Guillaume, Lukasz Wisniewski, Marco Ehrlich, Waseem Mandarawi, Henning Trsek, Hermann de Meer, Martin Wollschlaeger, Hans D. Schotten, Jürgen Jasperneite
WFCS8
2020 Work-in-Progress: Semantic Knowledge Base as a Solution for Heterogeneous Industrial Network Management
abstract
The advent of Industry 4.0 brings the Internet of Things (IoT) and Cyber-Physical Systems (CPSs) inside the factory premise and made the boundaries between the information and operational technologies (IT & OT) obsolete. This, in turn, introduces the problem of interoperability due to the integration of multiple industrial protocols and technologies from various automation networks. The aim of this paper is to investigate this interoperability problem of heterogeneous network management and propose a semantic network knowledge base as a solution to it. It also describes a set of generic interface functions for data acquisition.
Mainak Majumder, Santiago Soler Perez Olaya, Marco Ehrlich, Lukasz Wisniewski, Jürgen Jasperneite, Martin Wollschlaeger
WFCS3
2020 Plug & Play Retrofitting Approach for Data Integration to the Cloud
abstract
Driven by rapid digitalisation, production systems are becoming more flexible and adaptable with the help of emerging concepts like the Internet of Things (IoT) and Industry 4.0. Often, these transformations are not fully implemented in Small and Medium-sized Enterprises (SMEs) due to the replacement cost of existing machines. This paper aims to develop a Plug & Play retrofitting platform, where Industry 4.0 compliant sensor systems can be attached, detected, and configured automatically to the existing production environment. The purpose of the retrofitting is to integrate the sensor system with a cloud platform that would provide persistent storage for sensor data as well as the functionalities to perform monitoring, analysis, and predictive learning.
Santosh Kumar Panda, Lukasz Wisniewski, Marco Ehrlich, Mainak Majumder, Jürgen Jasperneite
WFCS3
2019 Secure and Flexible Deployment of Industrial Applications inside Cloud-Based Environments
abstract
Future industrial production systems following the paradigms of Industrie 4.0 will be reconfigured frequently and new system configurations will be deployed automatically as part of the engineering processes. In order to keep pace with this requirement of increased flexibility, it will be needed to achieve the adequate security levels in an automated way and to reduce the current static procedures and manual efforts as much as possible. Therefore, a modelling of all security-related functionalities and capabilities is mandatory. This paper further describes an approach for such a modelling based on the IEC 62443 security standard and an implementation of an automated deployment of components inside an industrial environment established with the OASIS Tosca and Ansible tools. The first results of the whole tool chain are evaluated with a real-world use case of software deployment in a suitable lab environment.
Marco Ehrlich, Henning Trsek, Martin Gergeleit, Julius Paffrath, Kostyantyn Simkin, Jürgen Jasperneite
ETFA1
2019 Survey of Security Standards for an automated Industrie 4.0 compatible Manufacturing
abstract
Due to the dynamic nature of the Industrie 4.0 developments, future production systems will be reconfigured more frequently and new system configurations will be deployed automatically. In order to keep pace with this development, it will be required to observe and ensure the needed security functionalities and corresponding certifications in an automated way. This implies an improvement of today's static procedures and manual efforts as much as possible in favor of a dynamic standard establishment. Therefore, this paper evaluates the state of the art of the industrial security standardization landscape and proposes a concept for the automated support of certification processes with information from industrial communication networks in order to enhance the usability of the standards establishments and the certifications within organizations and companies, especially small and medium-sized enterprises.
Marco Ehrlich, Henning Trsek, Lukasz Wisniewski, Jürgen Jasperneite
IECON1
2018 Software- Defined Networking as an Enabler for Future Industrial Network Management
abstract
The overall Industry 4.0 (I4.0) developments combined with the disruptive process of IT-based digitalisation create a vast amount of new opportunities but also challenges for the industrial automation domain. The combination of hybrid (wired & wireless) communication architectures, already widely installed legacy technologies, new approaches, such as Time-Sensitive Networking (TSN) or 5G, and the general heterogeneity of the industrial landscape results in a high configuration complexity. This creates the necessity for future-proof industrial communication network management systems. Therefore, this paper summarises the current state of the art in this area in order to identify the specific requirements towards future industrial network management systems. The most promising candidate is the Software-Defined Networking (SDN) concept. To evaluate SDN as a possible enabler, specified industrial requirements are compared with the current technological and conceptual capabilities of SDN. In addition, drawbacks resulting in future research questions are identified.
Marco Ehrlich, Dennis Krummacker, Christoph Fischer, René Guillaume, Santiago Soler Perez Olaya, Ansah Frimpong, Hermann de Meer, Martin Wollschlaeger, Hans D. Schotten, Jürgen Jasperneite
ETFA1
2018 Pursuing the Vision of Industrie 4.0: Secure Plug-and-Produce by Means of the Asset Administration Shell and Blockchain Technology
abstract
The Plug-and-Produce concept requires that after connecting a new module to a system, the exchange of the configuration data takes place. As further operation of the system depends on this initialization procedure, it is necessary to ensure that the data presented by the system and the newly attached component is authentic. Therefore, we propose a new concept for secure Plug-and-Produce functionality, which exploits the combination of the Asset Administration Shell (AAS) and Blockchain technology. On the one hand, the AAS shall be responsible for presenting uniform and standardized configuration data as well as for storing and managing Blockchain. On the other, Blockchain shall ensure authenticity and integrity of the configuration data.
Dorota Lang, Maxim Friesen, Marco Ehrlich, Lukasz Wisniewski, Jürgen Jasperneite
INDIN3
2017 Automatic mapping of cyber security requirements to support network slicing in software-defined networks
abstract
The process of digitalisation has an advanced impact on social lives, state affairs, and the industrial automation domain. Ubiquitous networks and the increased requirements in terms of Quality of Service (QoS) create the demand for future-proof network management. Therefore, new technological approaches, such as Software-Defined Networks (SDN) or the 5G Network Slicing concept, are considered. However, the important topic of cyber security has mainly been ignored in the past. Recently, this topic has gained a lot of attention due to frequently reported security related incidents, such as industrial espionage, or production system manipulations. Hence, this work proposes a concept for adding cyber security requirements to future network management paradigms. For this purpose, various security related standards and guidelines are available. However, these approaches are mainly static, require a high amount of manual efforts by experts, and need to be performed in a steady manner. Therefore, the proposed solution contains a dynamic, machine-readable, automatic, continuous, and future-proof approach to model and describe cyber security QoS requirements for the next generation network management.
Marco Ehrlich, Lukasz Wisniewski, Henning Trsek, Daniel Mahrenholz, Jürgen Jasperneite
ETFA1