Björn Leander

dblp:246/5620 · DBLP profile ↗
← Back
11ranked-venue papers
8as first author
8since 2021 · last 2026
0000-0003-2488-5774ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 6 first-author · 6 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Remote Attestation for Secure Industrial Device Onboarding
Volodymyr Trykoz, Björn Leander, Saad Mubeen, Mohammad Ashjaei
SAFECOMP2
2025 Towards Security Architecture Modeling for Modular Automation Systems
abstract
Software and system architecture modeling is a well-established technique for addressing design-time challenges and enabling validation early in the system and software development process. However, software and system modeling has not been as widely used in automation systems as it has been in the automotive industry. In addition to validating functional properties through modeling, security properties and features can be evaluated in the modeling phase. This paper provides a brief overview of existing modeling approaches for future automation systems, known as modular automation, that support security modeling and analysis. Modular automation refers to a new trend in automation in which various modules are developed in advance and integrated to build an automation system. Moreover, we study the gaps and missing components of the existing modeling approaches via a use case demonstration. Our study shows that the current state of automation and control system modeling has several limitations that require urgent attention.
Volodymyr Trykoz, Björn Leander, Saad Mubeen, Mohammad Ashjaei
ETFA2
2024 Redundancy Link Security Analysis: An Automation Industry Perspective
abstract
Industrial automation and control systems are responsible for running our most important infrastructures, providing electricity and clean water, producing medicine and food, along with many other services and products we take for granted. The safe and secure operation of these systems is therefore of great importance. Reliability is a fundamental requirement, with spatial controller redundancy being one important fault-tolerance mechanism. In current control system solutions, controller redundancy is implemented using state and heartbeat transfer communicated over dedicated physical links, based on an assumption of implicit trust. However, with the emerging network-centric control strategies there is a desire to transition into dynamic redundancy scenarios, where such dedicated links are unfeasible. In this paper, an approach for a threat-model based security analysis is presented from the perspective of the automation industry. The approach is applied to the communication links used for supporting control system redundancy within a network-centric architecture.
Björn Leander, Bjarne Johansson, Saad Mubeen, Mohammad Ashjaei, Tomas Lindström
ETFA1
2023 Dependability and Security Aspects of Network-Centric Control
abstract
Industrial automation and control systems are responsible for running our most important infrastructures, providing electricity and clean water, producing medicine and food, along with many other services and products we take for granted. The safe and secure operation of these systems is therefore of great importance.One of the emerging trends in industrial automation systems is the transition from static hierarchical controller-centric systems to flexible network-centric systems. This transition has a great impact on the characteristics of industrial automation systems. In this article we describe the network-centric design strategy for industrial automation systems and describe the impact on dependability and security aspects that this strategy brings, looking at both challenges and possibilities.
Björn Leander, Bjarne Johansson, Tomas Lindström, Olof Holmgren, Thomas Nolte, Alessandro Vittorio Papadopoulos
ETFA1
2023 Access Control Enforcement Architectures for Dynamic Manufacturing Systems
abstract
Industrial control systems are undergoing a trans-formation driven by business requirements as well as technical advances, aiming towards increased connectivity, flexibility and high level of modularity, that implies a need to revise existing cybersecurity measures. Access control, being one of the major security mechanisms in any system, is largely affected by these advances.In this article we investigate access control enforcement architectures, aiming at the principle of least privilege1in dynamically changing access control scenarios of dynamic manufacturing systems. Several approaches for permission delegation of dynamic access control policy decisions are described. We present an implementation using the most promising combination of architecture and delegation mechanism for which available industrial standards are applicable.
Björn Leander, Aida Causevic, Tomas Lindström, Hans A. Hansson
ICSA1
2023 Enhanced Simulation Environment to Support Research in Modular Manufacturing Systems
abstract
Modular automation provides a challenge for traditional physics simulators, especially if they are used as a simulator in the loop of a development or research project looking at behavior from a systems level. In this paper, we present extensions of a previously developed simulation environment that is tailored to provide these characteristics. The extensions include simulation engine level improvements, such as including better modeling of the material flow, and sensor anomaly injections to model sensor faults or tampering, as well as system-level enhancements and functionality including certificate handling and anomaly detection methods using machine learning. This simulation environment has proven useful for education as well as research and engineering work, and with the provided extensions several new directions of use can be envisioned. The system is demonstrated in the use case of a modular ice-cream factory, including all the new and enhanced functionalities.
Björn Leander, Tijana Markovic, Miguel León Ortiz
IECON1
2022 Simulation Environment for Modular Automation Systems
abstract
When developing products or performing experimental research studies, the simulation of physical or logical systems is of great importance for evaluation and verification purposes. For research-, and development-related distributed control systems, there is a need to simulate common physical environments with separate interconnected modules independently controlled, and orchestrated using standardized network communication protocols.The simulation environment presented in this paper is a bespoke solution precisely for these conditions, based on the Modular Automation design strategy. It allows easy configuration and combination of simple modules into complex production processes, with support for individual low-level control of modules, as well as recipe-orchestration for high-level coordination. The use of the environment is exemplified in a configuration of a modular ice-cream factory, used for cybersecurity-related research.
Björn Leander, Tijana Markovic, Aida Causevic, Tomas Lindström, Hans A. Hansson, Sasikumar Punnekkat
IECON1
2021 A Questionnaire Study on the Use of Access Control in Industrial Systems
abstract
Industrial systems have traditionally been kept isolated from external networks. However, business benefits are pushing for a convergence between the industrial systems and new information technology environments such as cloud computing, as well as higher level of connectivity between different systems. This makes cybersecurity a growing concern for industrial systems. In strengthening security, access control is a fundamental mechanisms for providing security in these systems. However, access control is relatively immature in traditional industrial systems, as compared to modern IT systems, and organizations' adherence to an established cybersecurity standard or guideline can be a deciding factor for choices of access control techniques used. This paper presents the results of a questionnaire study on the usage of access control within industrial system that are being developed, serviced or operated by Swedish organizations, contrasted to their usage of cybersecurity standards and guidelines. To be precise, the article focuses on two fundamental requirements of cybersecurity: identification and authentication control, and presents related findings based on a survey of the Swedish industry. The goal of the study is breaching the gap between the current state and the requirements of emerging systems with regards to access control.
Björn Leander, Aida Causevic, Tomas Lindström, Hans A. Hansson
ETFA1
2019 Applicability of the IEC 62443 standard in Industry 4.0 / IIoT
abstract
Today's industrial automation systems are undergoing a digital transformation that implies a shift towards the Internet of Things (IoT), leading to the Industrial Internet of Things (IIoT) paradigm. Existing Industrial Automated Control Systems (IACS), enriched with a potentially large number of IoT devices are expected to make systems more efficient, flexible, provide intelligence, and ultimately enable autonomous control. In general, the majority of such systems come with high level of criticality that calls for well-established methods and approaches when achieving cybersecurity, preferably prescribed by a standard.
Björn Leander, Aida Causevic, Hans A. Hansson
ARES1
2019 Classification of PROFINET I/O Configurations utilizing Neural Networks
abstract
In process automation installations, the I/O system connect the field devices to the process controller over a fieldbus, a reliable, real-time capable communication link with signal values cyclical being exchanged with a 10-100 millisecond rate. If a deviation from intended behaviour occurs, analyzing the potentially vast data recordings from the field can be a time consuming and cumbersome task for an engineer. For the engineer to be able to get a full understanding of the problem, knowledge of the used I/O configuration is required. In the problem report, the configuration description is sometimes missing. In such cases it is difficult to use the recorded data for analysis of the problem.In this paper we present our ongoing work towards using neural network models as assistance in the interpretation of an industrial fieldbus communication recording. To show the potential of such an approach we present an example using an industrial setup where fieldbus data is collected and classified. In this context we present an evaluation of the suitability of different neural net configurations and sizes for the problem at hand.
Bjarne Johansson, Björn Leander, Aida Causevic, Alessandro Vittorio Papadopoulos, Thomas Nolte
ETFA2
2019 Cybersecurity Challenges in Large Industrial IoT Systems
abstract
To achieve efficient and flexible production at affordable prices, industrial automation is pushed towards a digital transformation. Such a transformation assumes an enhancement of current Industrial Automated Control Systems with a large amount of IoT-devices, forming an Industrial Internet of Things (IIoT). The aim is to enable a shift from automatic towards autonomous control in such systems. This paper discusses some of the main challenges IIoT systems are facing with respect to cybersecurity. We discuss our findings in an example of a flow-control loop, where we apply a simple threat model based on the STRIDE method to deduce cybersecurity requirements in an IIoT context. Moreover, the identified requirements are assessed in the light of current state of the art solutions, and a number of challenges are discussed with respect to a large-scale IIoT system, together with some suggestions for future work.
Björn Leander, Aida Causevic, Hans A. Hansson
ETFA1