A novel proactive and dynamic cyber risk assessment methodology

被引:0
|
作者
Cheimonidis, Pavlos [1 ]
Rantos, Konstantinos [1 ]
机构
[1] Democritus Univ Thrace, Dept Informat, Kavala 65404, Greece
关键词
Cybersecurity; Cyber risk assessment; Dynamic risk assessment; Bayesian networks; Industrial control systems; VULNERABILITY; MANAGEMENT; SECURITY;
D O I
10.1016/j.cose.2025.104439
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's operational environment, organizations face numerous cybersecurity challenges and risks. This paper presents a novel risk assessment methodology designed to assess cyber risks in a proactive and dynamic manner. Our approach gathers information from both the organization's internal environment and cybersecurity-related open sources. It then converts the collected qualitative data into numerical form by applying predefined mapping rules, including categorical assignments and frequency-based quantification. These numerical values are then integrated with other quantitative data using a probabilistic method. Subsequently, all this information is integrated into a Bayesian network model to dynamically estimate the probability of success of a cyber attack. This probability, combined with the impact assessments of the organization's assets, is used to provide risk estimations. By incorporating the Exploit Prediction Scoring System, our model is capable of delivering not only dynamic but also proactive risk assessments. To validate the effectiveness of the proposed methodology, we present a use case that demonstrates its application in assessing risk within a SCADA environment.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] MITIGATE: a dynamic supply chain cyber risk assessment methodology
    Stefan Schauer
    Nineta Polemi
    Haralambos Mouratidis
    Journal of Transportation Security, 2019, 12 : 1 - 35
  • [2] MITIGATE: a dynamic supply chain cyber risk assessment methodology (vol 12, pg 1, 2019)
    Schauer, Stefan
    Polemi, Nineta
    Mouratidis, Haralambos
    JOURNAL OF TRANSPORTATION SECURITY, 2019, 12 (1-2) : 37 - 37
  • [3] Toward Proactive Cyber-Physical-Human Risk Assessment in Power Systems
    Umunnakwe, Amarachi
    Sun, Shining
    Davis, Katherine
    2024 IEEE TEXAS POWER AND ENERGY CONFERENCE, TPEC, 2024, : 608 - 613
  • [4] A novel data-driven methodology for fault detection and dynamic risk assessment
    Amin, Md. Tanjin
    Khan, Faisal
    Ahmed, Salim
    Imtiaz, Syed
    CANADIAN JOURNAL OF CHEMICAL ENGINEERING, 2020, 98 (11): : 2397 - 2416
  • [5] A Quantitative CVSS-Based Cyber Security Risk Assessment Methodology For IT Systems
    Aksu, M. Ugur
    Dilek, M. Hadi
    Tatli, E. Islam
    Bicakci, Kemal
    Dirik, H. Ibrahim
    Demirezen, M. Umut
    Aykir, Tayfun
    2017 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2017,
  • [6] A Dynamic Risk Assessment Methodology for Maintenance Decision Support
    Chemweno, Peter
    Pintelon, Liliane
    De Meyer, Anne-Marie
    Muchiri, Peter N.
    Van Horenbeek, Adriaan
    Wakiru, James
    QUALITY AND RELIABILITY ENGINEERING INTERNATIONAL, 2017, 33 (03) : 551 - 564
  • [7] Cyber risk assessment
    Nicholson, Todd
    CONTROL ENGINEERING, 2007, 54 (11) : C11 - C12
  • [8] A novel cyber-risk assessment method for ship systems
    Bolbot, Victor
    Theotokatos, Gerasimos
    Boulougouris, Evangelos
    Vassalos, Dracos
    SAFETY SCIENCE, 2020, 131
  • [9] Behavior Prediction of Cyber-Physical Systems for Dynamic Risk Assessment
    Grobelna, Marta
    DEPENDABLE COMPUTING, EDCC 2021 WORKSHOPS, 2021, 1462 : 30 - 38
  • [10] Combined Proactive Risk Assessment: Unifying Proactive and Reactive Risk Assessment Techniques In Health Care
    Bender, John A.
    Kulju, Stephen
    Soncrant, Christina
    JOINT COMMISSION JOURNAL ON QUALITY AND PATIENT SAFETY, 2022, 48 (6-7): : 326 - 334