A novel proactive and dynamic cyber risk assessment methodology

被引:0
|
作者
Cheimonidis, Pavlos [1 ]
Rantos, Konstantinos [1 ]
机构
[1] Democritus Univ Thrace, Dept Informat, Kavala 65404, Greece
关键词
Cybersecurity; Cyber risk assessment; Dynamic risk assessment; Bayesian networks; Industrial control systems; VULNERABILITY; MANAGEMENT; SECURITY;
D O I
10.1016/j.cose.2025.104439
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's operational environment, organizations face numerous cybersecurity challenges and risks. This paper presents a novel risk assessment methodology designed to assess cyber risks in a proactive and dynamic manner. Our approach gathers information from both the organization's internal environment and cybersecurity-related open sources. It then converts the collected qualitative data into numerical form by applying predefined mapping rules, including categorical assignments and frequency-based quantification. These numerical values are then integrated with other quantitative data using a probabilistic method. Subsequently, all this information is integrated into a Bayesian network model to dynamically estimate the probability of success of a cyber attack. This probability, combined with the impact assessments of the organization's assets, is used to provide risk estimations. By incorporating the Exploit Prediction Scoring System, our model is capable of delivering not only dynamic but also proactive risk assessments. To validate the effectiveness of the proposed methodology, we present a use case that demonstrates its application in assessing risk within a SCADA environment.
引用
收藏
页数:16
相关论文
共 50 条
  • [21] Proactive risk assessment of critical infrastructures
    Uusitalo, T.
    Koivisto, R.
    Schmitz, W.
    SAFETY, RELIABILITY AND RISK ANALYSIS: THEORY, METHODS AND APPLICATIONS, VOLS 1-4, 2009, : 2511 - 2517
  • [22] Proactive Damage Assessment of Cyber Attacks Using Mobile Observer Agents
    Lakhdhar, Yosra
    Rekhis, Slim
    Boudriga, Noureddine
    MOMM 2017: THE 15TH INTERNATIONAL CONFERENCE ON ADVANCES IN MOBILE COMPUTING & MULTIMEDIA, 2017, : 29 - 38
  • [23] A Novel Risk Assessment Methodology for SCADA Maritime Logistics Environments
    Kalogeraki, Eleni-Maria
    Papastergiou, Spyridon
    Mouratidis, Haralambos
    Polemi, Nineta
    APPLIED SCIENCES-BASEL, 2018, 8 (09):
  • [24] Cyber first aid: Proactive risk management and decision-making
    Sheppard B.
    Crannell M.
    Moulton J.
    Environment Systems and Decisions, 2013, 33 (4) : 530 - 535
  • [25] A methodology for architectural-level risk assessment using dynamic metrics
    Yacoub, SM
    Ammar, HH
    Robinson, T
    11TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, PROCEEDINGS, 2000, : 210 - 221
  • [26] A dynamic failure propagation methodology supporting the risk assessment of multidisciplinary systems
    Papakonstantinou, Nikolaos
    O'Halloran, Bryan
    2017 22ND IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2017,
  • [27] THE METHODOLOGY OF RISK ASSESSMENT
    GAFFEY, WR
    RISK ANALYSIS, 1984, 4 (01) : 5 - 5
  • [28] A novel data-driven approach for proactive risk assessment in shield tunnel construction
    Zhou, Xin-Hui
    Shen, Shui-Long
    Zhou, Annan
    TRANSPORTATION GEOTECHNICS, 2025, 50
  • [29] DRIVERS: A platform for dynamic risk assessment of emergent cyber threats for industrial control systems
    Nobili, Martina
    Fioravanti, Camilla
    Guarino, Simone
    Ansaldi, Silvia Maria
    Milazzo, Maria Francesca
    Bragatto, Paolo
    Setola, Roberto
    2023 31ST MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION, MED, 2023, : 395 - 400
  • [30] Dynamic risk assessment approach for analysing cyber security events in medical IoT networks
    Czekster, Ricardo M.
    Webber, Thais
    Furstenau, Leonardo Bertolin
    Marcon, Cesar
    INTERNET OF THINGS, 2025, 29