A novel proactive and dynamic cyber risk assessment methodology

被引:0
|
作者
Cheimonidis, Pavlos [1 ]
Rantos, Konstantinos [1 ]
机构
[1] Democritus Univ Thrace, Dept Informat, Kavala 65404, Greece
关键词
Cybersecurity; Cyber risk assessment; Dynamic risk assessment; Bayesian networks; Industrial control systems; VULNERABILITY; MANAGEMENT; SECURITY;
D O I
10.1016/j.cose.2025.104439
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's operational environment, organizations face numerous cybersecurity challenges and risks. This paper presents a novel risk assessment methodology designed to assess cyber risks in a proactive and dynamic manner. Our approach gathers information from both the organization's internal environment and cybersecurity-related open sources. It then converts the collected qualitative data into numerical form by applying predefined mapping rules, including categorical assignments and frequency-based quantification. These numerical values are then integrated with other quantitative data using a probabilistic method. Subsequently, all this information is integrated into a Bayesian network model to dynamically estimate the probability of success of a cyber attack. This probability, combined with the impact assessments of the organization's assets, is used to provide risk estimations. By incorporating the Exploit Prediction Scoring System, our model is capable of delivering not only dynamic but also proactive risk assessments. To validate the effectiveness of the proposed methodology, we present a use case that demonstrates its application in assessing risk within a SCADA environment.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] Dynamic Risk Assessment Enabling Automated Interventions for Medical Cyber-Physical Systems
    Leite, Fabio L., Jr.
    Schneider, Daniel
    Adler, Rasmus
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019, 2019, 11698 : 216 - 231
  • [32] Risk Assessment Method for Cyber Security of Cyber Physical Systems
    Wu, Wenbo
    Kang, Rui
    Li, Zi
    PROCEEDINGS OF THE 2015 FIRST INTERNATIONAL CONFERENCE ON RELIABILITY SYSTEMS ENGINEERING 2015 ICRSE, 2015,
  • [33] Cyber Risk Assessment for SHips (CRASH)
    Oruc, A.
    Kavallieratos, G.
    Gkioulos, V.
    Katsikas, S.
    TRANSNAV-INTERNATIONAL JOURNAL ON MARINE NAVIGATION AND SAFETY OF SEA TRANSPORTATION, 2024, 18 (01) : 115 - 124
  • [34] Methodology for Integrated Risk Management and Proactive Scheduling of Construction Projects
    Schatteman, Damien
    Herroelen, Willy
    Van de Vonder, Stijn
    Boone, Anton
    JOURNAL OF CONSTRUCTION ENGINEERING AND MANAGEMENT, 2008, 134 (11) : 885 - 893
  • [35] A Novel Risk Assessment Methodology - A Case Study of the PRISM Methodology in a Compliance Management Sensitive Sector
    Bognar, Ferenc
    Benedek, Petra
    ACTA POLYTECHNICA HUNGARICA, 2021, 18 (07) : 89 - 108
  • [36] A Novel Methodology for Risk Assessment Considering Risk Higher Order Interactions and Propagation Effects
    Liu, Hui
    Shen, Die
    Dabic, Marina
    Lu, Jintao
    IEEE TRANSACTIONS ON ENGINEERING MANAGEMENT, 2025, 72 : 907 - 924
  • [37] Cyber security of railway cyber-physical system (CPS) - A risk management methodology
    Wang, Zezhou
    Liu, Xiang
    COMMUNICATIONS IN TRANSPORTATION RESEARCH, 2022, 2
  • [38] A novel methodology for epidemic risk assessment of COVID-19 outbreak
    Pluchino, A.
    Biondo, A. E.
    Giuffrida, N.
    Inturri, G.
    Latora, V
    Le Moli, R.
    Rapisarda, A.
    Russo, G.
    Zappala, C.
    SCIENTIFIC REPORTS, 2021, 11 (01)
  • [39] A novel methodology for epidemic risk assessment of COVID-19 outbreak
    A. Pluchino
    A. E. Biondo
    N. Giuffrida
    G. Inturri
    V. Latora
    R. Le Moli
    A. Rapisarda
    G. Russo
    C. Zappalà
    Scientific Reports, 11
  • [40] A novel quantitative ecological and microbial risk assessment methodology: theory and practice
    Duarte, Heitor Oliveira
    Lopez Droguett, Enrique
    Moura, Marcio das Chagas
    Santos Campos Siqueira, Paulo Gabriel
    de Lira Junior, Jose Claudino
    HUMAN AND ECOLOGICAL RISK ASSESSMENT, 2020, 26 (06): : 1622 - 1645