A novel proactive and dynamic cyber risk assessment methodology

被引:0
|
作者
Cheimonidis, Pavlos [1 ]
Rantos, Konstantinos [1 ]
机构
[1] Democritus Univ Thrace, Dept Informat, Kavala 65404, Greece
关键词
Cybersecurity; Cyber risk assessment; Dynamic risk assessment; Bayesian networks; Industrial control systems; VULNERABILITY; MANAGEMENT; SECURITY;
D O I
10.1016/j.cose.2025.104439
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In today's operational environment, organizations face numerous cybersecurity challenges and risks. This paper presents a novel risk assessment methodology designed to assess cyber risks in a proactive and dynamic manner. Our approach gathers information from both the organization's internal environment and cybersecurity-related open sources. It then converts the collected qualitative data into numerical form by applying predefined mapping rules, including categorical assignments and frequency-based quantification. These numerical values are then integrated with other quantitative data using a probabilistic method. Subsequently, all this information is integrated into a Bayesian network model to dynamically estimate the probability of success of a cyber attack. This probability, combined with the impact assessments of the organization's assets, is used to provide risk estimations. By incorporating the Exploit Prediction Scoring System, our model is capable of delivering not only dynamic but also proactive risk assessments. To validate the effectiveness of the proposed methodology, we present a use case that demonstrates its application in assessing risk within a SCADA environment.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] Dynamic Assessment of Cyber Threats in the Field of Insurance
    Pavlik, Lukas
    Ficek, Martin
    Rak, Jakub
    RISKS, 2022, 10 (12)
  • [42] IoT cyber risk: a holistic analysis of cyber risk assessment frameworks, risk vectors, and risk ranking process
    Kandasamy, Kamalanathan
    Srinivas, Sethuraman
    Achuthan, Krishnashree
    Rangan, Venkat P.
    EURASIP JOURNAL ON INFORMATION SECURITY, 2020, 2020 (01)
  • [43] IoT cyber risk: a holistic analysis of cyber risk assessment frameworks, risk vectors, and risk ranking process
    Kamalanathan Kandasamy
    Sethuraman Srinivas
    Krishnashree Achuthan
    Venkat P. Rangan
    EURASIP Journal on Information Security, 2020
  • [44] Dynamic risk assessment methodology of operation process for deepwater oil and gas equipment
    Wang, Chenyushu
    Cai, Baoping
    Shao, Xiaoyan
    Zhao, Liqian
    Sui, Zhongfei
    Liu, Keyang
    Khan, Javed Akbar
    Gao, Lei
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2023, 239
  • [45] Application of a dynamic computational gis modeling methodology for exposure and dose risk assessment
    Magro, G.
    Scarpanti, S.
    Sumini, M.
    Teodori, F.
    PROCEEDINGS OF THE SECOND IASTED INTERNATIONAL CONFERENCE ON ENVIRONMENTAL MODELLING AND SIMULATION, 2006, : 43 - +
  • [46] Dynamic Risk Assessment Methodology with an LDM-based System for Parking Scenarios
    Natalia Canas, Paola
    Garcia, Mikel
    Aranjuelo, Nerea
    Nieto, Marcos
    Iglesias, Aitor
    Rodriguez, Igor
    2023 IEEE 26TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS, ITSC, 2023, : 5034 - 5039
  • [47] A novel methodology for dynamic vulnerability assessment of storage tank exposed to technological hazards
    Zeng, Tao
    Wei, Lijun
    Duo, Yingquan
    Chen, Chao
    Wang, Rujun
    Yang, Guoliang
    Chen, Sining
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2024, 92
  • [48] Cyber risk assessment of cyber-enabled autonomous cargo vessel
    Yousaf, Awais
    Amro, Ahmed
    Kwa, Philip Teow Huat
    Li, Meixuan
    Zhou, Jianying
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2024, 46
  • [49] Methodology of Disease Risk Assessment
    Melnyk, Karina
    Borysova, Natalia
    Ershova, Svetlana
    IDDM 2020: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATICS & DATA-DRIVEN MEDICINE, 2020, 2753
  • [50] The Security Risk Assessment Methodology
    Liu, Chunlin
    Tan, Chong-Kuan
    Fang, Yea-Saen
    Lok, Tat-Seng
    INTERNATIONAL SYMPOSIUM ON SAFETY SCIENCE AND ENGINEERING IN CHINA, 2012, 2012, 43 : 600 - 609