When Security Risk Assessment Meets Advanced Metering Infrastructure: Identifying the Appropriate Method

被引:1
|
作者
Shokry, Mostafa [1 ]
Awad, Ali Ismail [2 ,3 ]
Abd-Ellah, Mahmoud Khaled [4 ]
Khalaf, Ashraf A. M. [5 ]
机构
[1] Minist Elect & Renewable Energy, Dept Infrastruct & Informat Secur, Cairo 11517, Egypt
[2] United Arab Emirates Univ, Coll Informat Technol, POB 15551, Al Ain, U Arab Emirates
[3] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, England
[4] Egyptian Russian Univ, Fac Artificial Intelligence, Cairo 11829, Egypt
[5] Minia Univ, Fac Engn, Dept Elect Engn, Al Minya 61519, Egypt
关键词
advanced metering infrastructure; information security risk assessment; smart grids; smart cities; risk assessment methods; OCTAVE Allegro; CRAMM; ATTACKS;
D O I
10.3390/su15129812
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Leading risk assessment standards such as the NIST SP 800-39 and ISO 27005 state that information security risk assessment (ISRA) is one of the crucial stages in the risk-management process. It pinpoints current weaknesses and potential risks, the likelihood of their materializing, and their potential impact on the functionality of critical information systems such as advanced metering infrastructure (AMI). If the current security controls are insufficient, risk assessment helps with applying countermeasures and choosing risk-mitigation strategies to decrease the risk to a controllable level. Although studies have been conducted on risk assessment for AMI and smart grids, the scientific foundations for selecting and using an appropriate method are lacking, negatively impacting the credibility of the results. The main contribution of this work is identifying an appropriate ISRA method for AMI by aligning the risk assessment criteria for AMI systems with the ISRA methodologies' characteristics. Consequently, this work makes three main contributions. First, it presents a comprehensive comparison of multiple ISRA methods, including OCTAVE Allegro (OA), CORAS, COBRA, and FAIR, based on a variety of input requirements, tool features, and the type of risk assessment method. Second, it explores the necessary conditions for carrying out a risk assessment for an AMI system. Third, these AMI risk assessment prerequisites are aligned with the capabilities of multiple ISRA approaches to identify the best ISRA method for AMI systems. The OA method is found to be the best-suited risk assessment method for AMI, and this outcome paves the way to standardizing this method for AMI risk assessment.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Identifying Malicious Metering Data in Advanced Metering Infrastructure
    Choo, Euijin
    Park, Younghee
    Siyamwala, Huzefa
    2014 IEEE 8TH INTERNATIONAL SYMPOSIUM ON SERVICE ORIENTED SYSTEM ENGINEERING (SOSE), 2014, : 490 - 495
  • [2] Security analysis of an advanced metering infrastructure
    Hansen, Aaron
    Staggs, Jason
    Shenoi, Sujeet
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2017, 18 : 3 - 19
  • [3] Security Measures For Advanced Metering Infrastructure Components
    Shein, Rob
    2010 ASIA-PACIFIC POWER AND ENERGY ENGINEERING CONFERENCE (APPEEC), 2010,
  • [4] Challenges in Assuring Security and Resilience of Advanced Metering Infrastructure
    Jaskolka, Jason
    2018 IEEE ELECTRICAL POWER AND ENERGY CONFERENCE (EPEC), 2018,
  • [5] Cyber Security Issues for Advanced Metering Infrastructure (AMI)
    Cleveland, F. M.
    2008 IEEE POWER & ENERGY SOCIETY GENERAL MEETING, VOLS 1-11, 2008, : 2613 - 2617
  • [6] A Security Protocol for Advanced Metering Infrastructure in Smart Grid
    Ye, Feng
    Qian, Yi
    Hu, Rose Qingyang
    2014 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2014), 2014, : 649 - 654
  • [7] Light-weight Security for Advanced Metering Infrastructure
    Kamal, Mohsin
    Tariq, Muhammad
    2019 IEEE 89TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2019-SPRING), 2019,
  • [8] Assessment of potential security risks in advanced metering infrastructure using the OCTAVE Allegro approach
    Awad, Ali Ismail
    Shokry, Mostafa
    Khalaf, Ashraf A. M.
    Abd-Ellah, Mahmoud Khaled
    COMPUTERS & ELECTRICAL ENGINEERING, 2023, 108
  • [9] Communication Performance Assessment for Advanced Metering Infrastructure
    Teng, Jen-Hao
    Chao, Chia-Wei
    Liu, Bin-Han
    Huang, Wei-Hao
    Chiu, Jih-Ching
    ENERGIES, 2019, 12 (01):
  • [10] Enhancement of end-to-end security in advanced metering infrastructure
    Kalidass, J.
    Purusothaman, T.
    Suresh, P.
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2021,