A Taxonomy for Risk Assessment of Cyberattacks on Critical Infrastructure (TRACI)

被引:0
|
作者
Plachkinova, Miloslava [1 ]
Vo, Ace [2 ]
机构
[1] Kennesaw State Univ, Informat Syst & Secur Dept, Coles Coll Business, Kennesaw, GA 30144 USA
[2] Loyola Marymount Univ, Dept Informat Syst & Business Analyt, Coll Business Adm, Los Angeles, CA USA
关键词
Cybercrime; Cyberterrorism; Cybersecurity; Critical Infrastructure; Routine Activity Theory; Rational Choice Theory; Design Science Research; ROUTINE ACTIVITY THEORY; DESIGN SCIENCE; STUXNET; CRIME;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybercrime against critical infrastructure such as nuclear reactors, power plants, and dams has been increasing in frequency and severity. Recent literature regarding these types of attacks has been extensive but due to the sensitive nature of this field, there is very little empirical data. We address these issues by integrating Routine Activity Theory and Rational Choice Theory, and we create a classification tool called TRACI (Taxonomy for Risk Assessment of Cyberattacks on Critical Infrastructure). We take a Design Science Research approach to develop, evaluate, and refine the proposed artifact. We use mix methods to demonstrate that our taxonomy can successfully capture the characteristics of various cyberattacks against critical infrastructure. TRACI consists of three dimensions, and each dimension contains its own subdimensions. The first dimension comprises of hacker motivation, which can be financial, socio-cultural, thrill-seeking, and/or economic. The second dimension represents the assets such as cyber, physical, and/or cyber-physical components. The third dimension is related to threats, vulnerabilities, and controls that are fundamental to establishing and maintaining an information security posture and overall cyber resilience. Our work is among the first to utilize criminological theories and Design Science to create an empirically validated artifact for improving critical infrastructure risk management.
引用
收藏
页数:26
相关论文
共 50 条
  • [1] A Taxonomy for Risk Assessment of Cyberattacks on Critical Infrastructure (TRACI)
    Plachkinovа, Miloslava
    Vо, Ace
    Communications of the Association for Information Systems, 2023, 52
  • [2] A Taxonomy of Cyberattacks against Critical Infrastructure TREO Talk Paper
    Plachkinova, Miloslava
    25TH AMERICAS CONFERENCE ON INFORMATION SYSTEMS (AMCIS 2019), 2019,
  • [3] Cyberattacks on critical infrastructure: An economic perspective
    Lis, Piotr
    Mendel, Jacob
    ECONOMICS AND BUSINESS REVIEW, 2019, 5 (02) : 24 - 47
  • [4] The Risk Assessment of Critical Rail Infrastructure
    Titko, M.
    Byrtusova, A.
    TRANSPORT MEANS 2015, PTS I AND II, 2015, : 99 - +
  • [5] Strategies to Counter Cyberattacks: Cyberthreats and Critical Infrastructure Protection
    Karabacak, Bilge
    Tatar, Unal
    CRITICAL INFRASTRUCTURE PROTECTION, 2014, 116 : 63 - 73
  • [6] Controls for Protecting Critical Information Infrastructure from Cyberattacks
    Tsegaye, Tamir
    Flowerday, Stephen
    2014 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2014, : 24 - 29
  • [7] Cyberattacks on Critical Infrastructure and Potential Sustainable Development Impacts
    Mezher, Toufic
    El Khatib, Sameh
    Sooriyaarachchi, Thilanka Maduwanthi
    INTERNATIONAL JOURNAL OF CYBER WARFARE AND TERRORISM, 2015, 5 (03) : 1 - 18
  • [8] Environmental security, critical infrastructure and risk assessment
    Belluck, D. A.
    Hull, R. N.
    Benjamin, S. L.
    Alcorn, J.
    Linkov, I.
    ENVIRONMENTAL SECURITY IN HARBORS AND COASTAL AREAS: MANAGEMENT USING COMPARATIVE RISK ASSESSMENT AND MULTI-CRITERIA DECISION ANALYSIS, 2007, : 3 - +
  • [9] Risk assessment and improvement of resilience of critical communication infrastructure
    Johnsen, S. O.
    Veen, M.
    ADVANCES IN SAFETY, RELIABILITY AND RISK MANAGEMENT, 2012, : 2739 - 2747
  • [10] Critical Infrastructure Risk Assessment of Romanian Power Systems
    Marinescu, Ioan
    Botea, Bogdan
    Andrei, Horia
    2017 5TH INTERNATIONAL SYMPOSIUM ON ELECTRICAL AND ELECTRONICS ENGINEERING (ISEEE), 2017,