A Taxonomy for Risk Assessment of Cyberattacks on Critical Infrastructure (TRACI)

被引:0
|
作者
Plachkinova, Miloslava [1 ]
Vo, Ace [2 ]
机构
[1] Kennesaw State Univ, Informat Syst & Secur Dept, Coles Coll Business, Kennesaw, GA 30144 USA
[2] Loyola Marymount Univ, Dept Informat Syst & Business Analyt, Coll Business Adm, Los Angeles, CA USA
来源
COMMUNICATIONS OF THE ASSOCIATION FOR INFORMATION SYSTEMS | 2023年 / 52卷
关键词
Cybercrime; Cyberterrorism; Cybersecurity; Critical Infrastructure; Routine Activity Theory; Rational Choice Theory; Design Science Research; ROUTINE ACTIVITY THEORY; DESIGN SCIENCE; STUXNET; CRIME;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybercrime against critical infrastructure such as nuclear reactors, power plants, and dams has been increasing in frequency and severity. Recent literature regarding these types of attacks has been extensive but due to the sensitive nature of this field, there is very little empirical data. We address these issues by integrating Routine Activity Theory and Rational Choice Theory, and we create a classification tool called TRACI (Taxonomy for Risk Assessment of Cyberattacks on Critical Infrastructure). We take a Design Science Research approach to develop, evaluate, and refine the proposed artifact. We use mix methods to demonstrate that our taxonomy can successfully capture the characteristics of various cyberattacks against critical infrastructure. TRACI consists of three dimensions, and each dimension contains its own subdimensions. The first dimension comprises of hacker motivation, which can be financial, socio-cultural, thrill-seeking, and/or economic. The second dimension represents the assets such as cyber, physical, and/or cyber-physical components. The third dimension is related to threats, vulnerabilities, and controls that are fundamental to establishing and maintaining an information security posture and overall cyber resilience. Our work is among the first to utilize criminological theories and Design Science to create an empirically validated artifact for improving critical infrastructure risk management.
引用
收藏
页数:26
相关论文
共 50 条
  • [31] Resilience Assessment of Interdependent Critical Infrastructure
    Alsubaie, Abdullah
    Alutaibi, Khaled
    Marti, Jose
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, CRITIS 2015, 2016, 9578 : 43 - 55
  • [32] Critical Infrastructure Assessment by Emergency Management
    Klaver, Marieke H. A.
    Luiijf, H. A. M.
    Nieuwenhuijs, Albert N.
    van Os, Nico
    Oskam, Vincent
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY, CRITIS 2015, 2016, 9578 : 79 - 90
  • [33] Assessment of Critical Infrastructure Elements in Transport
    Dvorak, Zdenek
    Sventekova, Eva
    Rehak, David
    Cekerevac, Zoran
    TRANSBALTICA 2017: TRANSPORTATION SCIENCE AND TECHNOLOGY, 2017, 187 : 548 - 555
  • [34] CIIA: Critical Infrastructure Impact Assessment
    Carvalho, Olga
    Apolinario, Filipe
    Escravana, Nelson
    Ribeiro, Carlos
    37TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2022, : 124 - 132
  • [35] Condition Assessment of Critical Infrastructure with GPR
    Ekes, Csaba
    Takacs, Peter
    Neducza, Boriszlav
    PROCEEDINGS OF THE 2014 15TH INTERNATIONAL CONFERENCE ON GROUND PENETRATING RADAR (GPR 2014), 2014, : 429 - 434
  • [36] Risk and Vulnerability Analysis of Critical Infrastructure
    Wan, Kaiyu
    Alagar, Vangalur
    INTELLIGENT COMPUTING METHODOLOGIES, ICIC 2016, PT III, 2016, 9773 : 54 - 66
  • [37] Risk evaluation of threats to critical infrastructure
    Baecher, Gregory B.
    COMPARATIVE ANALYSIS OF TECHNOLOGICAL AND INTELLIGENT TERRORISM IMPACTS ON COMPLEX TECHNICAL SYSTEMS, 2012, 102 : 12 - 20
  • [38] Taxonomy of uncertainty in environmental life cycle assessment of infrastructure projects
    Saxe, Shoshanna
    Guven, Gursans
    Pereira, Lucas
    Arrigoni, Alessandro
    Opher, Tamar
    Roy, Adrien
    Arceo, Aldrick
    Von Raesfeld, Sofia Sampedro
    Duhamel, Mel
    McCabe, Brenda
    Panesar, Daman K.
    MacLean, Heather L.
    Posen, I. Daniel
    ENVIRONMENTAL RESEARCH LETTERS, 2020, 15 (08)
  • [39] Hierarchical Flow Model-Based Impact Assessment of Cyberattacks for Critical Infrastructures
    Zhu, Qianxiang
    Qin, Yuanqing
    Zhou, Chunjie
    Fei, Li
    IEEE SYSTEMS JOURNAL, 2019, 13 (04): : 3944 - 3955
  • [40] MASTODON: An Open-Source Software for Seismic Analysis and Risk Assessment of Critical Infrastructure
    Veeraraghavan, Swetha
    Bolisetti, Chandrakanth
    Slaughter, Andrew
    Coleman, Justin
    Dhulipala, Somayajulu
    Hoffman, William
    Kim, Kyungtae
    Kurt, Efe
    Spears, Robert
    Munday, Lynn
    NUCLEAR TECHNOLOGY, 2021, 207 (07) : 1073 - 1095