Functional quantitative security risk analysis (QSRA) to assist in protecting critical process infrastructure

被引:41
|
作者
van Staalduinen, Mark Adrian [1 ]
Khan, Faisal [1 ]
Gadag, Veeresh [1 ,2 ]
Reniers, Genserik [1 ,3 ]
机构
[1] Mem Univ, Fac Engn & Appl Sci, Ctr Risk Integr & Safety Engn, St John, NF A1B 3X5, Canada
[2] Mem Univ, Div Community Hlth & Humanities, St John, NF A1B 3V6, Canada
[3] Delft Univ Technol, Safety & Secur Sci Grp S3G, NL-2600 AA Delft, Netherlands
关键词
Quantitative security risk analysis; Bayesian network; Bow-Tie risk model; SYSTEMS; TREES;
D O I
10.1016/j.ress.2016.08.014
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This article proposes a quantitative security risk assessment methodology that can assist management in the decision-making process where and when to protect critical assets of a chemical facility. An improvement upon previous work is the approach of conducting concurrent Threat and Vulnerability Assessments, as opposed to a sequential approach. Furthermore, this method introduces a Bow Tie risk model mapped into a Bayesian Network model that allows for various logical relaxation assumptions to be applied. Different uncertainty relaxation approaches such as "Noisy-OR" and "Leaky Noisy-OR" and "Noisy-AND" are tested to improve Threat and Vulnerability likelihood. Finally, integrating threat/vulnerability likelihood with potential losses, the security risk is quantified. The potential security countermeasures are characterized into either decreasing vulnerability or decreasing threat likelihood and are reassessed considering a cost analysis. A theoretical case study is conducted to exemplify the execution and application of the proposed method. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:23 / 34
页数:12
相关论文
共 50 条
  • [31] Security analysis and solutions for deploying IP Telephony in the Critical Infrastructure
    Cao, Feng
    Malik, Saadat
    2005 Workshop of the 1st Intl Conference on Security and Privacy for Emerging Areas in Communication Networks - SECURECOMM, 2005, : 164 - 173
  • [32] An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
    Kure, Halima Ibrahim
    Islam, Shareeful
    Mouratidis, Haralambos
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (18): : 15241 - 15271
  • [33] An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
    Halima Ibrahim Kure
    Shareeful Islam
    Haralambos Mouratidis
    Neural Computing and Applications, 2022, 34 : 15241 - 15271
  • [34] Protecting Canada's critical national infrastructure from terrorism Mapping a proactive strategy for energy security
    Rudner, Martin
    INTERNATIONAL JOURNAL, 2009, 64 (03): : 775 - 797
  • [35] State Liability and Critical Infrastructure: A Comparative and Functional Analysis
    van Aaken, Anne
    Wildhaber, Isabelle
    EUROPEAN JOURNAL OF RISK REGULATION, 2015, 6 (02) : 244 - 254
  • [36] Industrial and Critical Infrastructure Security: Technical Analysis of Real-Life Security Incidents
    Makrakis, Georgios Michail
    Kolias, Constantinos
    Kambourakis, Georgios
    Rieger, Craig
    Benjamin, Jacob
    IEEE ACCESS, 2021, 9 : 165295 - 165325
  • [37] Vulnerability assessment and quantitative risk analysis of road infrastructure
    Spagnuolo, Franco Enzo
    Lombardi, Mara
    Cantisani, Giuseppe
    Guarascio, Massimo
    Rossi, Giuliano
    GEAM-GEOINGEGNERIA AMBIENTALE E MINERARIA-GEAM-GEOENGINEERING ENVIRONMENT AND MINING, 2018, (155): : 93 - 102
  • [38] A technical review on quantitative risk analysis for hydrogen infrastructure
    Patel, Parth
    Garaniya, Vikram
    Baalisampang, Til
    Arzaghi, Ehsan
    Abbassi, Rouzbeh
    Salehi, Fatemeh
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2024, 91
  • [39] Quantitative Security Risk Modeling and Analysis with RisQFLan
    ter Beek, Maurice H.
    Legay, Axel
    Lafuente, Alberto Lluch
    Vandin, Andrea
    COMPUTERS & SECURITY, 2021, 109
  • [40] Feasibility study of PRA for critical infrastructure risk analysis
    Johnson, Caroline A.
    Flage, Roger
    Guikema, Seth D.
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2021, 212