Critical Infrastructure Cyber-Security Risk Management

被引:0
|
作者
Spyridopoulos, Theodoros [1 ]
Maraslis, Konstantinos [2 ]
Tryfonas, Theo [2 ]
Oikonomou, George [2 ]
机构
[1] Univ West England, Bristol, Avon, England
[2] Univ Bristol, Bristol, Avon, England
关键词
Industrial Control Systems; Cyber-security; Risk Management; Game Theory; Viable System Model;
D O I
10.3233/978-1-61499-765-8-59
中图分类号
DF [法律]; D9 [法律];
学科分类号
0301 ;
摘要
Traditional IT cyber-security risk management methods are based on the evaluation of risks calculated as the likelihood of cyber-security incidents occurring. However, these probabilities are usually estimations or guesses based on past experience and incomplete data. Incorrect estimations can lead to errors in the evaluation of risks that can ultimately affect the protection of the system. This issue is also transferred to methods used in Industrial Control Systems (ICSs), as they are mainly adaptations of such traditional approaches. Additionally, conventional methods fail to adequately address the increasing threat environment and the highly interdependent critical nature of ICSs, while proposed methods by the research community are as yet far from providing a solution. The importance of securely managing ICS infrastructures is growing, as they are systems embedded in critical national infrastructure (e.g. city traffic lights controls) and thus a potentially attractive target for organized cyber-criminals and terrorists. In this Chapter we present a novel approach that combines Stafford Beer's Viable System Model (VSM) with Game Theory in order to develop a risk management process that addresses the above issues. The model we develop provides a holistic, cost-efficient cyber-security solution that takes into account interdependencies of critical components as well as the potential impact of different attack strategies.
引用
收藏
页码:59 / 76
页数:18
相关论文
共 50 条
  • [21] Cyber-Security and Risk Management in an Interoperable World: An Examination of Governmental Action in North America
    Quigley, Kevin
    Roy, Jeffrey
    [J]. SOCIAL SCIENCE COMPUTER REVIEW, 2012, 30 (01) : 83 - 94
  • [22] Development of Cyber Security Testbed for Critical Infrastructure
    Jarmakiewicz, Jacek
    Maslanka, Krzysztof
    Parobczak, Krzysztof
    [J]. 2015 INTERNATIONAL CONFERENCE ON MILITARY COMMUNICATIONS AND INFORMATION SYSTEMS (ICMCIS), 2015,
  • [23] Cyber threat intelligence for critical infrastructure security
    Osliak, Oleksii
    Saracino, Andrea
    Martinelli, Fabio
    Mori, Paolo
    [J]. CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2023, 35 (23):
  • [24] Balancing Cyber-Security and Privacy
    Patakyova, Maria T.
    [J]. BRATISLAVA LAW REVIEW, 2020, 4 (01): : 181 - 183
  • [25] CYBER-SECURITY RISKS OF FEDWIRE
    Bilger, Mark J.
    [J]. JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2019, 14 (04)
  • [26] On Cyber-security of Augmentation Networks
    Neri, Alessandro
    Baldoni, Sara
    Capua, Roberto
    [J]. PROCEEDINGS OF THE 2019 INTERNATIONAL TECHNICAL MEETING OF THE INSTITUTE OF NAVIGATION, 2019, : 408 - 422
  • [27] Challenging confidence in cyber-security
    [J]. Strand, Chris, 1600, Elsevier Ltd (2014):
  • [28] On Cyber-Security of Information Systems
    Sneps-Sneppe, Manfred
    Sukhomlin, Vladimir
    Namiot, Dmitry
    [J]. DISTRIBUTED COMPUTER AND COMMUNICATION NETWORKS (DCCN 2018), 2018, 919 : 201 - 211
  • [29] The Science of Social Cyber-Security
    Carley, Kathleen
    [J]. MOBICOM'18: PROCEEDINGS OF THE 24TH ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING, 2018, : 459 - 459
  • [30] A CYBER-SECURITY STORM MAP
    Ferebee, Denise
    Dasgupta, Dipankar
    Wu, Qishi
    [J]. 2012 ASE INTERNATIONAL CONFERENCE ON CYBER SECURITY (CYBERSECURITY), 2012, : 93 - 102