Assessing cyber threats for storyless systems

被引:12
|
作者
Meland, Per Hakon [1 ,3 ]
Nesheim, Dag Atle [2 ]
Bernsmed, Karin [1 ]
Sindre, Guttorm [3 ]
机构
[1] SINTEF Digital, Strindvegen 4, N-7465 Trondheim, Norway
[2] SINTEF Ocean, Postboks 4762 Torgard, N-7465 Trondheim, Norway
[3] Norwegian Univ Sci & Technol, Hogskoleringen 1, N-7491 Trondheim, Norway
基金
欧盟地平线“2020”;
关键词
Cyber threats; Decision-making; Estimation; Empirical evaluation; Case study; Maritime communication; RISK-MANAGEMENT; CYBERSECURITY; OPPORTUNITY; FRAMEWORK; CHOICE; MODEL;
D O I
10.1016/j.jisa.2021.103050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A proper assessment of potential cyber threats is vital for security decision-making. This becomes an even more challenging task when dealing with new system designs and industry sectors where there is little or no historical data about past security incidents. We have developed a threat likelihood estimation approach that supports risk management under such circumstances. Quantifiable conditions are determined from the environment in which the system will reside and operate, that is the availability of potential threat actors, their opportunities of performing attacks, the required means that are needed for the attack to succeed, and motivation factors. Our research method follows the principles of practice research where both researchers and practitioners have played central roles in a real-life development project for a maritime communication system. We used a qualitative case study for feature-based evaluation of the approach and associated tool template, and to gather evidence on practical aspects such as suitability for purpose, efficiency and drawbacks from five user groups. The results show that representative participants from the cyber security and maritime community gave positive and consistent scores on the features, and regarded time usage, traceability of the threat assessment and the ability to indicate underlying uncertainty to be very appropriate. The approach has been proven useful for this domain and should be applicable to others as well, but the template requires up-front investments in gathering knowledge that is relevant and reusable in additional context situations.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Assessing and addressing cyber threats to control systems
    Bartels, Andrew
    [J]. POWER, 2008, 152 (06) : 40 - 43
  • [2] ASSESSING SEVERITY OF CYBER-ATTACK THREATS AGAINST CYBER-MANUFACTURING SYSTEMS
    Espinoza-Zelaya, Carlos
    Moon, Young
    [J]. PROCEEDINGS OF ASME 2022 INTERNATIONAL MECHANICAL ENGINEERING CONGRESS AND EXPOSITION, IMECE2022, VOL 2B, 2022,
  • [3] On the Top Threats to Cyber Systems
    Kettani, Houssain
    Wainwright, Polly
    [J]. 2019 IEEE 2ND INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTER TECHNOLOGIES (ICICT), 2019, : 175 - 179
  • [4] Critical Systems under Cyber Threats
    Pantopoulou, Styliani
    Lagari, Pola Lydia
    Townsend, Clive H.
    Tsoukalas, Lefteri H.
    [J]. 2020 11TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS AND APPLICATIONS (IISA 2020), 2020, : 460 - 463
  • [5] Analysis on Cyber Threats to SCADA systems
    Kang, Dong-Joo
    Lee, Jong-Joo
    Kim, Seog-Joo
    Park, Jong-Hyuk
    [J]. T& D ASIA: 2009 TRANSMISSION & DISTRIBUTION CONFERENCE & EXPOSITION: ASIA AND PACIFIC, 2009, : 14 - +
  • [6] On Security Threats of Botnets to Cyber Systems
    Lange, Thomas
    Kettani, Houssain
    [J]. 2019 6TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INTEGRATED NETWORKS (SPIN), 2019, : 176 - 183
  • [7] Cyber Security of Cyber Physical Systems: Cyber Threats and Defense of Critical Infrastructures
    Shukla, Sandeep K.
    [J]. 2016 29TH INTERNATIONAL CONFERENCE ON VLSI DESIGN AND 2016 15TH INTERNATIONAL CONFERENCE ON EMBEDDED SYSTEMS (VLSID), 2016, : 30 - 31
  • [8] A simulation-based platform for assessing the impact of cyber-threats on smart manufacturing systems
    Bracho, Alejandro
    Saygin, Can
    Wan, HungDa
    Lee, Yooneun
    Zarreh, Alireza
    [J]. 46TH SME NORTH AMERICAN MANUFACTURING RESEARCH CONFERENCE, NAMRC 46, 2018, 26 : 1116 - 1127
  • [9] Evaluation of Cyber Security Threats in Banking Systems
    Stanikzai, Abdul Qarib
    Shah, Munam Ali
    [J]. 2021 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI 2021), 2021,
  • [10] An Evaluation of Cyber Threats to Industrial Control Systems
    Vavra, Jan
    Hromada, Martin
    [J]. INTERNATIONAL CONFERENCE ON MILITARY TECHNOLOGIES (ICMT 2015), 2015, : 369 - 373