Assessing cyber threats for storyless systems

被引:12
|
作者
Meland, Per Hakon [1 ,3 ]
Nesheim, Dag Atle [2 ]
Bernsmed, Karin [1 ]
Sindre, Guttorm [3 ]
机构
[1] SINTEF Digital, Strindvegen 4, N-7465 Trondheim, Norway
[2] SINTEF Ocean, Postboks 4762 Torgard, N-7465 Trondheim, Norway
[3] Norwegian Univ Sci & Technol, Hogskoleringen 1, N-7491 Trondheim, Norway
基金
欧盟地平线“2020”;
关键词
Cyber threats; Decision-making; Estimation; Empirical evaluation; Case study; Maritime communication; RISK-MANAGEMENT; CYBERSECURITY; OPPORTUNITY; FRAMEWORK; CHOICE; MODEL;
D O I
10.1016/j.jisa.2021.103050
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A proper assessment of potential cyber threats is vital for security decision-making. This becomes an even more challenging task when dealing with new system designs and industry sectors where there is little or no historical data about past security incidents. We have developed a threat likelihood estimation approach that supports risk management under such circumstances. Quantifiable conditions are determined from the environment in which the system will reside and operate, that is the availability of potential threat actors, their opportunities of performing attacks, the required means that are needed for the attack to succeed, and motivation factors. Our research method follows the principles of practice research where both researchers and practitioners have played central roles in a real-life development project for a maritime communication system. We used a qualitative case study for feature-based evaluation of the approach and associated tool template, and to gather evidence on practical aspects such as suitability for purpose, efficiency and drawbacks from five user groups. The results show that representative participants from the cyber security and maritime community gave positive and consistent scores on the features, and regarded time usage, traceability of the threat assessment and the ability to indicate underlying uncertainty to be very appropriate. The approach has been proven useful for this domain and should be applicable to others as well, but the template requires up-front investments in gathering knowledge that is relevant and reusable in additional context situations.
引用
下载
收藏
页数:15
相关论文
共 50 条
  • [41] Threats and Countermeasures of Cyber Security in Direct and Remote Vehicle Communication Systems
    Bharati, Subrato
    Podder, Prajoy
    Mondal, M. Rubaiyat Hossain
    Robel, Md Robiul Alam
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2020, 15 (04): : 153 - 164
  • [42] Developing Chatbots for Cyber Security: Assessing Threats through Sentiment Analysis on Social Media
    Arora, Amit
    Arora, Anshu
    Mcintyre, John
    SUSTAINABILITY, 2023, 15 (17)
  • [43] ON MANAGING PHYSICAL AND CYBER THREATS TO ENERGY SYSTEMS IDENTIFICATION AND COUNTERMEASURE REQUIREMENTS
    Jormakka, Henryka
    Koponen, Pekka
    Pentikainen, Heimo
    Bartoszewicz-Burczy, Hanna
    EKSPLOATACJA I NIEZAWODNOSC-MAINTENANCE AND RELIABILITY, 2010, (03): : 27 - 33
  • [44] GNSS-BASED MARITIME NAVIGATION SYSTEMS: CYBER THREATS SOURCING
    Svilicic, Boris
    13TH ANNUAL BASKA GNSS CONFERENCE PROCEEDINGS, 2019, : 55 - 65
  • [45] On managing physical and cyber threats to energy systems identification and countermeasure requirements
    Jormakka, Henryka
    Koponen, Pekka
    PentikäInen, Heimo
    Bartoszewicz-Burczy, Hanna
    Eksploatacja i Niezawodnosc, 2010, 47 (03) : 27 - 33
  • [46] Special Issue "Security Threats and Countermeasures in Cyber-Physical Systems"
    Hammoudeh, Mohammad
    Watters, Paul
    Epiphaniou, Gregory
    Kayes, A. S. M.
    Pinto, Pedro
    JOURNAL OF SENSOR AND ACTUATOR NETWORKS, 2021, 10 (03)
  • [47] From balance to breach: cyber threats to battery energy storage systems
    Frans Öhrström
    Joakim Oscarsson
    Zeeshan Afzal
    János Dani
    Mikael Asplund
    Energy Informatics, 8 (1)
  • [48] A Systems Approach to Analysing Cyber-Physical Threats in the Smart Grid
    AlMajali, Anas
    Rice, Eric
    Viswanathan, Arun
    Tan, Kymie
    Neuman, Clifford
    2013 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2013, : 456 - 461
  • [49] Aviation cyber security: legal aspects of cyber threats
    Klenka, Michal
    JOURNAL OF TRANSPORTATION SECURITY, 2021, 14 (3-4) : 177 - 195
  • [50] Cyber Threats and Nuclear Weapons
    Griffith, Melissa K.
    SURVIVAL, 2022, 64 (05) : 177 - 180