Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems

被引:31
|
作者
Alanen, Jarmo [1 ]
Linnosmaa, Joonas [1 ]
Malm, Timo [1 ]
Papakonstantinou, Nikolaos [1 ]
Ahonen, Toni [1 ]
Heikkila, Eetu [1 ]
Tiusanen, Risto [1 ]
机构
[1] VTT Tech Res Ctr Finland Ltd, Oulu, Finland
关键词
Hybrid risk assessment; Cybersecurity analysis method; Model-based system engineering; Ontology; Industrial control systems; INFORMATION; CYBERSECURITY;
D O I
10.1016/j.ress.2021.108270
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This paper introduces a model-based methodology for hybrid reliability, availability, maintainability, safety, and security (RAMSS) risk assessment management, which extends our previous work of model-based, data-driven, support for engineering mission-critical systems. It represents a hybrid risk assessment ontology, which harmonises basic concepts between dependability, safety and security based on well-known industrial standards. Based on the proposed ontology, we create a cybersecurity risk analysis method, called Security Threat Analysis (STA), for industrial control systems and successfully demonstrate the method. For the demonstration, we introduce a data model for creating a tool-supported data repository for STA, then implement this repository with a commercial-off-the-shelf tool. We use the repository to carry out an exemplary STA of a nuclear fuel pool cooling control system, assessing a cybersecurity-related hazard. The demonstration suggests that the hybrid RAMSS risk assessment ontology and the related STA data model are ready to be tested in industrial use, offering a structured data repository to support assessment and traceability between the created artefacts.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems
    Alanen, Jarmo
    Linnosmaa, Joonas
    Malm, Timo
    Papakonstantinou, Nikolaos
    Ahonen, Toni
    Heikkilä, Eetu
    Tiusanen, Risto
    Reliability Engineering and System Safety, 2022, 220
  • [2] Insights on the Security and Dependability of Industrial Control Systems
    Kargl, Frank
    van der Heijden, Rens W.
    Koenig, Hartmut
    Valdes, Alfonso
    Dacier, Marc C.
    IEEE SECURITY & PRIVACY, 2014, 12 (06) : 75 - 78
  • [3] A new safety and security risk analysis framework for industrial control systems
    Kriaa, Siwar
    Bouissou, Marc
    Laarouchi, Youssef
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART O-JOURNAL OF RISK AND RELIABILITY, 2019, 233 (02) : 151 - 174
  • [4] A Zero Trust Hybrid Security and Safety Risk Analysis Method
    Papakonstantinou, Nikolaos
    Van Bossuyt, Douglas L.
    Linnosmaa, Joonas
    Hale, Britta
    O'Halloran, Bryan
    JOURNAL OF COMPUTING AND INFORMATION SCIENCE IN ENGINEERING, 2021, 21 (05)
  • [5] Ontology-based Framework for Boundary Verification of Safety and Security Properties in Industrial Control Systems
    Ukegbu, Chibuzo
    Neupane, Ramesh
    Mehrpouyan, Hoda
    PROCEEDINGS OF THE 2023 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2023, 2023, : 47 - 52
  • [6] Alignment of safety and security risk assessments for modular production systems
    Ehrlich, Marco
    Broering, Andre
    Harder, Dimitri
    Auhagen-Meyer, Torben
    Kleen, Philip
    Wisniewski, Lukasz
    Trsek, Henning
    Jasperneite, Jurgen
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2021, 138 (07): : 454 - 461
  • [7] Automating Safety and Security Risk Assessment in Industrial Control Systems: Challenges and Constraints
    Bhosale, Pushparaj
    Kastner, Wolfgang
    Sauter, Thilo
    2022 IEEE 27TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2022,
  • [8] A Survey of Cyber Security and Safety in Industrial Control Systems
    Ma, Yi-Wei
    Tu, Yi-Hao
    Tsou, Chia-Wei
    Chiang, Yen-Neng
    Chen, Jiann-Liang
    JOURNAL OF INTERNET TECHNOLOGY, 2024, 25 (04): : 541 - 550
  • [9] Analysis of Cyber Security for Industrial Control Systems
    Drias, Zakarya
    Serhrouchni, Ahmed
    Vogel, Olivier
    2015 INTERNATIONAL CONFERENCE ON CYBER SECURITY OF SMART CITIES, INDUSTRIAL CONTROL AND COMMUNICATIONS (SSIC), 2015,
  • [10] Vision: Security-Usability Threat Modeling for Industrial Control Systems
    Li, Karen
    Roudaut, Anne
    Rashid, Awais
    PROCEEDINGS OF THE 2021 EUROPEAN SYMPOSIUM ON USABLE SECURITY, EUROUSEC 2021, 2021, : 83 - 88