Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems

被引:31
|
作者
Alanen, Jarmo [1 ]
Linnosmaa, Joonas [1 ]
Malm, Timo [1 ]
Papakonstantinou, Nikolaos [1 ]
Ahonen, Toni [1 ]
Heikkila, Eetu [1 ]
Tiusanen, Risto [1 ]
机构
[1] VTT Tech Res Ctr Finland Ltd, Oulu, Finland
关键词
Hybrid risk assessment; Cybersecurity analysis method; Model-based system engineering; Ontology; Industrial control systems; INFORMATION; CYBERSECURITY;
D O I
10.1016/j.ress.2021.108270
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This paper introduces a model-based methodology for hybrid reliability, availability, maintainability, safety, and security (RAMSS) risk assessment management, which extends our previous work of model-based, data-driven, support for engineering mission-critical systems. It represents a hybrid risk assessment ontology, which harmonises basic concepts between dependability, safety and security based on well-known industrial standards. Based on the proposed ontology, we create a cybersecurity risk analysis method, called Security Threat Analysis (STA), for industrial control systems and successfully demonstrate the method. For the demonstration, we introduce a data model for creating a tool-supported data repository for STA, then implement this repository with a commercial-off-the-shelf tool. We use the repository to carry out an exemplary STA of a nuclear fuel pool cooling control system, assessing a cybersecurity-related hazard. The demonstration suggests that the hybrid RAMSS risk assessment ontology and the related STA data model are ready to be tested in industrial use, offering a structured data repository to support assessment and traceability between the created artefacts.
引用
收藏
页数:20
相关论文
共 50 条
  • [21] A Model-Data Integrated Cyber Security Risk Assessment Method for Industrial Control Systems
    Peng, Yuan
    Huang, Kaixing
    Tu, Weixun
    Zhou, Chunjie
    PROCEEDINGS OF 2018 IEEE 7TH DATA DRIVEN CONTROL AND LEARNING SYSTEMS CONFERENCE (DDCLS), 2018, : 344 - 349
  • [22] AutomationML Meets Bayesian Networks: A Comprehensive Safety-Security Risk Assessment in Industrial Control Systems
    Bhosale, Pushparaj
    Kastner, Wolfgang
    Sauter, Thilo
    IEEE OPEN JOURNAL OF THE INDUSTRIAL ELECTRONICS SOCIETY, 2024, 5 : 823 - 835
  • [23] A Method of Entropy Weight Quantitative Risk Assessment for the Safety and Security Integration of a Typical Industrial Control System
    Mi, Junpeng
    Huang, Wenjun
    Chen, Mengchi
    Zhang, Wei
    IEEE ACCESS, 2021, 9 : 90919 - 90932
  • [24] A safety/security risk analysis approach of Industrial Control Systems: A cyber bowtie - combining new version of attack tree with bowtie analysis
    Abdo, H.
    Kaouk, M.
    Flaus, J. -M.
    Masse, F.
    COMPUTERS & SECURITY, 2018, 72 : 175 - 195
  • [25] Co-engineering Safety and Security in Industrial Control Systems: A Formal Outlook
    Vistbakka, Inna
    Troubitsyna, Elena
    Kuismin, Tuomas
    Latvala, Timo
    SOFTWARE ENGINEERING FOR RESILIENT SYSTEMS, SERENE 2017, 2017, 10479 : 96 - 114
  • [26] SEAG: A novel dynamic security risk assessment method for industrial control systems with consideration of social engineering
    Liu, Kaixiang
    Xie, Yongfang
    Xie, Shiwen
    Sun, Limin
    JOURNAL OF PROCESS CONTROL, 2023, 132
  • [27] Vulnerability Analysis and Enhancement of Security of Communication Protocol in Industrial Control Systems
    Rajesh, L.
    Satyanarayana, Penke
    HELIX, 2019, 9 (04): : 5122 - 5127
  • [28] A logic-based framework for the security analysis of Industrial Control Systems
    Lemaire L.
    Vossaert J.
    Jansen J.
    Naessens V.
    Automatic Control and Computer Sciences, 2017, 51 (2) : 114 - 123
  • [29] A Study on Quantitative Risk Assessment Methods in Security Design for Industrial Control Systems
    Kawanishi, Yasuyuki
    Nishihara, Hideaki
    Souma, Daisuke
    Yoshida, Hirotaka
    Hata, Yoichi
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 62 - 69
  • [30] Information Security Risk Assessment of Industrial Control System Based on Hybrid Genetic Algorithms
    Jie, Chen
    2021 13TH INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION (ICMTMA 2021), 2021, : 423 - 426