Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems

被引:31
|
作者
Alanen, Jarmo [1 ]
Linnosmaa, Joonas [1 ]
Malm, Timo [1 ]
Papakonstantinou, Nikolaos [1 ]
Ahonen, Toni [1 ]
Heikkila, Eetu [1 ]
Tiusanen, Risto [1 ]
机构
[1] VTT Tech Res Ctr Finland Ltd, Oulu, Finland
关键词
Hybrid risk assessment; Cybersecurity analysis method; Model-based system engineering; Ontology; Industrial control systems; INFORMATION; CYBERSECURITY;
D O I
10.1016/j.ress.2021.108270
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This paper introduces a model-based methodology for hybrid reliability, availability, maintainability, safety, and security (RAMSS) risk assessment management, which extends our previous work of model-based, data-driven, support for engineering mission-critical systems. It represents a hybrid risk assessment ontology, which harmonises basic concepts between dependability, safety and security based on well-known industrial standards. Based on the proposed ontology, we create a cybersecurity risk analysis method, called Security Threat Analysis (STA), for industrial control systems and successfully demonstrate the method. For the demonstration, we introduce a data model for creating a tool-supported data repository for STA, then implement this repository with a commercial-off-the-shelf tool. We use the repository to carry out an exemplary STA of a nuclear fuel pool cooling control system, assessing a cybersecurity-related hazard. The demonstration suggests that the hybrid RAMSS risk assessment ontology and the related STA data model are ready to be tested in industrial use, offering a structured data repository to support assessment and traceability between the created artefacts.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] Alignment of safety and security risk assessments for modular production systems; [Abgleich von Safety- und Security-Risikobeurteilungen für modulare Produktionssysteme]
    Ehrlich M.
    Bröring A.
    Harder D.
    Auhagen-Meyer T.
    Kleen P.
    Wisniewski L.
    Trsek H.
    Jasperneite J.
    e & i Elektrotechnik und Informationstechnik, 2021, 138 (7) : 454 - 461
  • [32] A Risk Assessment Method for IoT Systems Using Maintainability, Safety, and Security Matrixes
    Sasaki, Ryoichi
    INFORMATION SCIENCE AND APPLICATIONS, 2020, 621 : 363 - 374
  • [33] Risk assessment method of power plant industrial control information security based on Bayesian attack graph Systems
    Xie, Jianbo
    Sun, Keda
    Lei, Xubing
    JOURNAL OF ELECTRICAL SYSTEMS, 2021, 17 (04) : 529 - 541
  • [34] Security Analysis of Vendor Implementations of the OPC UA Protocol for Industrial Control Systems
    Erba, Alessandro
    Mueller, Anne
    Tippenhauer, Nils Ole
    PROCEEDINGS OF THE 4TH WORKSHOP ON CPS & IOT SECURITY AND PRIVACY, CPSIOTSEC 2022, 2022, : 1 - 13
  • [35] ACSRA ICS: Automated Cyber Security Risk Assessment Methodology for Industrial Control Systems
    Altaleb, Haya
    Ady, Laszlo
    Varga, Peter Janos
    Rajnai, Zoltan
    ACTA POLYTECHNICA HUNGARICA, 2025, 22 (02) : 47 - 74
  • [36] A Fault Risk Assessment Method for Security Control Systems Based on Control Strategy Influence
    Lei, Ming
    Cui, Xiaodan
    Li, Manli
    Wang, Yanpin
    Li, Yajie
    Shen, Fengjie
    Xu, Jianbing
    Lai, Yening
    2024 4TH POWER SYSTEM AND GREEN ENERGY CONFERENCE, PSGEC 2024, 2024, : 1009 - 1013
  • [37] Information Security Evaluation of Industrial Control Systems Using Probabilistic Linguistic MCDM Method
    Xu, Wenshu
    Lin, Mingwei
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 77 (01): : 199 - 222
  • [38] Security Risk Analysis Approach for Safety-Critical Systems of Connected Vehicles
    Luo, Feng
    Hou, Shuo
    Zhang, Xuan
    Yang, Zhenyu
    Pan, Wenwen
    ELECTRONICS, 2020, 9 (08) : 1 - 20
  • [39] Harmonizing safety and security risk analysis and prevention in cyber-physical systems
    Ji, Zuzhen
    Yang, Shuang-Hua
    Cao, Yi
    Wang, Yuchen
    Zhou, Chenchen
    Yue, Liang
    Zhang, Yinqiao
    PROCESS SAFETY AND ENVIRONMENTAL PROTECTION, 2021, 148 : 1279 - 1291
  • [40] A Security Risk Assessment Method of Website Based on Threat Analysis Combined with AHP and Entropy Weight
    Lai, Zhiquan
    Shen, Yongjun
    Zhang, Guidong
    PROCEEDINGS OF 2016 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2016), 2016, : 481 - 484