Hybrid ontology for safety, security, and dependability risk assessments and Security Threat Analysis (STA) method for industrial control systems

被引:31
|
作者
Alanen, Jarmo [1 ]
Linnosmaa, Joonas [1 ]
Malm, Timo [1 ]
Papakonstantinou, Nikolaos [1 ]
Ahonen, Toni [1 ]
Heikkila, Eetu [1 ]
Tiusanen, Risto [1 ]
机构
[1] VTT Tech Res Ctr Finland Ltd, Oulu, Finland
关键词
Hybrid risk assessment; Cybersecurity analysis method; Model-based system engineering; Ontology; Industrial control systems; INFORMATION; CYBERSECURITY;
D O I
10.1016/j.ress.2021.108270
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
This paper introduces a model-based methodology for hybrid reliability, availability, maintainability, safety, and security (RAMSS) risk assessment management, which extends our previous work of model-based, data-driven, support for engineering mission-critical systems. It represents a hybrid risk assessment ontology, which harmonises basic concepts between dependability, safety and security based on well-known industrial standards. Based on the proposed ontology, we create a cybersecurity risk analysis method, called Security Threat Analysis (STA), for industrial control systems and successfully demonstrate the method. For the demonstration, we introduce a data model for creating a tool-supported data repository for STA, then implement this repository with a commercial-off-the-shelf tool. We use the repository to carry out an exemplary STA of a nuclear fuel pool cooling control system, assessing a cybersecurity-related hazard. The demonstration suggests that the hybrid RAMSS risk assessment ontology and the related STA data model are ready to be tested in industrial use, offering a structured data repository to support assessment and traceability between the created artefacts.
引用
收藏
页数:20
相关论文
共 50 条
  • [41] A cyber-physical experimentation environment for the security analysis of networked industrial control systems
    Genge, Bela
    Siaterlis, Christos
    Fovino, Igor Nai
    Masera, Marcelo
    COMPUTERS & ELECTRICAL ENGINEERING, 2012, 38 (05) : 1146 - 1161
  • [42] The Global State of Security in Industrial Control Systems: An Empirical Analysis of Vulnerabilities Around the World
    Anton, Simon Daniel Duque
    Fraunholz, Daniel
    Krohmer, Daniel
    Reti, Daniel
    Schneider, Daniel
    Schotten, Hans Dieter
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (24) : 17525 - 17540
  • [43] Security Analysis of Cloud-connected Industrial Control Systems using Combinatorial Testing
    Tran-Jorgensen, Peter W. V.
    Kulik, Tomas
    Boudjadar, Jalil
    Larsen, Peter Gorm
    17TH ACM-IEEE INTERNATIONAL CONFERENCE ON FORMAL METHODS AND MODELS FOR SYSTEM DESIGN (MEMOCODE), 2019,
  • [44] Extracting Interdependent Requirements and. Resolving Conflicted. Requirements of Safety And Security for Industrial Control Systems
    Gu, Tingyang
    Lu, Minyan
    Li, Luyi
    PROCEEDINGS OF THE 2015 FIRST INTERNATIONAL CONFERENCE ON RELIABILITY SYSTEMS ENGINEERING 2015 ICRSE, 2015,
  • [45] Cyber Attack Scenario Generation Method for Improving the Efficient of Security Measures in Industrial Control Systems
    Ogura T.
    Fujita J.
    Matsumoto N.
    IEEJ Transactions on Electronics, Information and Systems, 2024, 144 (01) : 35 - 42
  • [46] A Novel Security Risk Analysis Using the AHP Method in Smart Railway Systems
    Avci, Isa
    Koca, Murat
    APPLIED SCIENCES-BASEL, 2024, 14 (10):
  • [47] Threat scenario-based security risk analysis using use case modeling in information systems
    Kim, Young-Gab
    Cha, Sungdeok
    SECURITY AND COMMUNICATION NETWORKS, 2012, 5 (03) : 293 - 300
  • [48] Quantitative evaluation model for dynamic performance analysis of security risk in industrial cyber physics systems
    Sun Z.-W.
    Zhang S.-G.
    Kongzhi yu Juece/Control and Decision, 2021, 36 (08): : 1939 - 1946
  • [49] Integrated process safety and process security risk assessment of industrial cyber-physical systems in chemical plants
    Yuan, Shuaiqi
    Yang, Ming
    Reniers, Genserik
    COMPUTERS IN INDUSTRY, 2024, 155
  • [50] Cyber Security in Industrial Control Systems: Analysis of DoS Attacks against PLCs and the Insider Effect
    Ylmaz, Ercan Nurcan
    Ciylan, Bunyamin
    Gonen, Serkan
    Sindiren, Erhan
    Karacayilmaz, Gokce
    2018 6TH INTERNATIONAL ISTANBUL SMART GRIDS AND CITIES CONGRESS AND FAIR (ICSG ISTANBUL 2018), 2018, : 81 - 85