The industrial control system cyber defence triage process

被引:19
|
作者
Cook, Allan [1 ]
Janicke, Heige [1 ]
Smith, Richard [1 ]
Maglaras, Leandros [1 ]
机构
[1] De Montfort Univ, Cyber Technol Inst, Leicester LE1 9BH, Leics, England
关键词
ICS; SCADA; Cyber; Security; Triage; Risk;
D O I
10.1016/j.cose.2017.07.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The threat to Industrial Control Systems (ICS) from cyber attacks is widely acknowledged by governments and literature. Operators of ICS are looking to address these threats in an effective and cost-sensitive manner that does not expose their operations to additional risks through invasive testing. Whilst existing standards and guidelines offer comprehensive advice for reviewing the security of ICS infrastructure, resource and time limitations can lead to incomplete assessments or undesirably long countermeasure implementation schedules. In this paper we consider the problem of undertaking efficient cyber security risk assessments and implementing mitigations in large, established ICS operations for which a full security review cannot be implemented on a constrained timescale. The contribution is the Industrial Control System Cyber Defence Triage Process (ICS-CDTP). ICS-CDTP determines areas of priority where the impact of attacks is greatest, and where initial investment reduces the organisation's overall exposure swiftly. ICS-CDTP is designed to be a precursor to a wider, holistic review across the operation following established security management approaches. ICS-CDTP is a novel combination of the Diamond Model of Intrusion Analysis, the Mandiant Attack Lifecycle, and the CARVER Matrix, allowing for an effective triage of attack vectors and likely targets for a capable antagonist. ICS-CDTP identifies and focuses on key ICS processes and their exposure to cyber threats with the view to maintain critical operations. The article defines ICS-CDTP and exemplifies its application using a fictitious water treatment facility, and explains its evaluation as part of a large-scale serious game exercise. (C) 2017 Elsevier Ltd. All rights reserved.
引用
收藏
页码:467 / 481
页数:15
相关论文
共 50 条
  • [1] Process Discovery for Industrial Control System Cyber Attack Detection
    Myers, David
    Radke, Kenneth
    Suriadi, Suriadi
    Foo, Ernest
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, SEC 2017, 2017, 502 : 61 - 75
  • [2] Design and Implementation of Industrial Control Cyber Range System
    Low, Xuan
    Yang, DeQuan
    Yang, DengPan
    2022 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY, CYBERC, 2022, : 166 - 170
  • [3] Overview of Cyber-security of Industrial Control System
    Fan, Xiaohe
    Fan, Kefeng
    Wang, Yong
    Zhou, Ruikang
    2015 INTERNATIONAL CONFERENCE ON CYBER SECURITY OF SMART CITIES, INDUSTRIAL CONTROL AND COMMUNICATIONS (SSIC), 2015,
  • [4] An evaluation framework for industrial control system cyber incidents
    Firoozjaei, Mandi Daghmehchi
    Mahmoudyar, Nastaran
    Baseri, Yaser
    Ghorbani, Ali A.
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2022, 36
  • [5] APT Adversarial Defence Mechanism for Industrial IoT Enabled Cyber-Physical System
    Javed, Safdar Hussain
    Bin Ahmad, Maaz
    Asif, Muhammad
    Akram, Waseem
    Mahmood, Khalid
    Das, Ashok Kumar
    Shetty, Sachin
    IEEE ACCESS, 2023, 11 : 74000 - 74020
  • [6] Cyber Threat Information Sharing System for Industrial Control System (ICS)
    Abe, Shingo
    Uchida, Yukako
    Hori, Mitsutaka
    Hiraoka, Yuichiro
    Horata, Shinichi
    2018 57TH ANNUAL CONFERENCE OF THE SOCIETY OF INSTRUMENT AND CONTROL ENGINEERS OF JAPAN (SICE), 2018, : 374 - 379
  • [7] A Cyber-Security Methodology for a Cyber-Physical Industrial Control System Testbed
    Noorizadeh, Mohammad
    Shakerpour, Mohammad
    Meskin, Nader
    Unal, Devrim
    Khorasani, Khashayar
    IEEE ACCESS, 2021, 9 : 16239 - 16253
  • [8] Cyber Security Issues of Critical Components for Industrial Control System
    Yang, Wen
    Zhao, Qianchuan
    2014 IEEE CHINESE GUIDANCE, NAVIGATION AND CONTROL CONFERENCE (CGNCC), 2014, : 2698 - 2703
  • [9] INDUSTRIAL PROCESS MONITORING AND CONTROL SYSTEM
    Saracin, Cristina Gabriela
    Tunsoiu, Radu Andrei
    UNIVERSITY POLITEHNICA OF BUCHAREST SCIENTIFIC BULLETIN SERIES C-ELECTRICAL ENGINEERING AND COMPUTER SCIENCE, 2022, 84 (01): : 145 - 154
  • [10] INDUSTRIAL PROCESS MONITORING AND CONTROL SYSTEM
    Sărăcin, Cristina Gabriela
    Tunsoiu, Radu Andrei
    UPB Scientific Bulletin, Series C: Electrical Engineering and Computer Science, 2022, 84 (01): : 145 - 154