Cyber Physical Systems Security for Maritime Assets

被引:18
|
作者
Progoulakis, Iosif [1 ]
Rohmeyer, Paul [2 ]
Nikitakos, Nikitas [1 ]
机构
[1] Univ Aegean, Dept Shipping Trade & Transport, Korais St 2A, GR-82132 Chios, Greece
[2] Stevens Inst Technol, Sch Business, 1 Castle Hudson, Hoboken, NJ 07030 USA
关键词
cyber security; cyber physical systems; IT; OT; maritime assets; cyber and physical security convergence; API STD 780; Security Risk Assessment (SRA); Bow Tie Analysis; RISK ANALYSIS;
D O I
10.3390/jmse9121384
中图分类号
U6 [水路运输]; P75 [海洋工程];
学科分类号
0814 ; 081505 ; 0824 ; 082401 ;
摘要
The integration of IT, OT, and human factor elements in maritime assets is critical for their efficient and safe operation and performance. This integration defines cyber physical systems and involves a number of IT and OT components, systems, and functions that involve multiple and diverse communication paths that are technologically and operationally evolving along with credible cyber security threats. These cyber security threats and risks as well as a number of known security breach scenarios are described in this paper to highlight the evolution of cyber physical systems in the maritime domain and their emerging cyber vulnerabilities. Current industry and governmental standards and directives related to cyber security in the maritime domain attempt to enforce the regulatory compliance and reinforce asset cyber security integrity for optimum and safe performance with limited focus, however, in the existing OT infrastructure and systems. The use of outside-of-the-maritime industry security risk assessment tools and processes, such the API STD 780 Security Risk Assessment (SRA) and the Bow Tie Analysis methodologies, can assist the asset owner to assess its IT and OT infrastructure for cyber and physical security vulnerabilities and allocate proper mitigation measures assuming their similarities to ICS infrastructure. The application of cyber security controls deriving from the adaptation of the NIST CSF and the MITRE ATT&CK Threat Model can further increase the cyber security integrity of maritime assets, assuming they are periodically evaluated for their effectiveness and applicability. Finally, the improvement in communication among stakeholders, the increase in operational and technical cyber and physical security resiliency, and the increase in operational cyber security awareness would be further increased for maritime assets by the convergence of the distinct physical and cyber security functions as well as onshore- and offshore-based cyber infrastructure of maritime companies and asset owners.
引用
收藏
页数:24
相关论文
共 50 条
  • [31] Analysis of security in cyber-physical systems
    Jie Chen
    Fan Zhang
    Jian Sun
    [J]. Science China Technological Sciences, 2017, 60 : 1975 - 1977
  • [32] Cyber Security of Cyber Physical Systems: Cyber Threats and Defense of Critical Infrastructures
    Shukla, Sandeep K.
    [J]. 2016 29TH INTERNATIONAL CONFERENCE ON VLSI DESIGN AND 2016 15TH INTERNATIONAL CONFERENCE ON EMBEDDED SYSTEMS (VLSID), 2016, : 30 - 31
  • [33] A new enhanced cyber security framework for medical cyber physical systems
    Priyadarshini, Ishaani
    Kumar, Raghvendra
    Tuan, Le Minh
    Son, Le Hoang
    Long, Hoang Viet
    Sharma, Rohit
    Rai, Sakshi
    [J]. SICS SOFTWARE-INTENSIVE CYBER-PHYSICAL SYSTEMS, 2021, 35 (3-4): : 159 - 183
  • [34] Integrating artificial intelligence in cyber security for cyber-physical systems
    Alowaidi, Majed
    Sharma, Sunil Kumar
    AlEnizi, Abdullah
    Bhardwaj, Shivam
    [J]. ELECTRONIC RESEARCH ARCHIVE, 2023, 31 (04): : 1876 - 1896
  • [35] On modeling of electrical cyber-physical systems considering cyber security
    Wang, Yi-nan
    Lin, Zhi-yun
    Liang, Xiao
    Xu, Wen-yuan
    Yang, Qiang
    Yan, Gang-feng
    [J]. FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2016, 17 (05) : 465 - 478
  • [36] Cyber Security Based on Artificial Intelligence for Cyber-Physical Systems
    Sedjelmaci, Hichem
    Guenab, Fateh
    Senouci, Sidi-Mohammed
    Moustafa, Hassnaa
    Liu, Jiajia
    Han, Shuai
    [J]. IEEE NETWORK, 2020, 34 (03): : 6 - 7
  • [37] Generative AI in Cyber Security of Cyber Physical Systems: Benefits and Threats
    Mavikumbure, Harindra S.
    Cobilean, Victor
    Wickramasinghe, Chathurika S.
    Drake, Devin
    Manic, Milos
    [J]. 2024 16TH INTERNATIONAL CONFERENCE ON HUMAN SYSTEM INTERACTION, HSI 2024, 2024,
  • [38] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan WANG
    Zhi-yun LIN
    Xiao LIANG
    Wen-yuan XU
    Qiang YANG
    Gang-feng YAN
    [J]. Frontiers of Information Technology & Electronic Engineering, 2016, 17 (05) : 465 - 478
  • [39] On modeling of electrical cyber-physical systems considering cyber security
    Yi-nan Wang
    Zhi-yun Lin
    Xiao Liang
    Wen-yuan Xu
    Qiang Yang
    Gang-feng Yan
    [J]. Frontiers of Information Technology & Electronic Engineering, 2016, 17 : 465 - 478
  • [40] BRAT: A BRidge Attack Tool for Cyber Security Assessments of Maritime Systems
    Hemminghaus, C.
    Bauer, J.
    Padilla, E.
    [J]. TRANSNAV-INTERNATIONAL JOURNAL ON MARINE NAVIGATION AND SAFETY OF SEA TRANSPORTATION, 2021, 15 (01) : 35 - 44