Towards an Automated and Dynamic Risk Management Response System

被引:6
|
作者
Gonzalez-Granadillo, Gustavo [1 ]
Alvarez, Ender [1 ]
Motzek, Alexander [2 ]
Merialdo, Matteo [3 ]
Garcia-Alfaro, Joaquin [1 ]
Debar, Herve [1 ]
机构
[1] Telecom SudParis, Inst Mines Telecom, SAMOVAR, CNRS UMR 5157, 9 Rue Charles Fourier, F-91011 Evry, France
[2] Univ Lubeck, Inst Informat Syst, Ratzeburger Allee 160, D-23562 Lubeck, Germany
[3] RHEA Grp, Ave Pasteur 23, B-1300 Wavre, Belgium
来源
基金
欧盟第七框架计划;
关键词
Dynamic response system; RORI; Operational impact; Automatic response; Critical infrastructures;
D O I
10.1007/978-3-319-47560-8_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Achieving a fully automated and dynamic system in critical infrastructure scenarios is an open issue in ongoing research. Generally, decisions in SCADA systems require a manual intervention, that in most of the cases is performed by highly experienced operators. In this paper we propose a framework consisting of a proactive management software that aims at anticipating the occurrence of potential attacks. It conducts an initial evaluation of reported proactive evidences based on a quantitative metric of monetary return on response investment. The framework evaluates and selects mitigation actions from a pool of candidates, by ranking them in terms of financial and operational impacts. The purpose of this process is to select an optimal set of mitigation actions from financial and operational perspectives and propose them to reduce the risk of threats against the monitored system, without sacrificing an organization's missions in favor of security. A real world case study of a SCADA environment shows the applicability of the model, from the analysis of the input data to the selection of the response plan.
引用
收藏
页码:37 / 53
页数:17
相关论文
共 50 条
  • [1] IS Project Management and Risk Escalation: Towards A Dynamic Model Response
    Parinyavuttichai, Nipon
    Lin, Angela Y.
    AUSTRALASIAN JOURNAL OF INFORMATION SYSTEMS, 2015, 19 : P3 - P4
  • [2] Dynamic risk management response system to handle cyber threats
    Gonzalez-Granadillo, G.
    Dubus, S.
    Motzek, A.
    Garcia-Alfaro, J.
    Alvarez, E.
    Merialdo, M.
    Papillon, S.
    Debar, H.
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 83 : 535 - 552
  • [3] IS Project Management and Risk Escalation: Towards A Dynamic Model
    Cuellar, Michael
    AUSTRALASIAN JOURNAL OF INFORMATION SYSTEMS, 2015, 19 : P1 - P3
  • [4] An Automated Voice Response System for Anticoagulant Therapy Management
    Quaglini, Silvana
    Giorgino, Toni
    Rojas-Barahona, Lina M.
    MEDICAL INFORMATICS IN A UNITED AND HEALTHY EUROPE, 2009, 150 : 453 - 457
  • [5] A Dynamic and Automated Access Control Management System for Social Networks
    Abid, Sohail
    Daud, Malik Imran
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [6] Automated Management of Dynamic Component Dependency for Runtime System Reconfiguration
    Su, Ping
    Cao, Chun
    Ma, Xiaoxing
    Lu, Jian
    2013 20TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2013), VOL 1, 2013, : 450 - 458
  • [7] Towards Dynamic Risk Management: Success Likelihood of Ongoing Attacks
    Kanoun, Wael
    Dubus, Samuel
    Papillon, Serge
    Cuppens-Boulahia, Nora
    Cuppens, Frederic
    BELL LABS TECHNICAL JOURNAL, 2012, 17 (03) : 61 - 78
  • [8] Towards a Self-Driving Management System for the Automated Realization of Intents
    Dzeparoska, Kristina
    Beigi-Mohammadi, Nasim
    Tizghadam, Ali
    Leon-Garcia, Alberto
    Dzeparoska, Kristina (kristina.dzeparoska@mail.utoronto.ca), 1600, Institute of Electrical and Electronics Engineers Inc. (09): : 159882 - 159907
  • [9] Towards a Self-Driving Management System for the Automated Realization of Intents
    Dzeparoska, Kristina
    Beigi-Mohammadi, Nasim
    Tizghadam, Ali
    Leon-Garcia, Alberto
    IEEE ACCESS, 2021, 9 : 159882 - 159907
  • [10] Automated Demand Response From Home Energy Management System Under Dynamic Pricing and Power and Comfort Constraints
    Althaher, Sereen
    Mancarella, Pierluigi
    Mutale, Joseph
    IEEE TRANSACTIONS ON SMART GRID, 2015, 6 (04) : 1874 - 1883