Towards an Automated and Dynamic Risk Management Response System

被引:6
|
作者
Gonzalez-Granadillo, Gustavo [1 ]
Alvarez, Ender [1 ]
Motzek, Alexander [2 ]
Merialdo, Matteo [3 ]
Garcia-Alfaro, Joaquin [1 ]
Debar, Herve [1 ]
机构
[1] Telecom SudParis, Inst Mines Telecom, SAMOVAR, CNRS UMR 5157, 9 Rue Charles Fourier, F-91011 Evry, France
[2] Univ Lubeck, Inst Informat Syst, Ratzeburger Allee 160, D-23562 Lubeck, Germany
[3] RHEA Grp, Ave Pasteur 23, B-1300 Wavre, Belgium
来源
基金
欧盟第七框架计划;
关键词
Dynamic response system; RORI; Operational impact; Automatic response; Critical infrastructures;
D O I
10.1007/978-3-319-47560-8_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Achieving a fully automated and dynamic system in critical infrastructure scenarios is an open issue in ongoing research. Generally, decisions in SCADA systems require a manual intervention, that in most of the cases is performed by highly experienced operators. In this paper we propose a framework consisting of a proactive management software that aims at anticipating the occurrence of potential attacks. It conducts an initial evaluation of reported proactive evidences based on a quantitative metric of monetary return on response investment. The framework evaluates and selects mitigation actions from a pool of candidates, by ranking them in terms of financial and operational impacts. The purpose of this process is to select an optimal set of mitigation actions from financial and operational perspectives and propose them to reduce the risk of threats against the monitored system, without sacrificing an organization's missions in favor of security. A real world case study of a SCADA environment shows the applicability of the model, from the analysis of the input data to the selection of the response plan.
引用
收藏
页码:37 / 53
页数:17
相关论文
共 50 条
  • [31] TOWARDS A UNIFIED INFRASTRUCTURE FOR AUTOMATED MANAGEMENT AND INTEGRATION OF HETEROGENEOUS GEO-DATASETS IN DISASTER RESPONSE
    Mobasheri, Amin
    Bakillah, Mohamed
    2015 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM (IGARSS), 2015, : 4570 - 4573
  • [32] Towards Automated Patch Management in a Hybrid Cloud
    Hafeez, Ubaid Ullah
    Karve, Alexei
    Dumba, Braulio
    Gandhi, Anshul
    Zeng, Sai
    SERVICE-ORIENTED COMPUTING (ICSOC 2019), 2019, 11895 : 345 - 350
  • [33] Dynamic risk management
    Rampini, Adriano A.
    Sufi, Amir
    Viswanathan, S.
    JOURNAL OF FINANCIAL ECONOMICS, 2014, 111 (02) : 271 - 296
  • [34] Distributed automated management system
    Prokofiev, Yu.A.
    Saryan, V.K.
    Zubarev, Yu.P.
    Balasanyan, V.E.
    Elektrosvyaz, 1999, (06): : 19 - 22
  • [35] Automated Course Management System
    Alvi, Ashik Mostafa
    Shaon, Md. Faqrul Islam
    Das, Prithvi Ranjan
    Mustafa, Manazir
    Bari, Mohammad Rezaul
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 161 - 166
  • [36] Dynamic Software Architecture Development: Towards an Automated Process
    ter Beek, Maurice H.
    Bucchiarone, Antonio
    Gnesi, Stefania
    2009 35TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS, PROCEEDINGS, 2009, : 105 - +
  • [37] Towards Automated Conceptual Design of Physical Dynamic Systems
    Redfield, R. C.
    Krishnan, S.
    JOURNAL OF ENGINEERING DESIGN, 1992, 3 (03) : 187 - 204
  • [38] Towards a dynamic ontology based software project management antipattern intelligent system
    Settas, Dimitrios
    Stamelos, Ioannis
    19TH IEEE INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, VOL I, PROCEEDINGS, 2007, : 186 - +
  • [39] Towards program risk management and perceived risk management barriers
    BeijingUniversity of Posts and Telecommunications, China
    不详
    Int. J. Hybrid Inf. Technol., 5 (323-338):
  • [40] Dynamic Response of Aerial Refueling Hose-Drogue System with Automated Control Surfaces
    Garcia-Fogeda, P.
    Molina, J. Esteban
    Arevalo, F.
    JOURNAL OF AEROSPACE ENGINEERING, 2018, 31 (06)